Glossary
The platform shows many labels in capital letters. This guide quotes them in bold, exactly as they appear on screen, so you can match them. Where the platform uses two names for one thing, the entry says so.
Important
The platform uses several scores and levels. They cannot be compared with each other:
- Security score (External Attack Surface Management, EASM): a number with a letter grade, A from 800 down to F from 300.
- Risk Score (Brand Risk Protection, BRP): 0 to 100, in bands from INFORMATION to CRITICAL.
- Risk level (Cyber Threat Intelligence, CTI): labels from CRITICAL to LOW.
- AVG STRENGTH SCORE (CTI): the strength of an employee's leaked passwords, out of 10.
- CVSS (SCORE/SEVERITY): 0 to 10.
- EPSS and AVERAGE EXPLOITABILITY SCORE: percentages