The platform shows many labels in capital letters. This guide quotes them in bold, exactly as they appear on screen, so you can match them. Where the platform uses two names for one thing, the entry says so.

Important

The platform uses several scores and levels. They cannot be compared with each other:

  • Security score (External Attack Surface Management, EASM): a number with a letter grade, A from 800 down to F from 300.
  • Risk Score (Brand Risk Protection, BRP): 0 to 100, in bands from INFORMATION to CRITICAL.
  • Risk level (Cyber Threat Intelligence, CTI): labels from CRITICAL to LOW.
  • AVG STRENGTH SCORE (CTI): the strength of an employee's leaked passwords, out of 10.
  • CVSS (SCORE/SEVERITY): 0 to 10.
  • EPSS and AVERAGE EXPLOITABILITY SCORE: percentages.

Account and Access

Term UI labels Meaning
Organization ORGANIZATION SETTINGS / Organization Details Your company's account on the platform. Each user belongs to exactly one organization; there is no switching between organizations.
Admin, Member ADMIN / MEMBER / SET AS ADMIN / SET AS MEMBER The roles. Only admins see the organization's Settings, Members and Security pages. See Manage members and invitations.
Package … IS NOT INCLUDED IN YOUR PACKAGE / TALK TO US / "This feed is not included in your package" What your organization has bought. A screen outside your package is covered by a notice whose TALK TO US button opens an e-mail to Deepinfo support. See What you can access.
API key, default API key API Keys / Default API Key / Set as Default / TEAM MEMBER A key for calling the Deepinfo API at api.deepinfo.com (demo accounts use a different address; see Environments & base URL). Each key belongs to a member, shown under TEAM MEMBER. The default key is marked with a badge and cannot be deleted. The platform also uses it for its own calls to the API. See Create and manage API keys.
Quota QUOTA: / USED: / REMAINING: Your package's allowance for a group of API endpoints. On API Usage, the bar and the percentage show the share that remains. The period is not shown. See Check API usage and quota.
Two-factor authentication, recovery code Two Factor Authentication / Use a Recovery Code / DOWNLOAD CODE AND CLOSE A 6-digit code from an authenticator app, asked for at sign-in. Recovery codes let you sign in without the app. Each works once, and you can download them only when you set up two-factor authentication. See Use two-factor authentication.

Finding Your Way

Term UI labels Meaning
Sidebar Group headings EXTERNAL ATTACK SURFACE MANAGEMENT / CYBER THREAT INTELLIGENCE / BRAND RISK PROTECTION / DEEP SEARCH & INSIGHTS; Collapse sidebar / Expand sidebar The menu on the left. The module items sit under the coloured module group headings, followed by REPORTS, NOTIFICATION CENTER and SETTINGS. Collapsed, the sidebar shows icons and the short group names EASM, CTI, BRP and DSI. See Find your way around.
Breadcrumb For example EASM / ISSUES / ISSUE LIST The path at the top left of every page, from the module to the page you are on.
In-page tabs OVERVIEW, then a list tab such as ISSUE LIST, then INSIGHTS or SETTINGS Tabs under a page's title. OVERVIEW holds the key figures, the list tab holds the records, INSIGHTS holds charts and distributions, and SETTINGS holds the area's settings.

Lists and Records

Term UI labels Meaning
Quick view, list view Two icons: an eye and a list The two layouts of a list: a split pane with the list on the left and the selected record on the right (quick view), or a table (list view).
Drawer OPEN IN NEW TAB A panel that opens on the right with a record's details. Its tabs are icons down its left side; hover over an icon to see its name. OPEN IN NEW TAB opens the record's full page.
Filter, filter rule Filter chips; SHOW ALL FILTERS / HIDE FILTERS; Must / Must Not / Should Filters sit above a list as chips. A chip opens a popover where you choose a field, a rule, an operator and a value. The rule includes (Must), excludes (Must Not) or prefers (Should) matching records. API search filters use the same model; see Search & filters.
View options VIEW SETTINGS / View Options / Sort By / Result Per Page / Reset to Default View / SHOWN A list's display settings: the sort order, the number of rows per page and which columns are shown.
Export, export scope EXPORT / DOWNLOAD / RECORDS (ALL / FILTERED) / FILE FORMAT (CSV / JSON) / EXPORT SCOPE (DEFAULT / BASIC / EXTENDED) Download a list as a CSV or JSON file: every record, or only the records that match your filters. Some lists also let you choose an export scope. See Search, filter and export lists.

Assets

Term UI labels Meaning
Asset Tabs DOMAINS / SUBDOMAINS / IP ADDRESSES / WEBSITES; filter values Domain / Subdomain / IP Address / Website Something you monitor: a domain, a subdomain, an IP address or a website. A website's name includes its port (host:port). See Browse your asset inventory.
Inventory ("portfolio") Inventory / Add to Portfolio / "… in your portfolio" Your monitored assets. Where the platform says "portfolio", it means the same thing.
Main asset MAIN ASSET / SET AS MAIN ASSET / REVERT TO NORMAL ASSET An asset you mark as main. The platform describes it as "the primary asset for all related assets, configurations, and reports."
Seems inactive SEEMS INACTIVE / THIS … IS CURRENTLY INACTIVE The platform's message says it found no active DNS records or WHOIS information for the asset; for a subdomain, no DNS records.
Parked, Redirected, Login page, IDN Parked / Redirected / Login Page / IDN: Icons next to an asset's name. The Parked and Redirected tooltips show the name the asset redirects to. Login Page means the asset has a login page. IDN: marks an internationalized name and shows its punycode form. Parked assets are shown muted in tables.
Asset weight ASSET WEIGHT / SYSTEM WEIGHT / NEW WEIGHT / SET ASSET WEIGHT How important an asset is to your organization. The system calculates a SYSTEM WEIGHT, which can be above 100. With SET ASSET WEIGHT you can set your own weight, from 1 to 100. The weight affects your organization's security score.
Security score, rating SECURITY RATING / SCORE / A to F The EASM security score and its letter grade: A from 800, B from 700, C from 600, D from 500, E from 400 and F from 300. Below 300, or without a score, the grade shows -. See How security scores work.
Scan SCAN NOW / START PORT SCAN / LAST CHECK DATE An on-demand rescan of an asset (SCAN NOW) or of its ports (START PORT SCAN). LAST CHECK DATE shows when the asset was last checked. On an asset's page, SCAN NOW is unavailable for 5 minutes after a manual scan.
Historical records SHOW HISTORICAL … RECORDS / Compare Dates (Up to 3 Records) Earlier snapshots of an asset's WHOIS, DNS, SSL, website info and open ports. You can compare up to three dates side by side.
Expiry status ACTIVE / EXPIRES SOON / EXPIRED / INVALID CERTIFICATE The status of an SSL certificate or a domain registration: more than a month left, less than a month left, expired, or an invalid certificate.
Port state OPEN / OPEN FILTERED / CLOSED / CLOSED FILTERED / FILTERED / UNFILTERED The state of a scanned port. The OPEN PORTS tab shows open ports by default.
Creation method MANUALLY ADDED / MANUALLY APPROVED / AUTO APPROVED How an asset entered your inventory.

Discovery

Term UI labels Meaning
Discovery, discovered asset DISCOVERED ASSETS / IN REVIEW / APPROVED / IGNORED / ADD TO MY ASSETS / IGNORE / UNDO IGNORE A discovered asset is a candidate that discovery rules found around your attack surface. It stays IN REVIEW until it is approved into your assets (with ADD TO MY ASSETS, or automatically by Auto Approval) or ignored. UNDO IGNORE reverses an ignore. See Review discovered assets.
Smart and custom discovery rules SMART DISCOVERY RULES / SMART MONITORING RULES / Custom Rules Smart rules are managed by Deepinfo; you can switch them on or off and tune them. Custom rules are discovery rules you build from filters. All of them are on the SETTINGS tab of DISCOVERY.
Seed asset, seed value MANAGE EXCLUDED SEED ASSETS / MANAGE EXCLUDED SEED VALUES The assets and values a smart rule starts from. A rule skips the seeds you exclude.
Auto approval Auto Approval / AUTO APPROVAL On a discovery rule: assets in review that match the rule are approved automatically. On a BRP detection rule: suspicious domains that match the rule are marked as fraudulent automatically.
Global Blacklist Global Blacklist A list that Deepinfo's data team manages and updates. It excludes generic values to reduce false-positive discoveries.
Ignored Assets (discovery) Ignored Assets A list in the discovery settings. Domains, subdomains and IP addresses on it never appear in discovery lists, even when a rule finds them.

Issues and Vulnerabilities

Term UI labels Meaning
Issue type, issue ISSUES / GROUP BY ISSUE TYPES An issue type is a kind of finding, such as an expired SSL certificate. An issue is one issue type found on one asset. The issue list is grouped by issue type by default. See Triage issues.
Issue category CATEGORY / CATEGORY STATS A group of related issue types.
Severity CRITICAL / HIGH / MEDIUM / LOW / INFORMATION The severity levels of issue types and issues.
State ACTIVE: NEWLY DETECTED / UNRESOLVED / REAPPEARED; INACTIVE: NOT APPLICABLE / VERIFIED RESOLVED / IGNORED / RISK ACCEPTED / MARKED AS RESOLVED / MARKED AS FALSE POSITIVE; SHOW INACTIVES Where an issue, or a CVE on one asset, stands. The states are grouped as active or inactive. The platform sets NEWLY DETECTED, UNRESOLVED, REAPPEARED, NOT APPLICABLE and VERIFIED RESOLVED. Users set the others. Lists show only active records until you tick SHOW INACTIVES. See Change the state of issues and vulnerabilities.
State actions CHANGE STATUS / IGNORE / ACCEPT RISK / MARK AS RESOLVED / MARK AS FALSE POSITIVE / REVERT IT / UNDO / CHANGE STATE / CHANGE ALL STATUS The actions that set a user state, on one record or in bulk. Only states set by a user can be reverted. A change shows a few seconds after you confirm it.
Active days ACTIVE DAYS The days between an issue's first and last detection, not its age up to today. After 30 days the value turns red with a fire icon.
Issue duration, fix duration, issue age AVERAGE ISSUE DURATION / AVERAGE FIX DURATION / AVERAGE ISSUE AGE Averages, in days.
Proof PROOF The evidence for an issue, shown as JSON.
Classifications CLASSIFICATIONS The compliance frameworks an issue type maps to, such as OWASP Top 10 2021, PCI 3.2, CAPEC, CWE, HIPAA and WASC.
Vulnerability (CVE), asset vulnerability VULNERABILITIES / CVE ID A CVE that affects at least one of your assets. Its state is changed per asset, not for the CVE as a whole. See Prioritize vulnerabilities.
Certain, Potential CERTAIN / POTENTIAL Certain: "This vulnerability has been verified through testing and confirmed as valid." Potential: "This vulnerability has been identified through testing but not yet confirmed."
CVSS score SCORE/SEVERITY / CVSS SCORE The CVE's CVSS base score, from 0 to 10, with its severity. CVSS v3 is used, or v2 when v3 is missing.
EPSS EPSS / EPSS SCORE The CVE's EPSS value, shown as a percentage.
Exploitable (CISA KEV) EXPLOITABLE / EXP. / CISA KEV CATALOG Shown when the CVE is in the CISA KEV catalog.
Classification chips C/I/A: H/L/N / OWASP … C/I/A shows the CVE's impact on confidentiality, integrity and availability, as the first letter of each impact level. OWASP shows its OWASP category.
New vulnerability NEW "This vulnerability was first detected on your assets in the last 7 days."
Technology version LATEST VERSION / VERSION SCOPE (Out of Date) / EOL The latest known version of a technology, a filter for technologies on an out-of-date version, and the product's end-of-life table.

Cyber Threat Intelligence (CTI)

Term UI labels Meaning
Compromised employee COMPROMISED EMPLOYEE DATA / COMPROMISED EMPLOYEES An employee account on your domains that was found in leaked credential data. See Investigate compromised employees.
Exposed credential EXPOSED CREDENTIALS / CREDENTIAL / SHOW PASSWORD One leaked login of an employee: the site or service, the account and the password. Passwords are masked until you reveal them with SHOW PASSWORD or the eye icon; revealing shows the password in plain text in your browser. See Review exposed credentials.
Credential state STATE, for example ACTIVE · UNRESOLVED or ACTIVE · NEWLY DETECTED; IGNORED / RISK ACCEPTED / MARKED AS RESOLVED / MARKED AS FALSE POSITIVE; CHANGE STATE / CHANGE ALL STATES / REVERT STATE; SHOW INACTIVES Where an exposed credential stands: ACTIVE or INACTIVE, with a detail, like an issue state. You can ignore a credential, accept its risk, or mark it as resolved or as a false positive, one at a time or in bulk; these states are inactive. REVERT STATE undoes a state you set. Inactive credentials are hidden until you tick SHOW INACTIVES. Client and payment credentials have a STATE too. See Change the state of exposed credentials.
Compromised client credential COMPROMISED CLIENT CREDENTIALS / COMPROMISED CLIENTS A login of one of your clients or customers that was found in breach data: the username and the site it belongs to. The list does not show passwords. See Review compromised client credentials.
Compromised payment credential COMPROMISED PAYMENT CREDENTIALS / COMPROMISED PAYMENTS / PAN / CONFIDENCE / TIMES SEEN A payment card that was found in breach data. The list shows the card number (PAN), CONFIDENCE, SOURCE, HACKISHNESS, TIMES SEEN, STATE and LAST SEEN. See Review compromised payment credentials.
Risk level (CTI) CRITICAL / HIGH / MEDIUM / LOW An employee's priority. The platform describes it as "Composite priority based on credential, role, and recency."
Password strength VERY WEAK / WEAK / MEDIUM / STRONG / VERY STRONG; AVG STRENGTH SCORE A five-level strength label for a leaked password. AVG STRENGTH SCORE is the average strength of an employee's passwords, out of 10.
Exposure velocity, trend VELOCITY / TREND / EXPOSURE SPAN Part of an employee's security profile, which shows "how long the exposure has run and whether the rate is rising." VELOCITY is in credentials per month (cred/mo); TREND shows the direction, for example STABLE.
Executive Is Executive / EXECUTIVE A flag you set on an employee. Executives are shown with a VIP icon.
Target service attributes CORPORATE / MFA BY DEFAULT (ENFORCED / NOT ENFORCED) / RISK TIER Properties of the site or service a leaked credential belongs to.
Hackishness HACKISHNESS / Hackishness A score shown on dark-web search results and on compromised payment records.
Dark-web source SOURCE TYPE / SOURCE GROUP Where a dark-web result comes from: the type, such as Discord, Onion or Telegram, and the group, such as Forums, Markets or Pastes. See Search the dark web.

Brand Risk Protection (BRP)

Term UI labels Meaning
Suspicious domain SUSPICIOUS DOMAINS A lookalike domain that your detection rules found. It waits for your review. See Review suspicious domains.
Fraudulent domain FRAUDULENT DOMAINS / MARK AS FRAUDULENT / REMOVE FROM FRAUDULENT DOMAINS A suspicious domain you confirmed as fraudulent. It moves to the FRAUDULENT DOMAINS tab. See Track fraudulent domains.
Ignored domain IGNORED DOMAINS / UNDO IGNORE A suspicious domain you dismissed. UNDO IGNORE restores it. See Restore ignored domains.
Risk Score (BRP) RISK SCORE / INFORMATION / LOW / MEDIUM / HIGH / CRITICAL A score from 0 to 100 for a detected domain, in bands: INFORMATION from 1 to 20, LOW above 20 up to 40, MEDIUM above 40 up to 60, HIGH above 60 up to 80, CRITICAL above 80. It is not on the same scale as the security score.
Indicators DNS / DNS MX / SSL / HTTP Four signals shown for a detected domain. An icon is dark when the signal is present and light when it is not.
Match type Exact / Contains / Fuzzy / Fuzzy Contains / Confusable Exact / Confusable Contains / Confusable Fuzzy / Confusable Fuzzy Contains How a detection rule matches its keyword against domain names. The default is Contains.
Keywords and TLDs KEYWORD / HELPER KEYWORDS / NEGATIVE KEYWORDS / TLD MUST BE / TLD MUST NOT BE The inputs of a BRP detection rule. KEYWORD is required and has at least 3 characters. TLD MUST BE and TLD MUST NOT BE take extensions from a fixed list. See Set up detection rules.
Start detection From Now On / Include Past Whether a new detection rule starts from now (From Now On, the default) or also covers the past (Include Past). It cannot be changed after the rule is created.
Ignored Assets (BRP) Ignored Assets A list in the BRP settings. Domains and subdomains on it never appear as detected, even when a detection rule matches them.

Deep Search & Insights (DSI)

Term UI labels Meaning
DSI DEEP SEARCH & INSIGHTS / DSI The sidebar group of search and research tools: DOMAIN INTELLIGENCE, DOMAIN SEARCH, VULNERABILITY INTELLIGENCE, VULNERABILITY SEARCH, INSTANT LOOKUP and FEEDS. Its breadcrumbs start with DSI, which is also its short name in the collapsed sidebar. See Deep Search & Insights (DSI).
Page tabs Duplicate / New Tab to The Right / Close Tab / Close Other Tabs / Close Tabs to the Right Browser-like tabs in Domain Search, Vulnerability Search, Instant Lookup and Dark Web Search. They are saved in your browser, so they survive a reload.
Reverse lookup SEE OTHERS / Domain with same IP Address / Domain with same Name Server / Domain with same Mail Exchanger / Domain with same Email Other domains that share an IP address, name server, mail server or registrant e-mail with the domain you are looking at. See Domain details and reverse lookups.
Instant lookup LOOKUP / PARSED / RAW A real-time query about a single target: WHOIS, DNS, SSL, webdata, technology, screenshot or port scan. PARSED and RAW switch between the formatted result and the JSON. See Run instant lookups.
Feeds DAILY FEEDS / EXCLUSIVE FEEDS / CUSTOM FEEDS Bulk data files you can download, such as the domains registered each day. See Download data feeds.

Reports and Notifications

Term UI labels Meaning
General report, CSV/JSON report GENERAL REPORTS / CSV AND JSON REPORTS / .PDF A general report is a PDF that the platform generates from your data. A CSV/JSON report downloads a whole dataset as a file. See Reports.
Reports history REPORTS HISTORY The copies of a report type generated so far, listed in the report's drawer. Each copy is a snapshot of your data at the time it was generated.
Scheduled report SCHEDULED REPORTS / SCHEDULE A REPORT / SCHEDULE NEW REPORT A PDF report that the platform generates daily, weekly or monthly and e-mails to the members you choose. See Schedule a report.
Notification rule Notification Rules / Event Type / Rule Settings / Filters / Reviews / SCOPE A rule that e-mails chosen members when an event happens. It has one event, optional filters, a frequency and at least one recipient. The rules list shows the event in the SCOPE column. See Notification Center.
Frequency INSTANT / HOURLY / DAILY / WEEKLY / MONTHLY How often a notification rule sends e-mails. Scheduled reports offer DAILY, WEEKLY and MONTHLY.
Delivery channel Email / Slack / Webhook How a rule's notifications are delivered. Only Email can be used; Slack and Webhook are shown but not available.
E-mail preferences, notification rules SETTINGS › USER SETTINGS › Notifications vs NOTIFICATION CENTER E-mail preferences choose which Deepinfo e-mails you receive: announcements, newsletter, product updates and training. Notification rules send alerts about your organization's data. See Choose which Deepinfo e-mails you receive.

Last updated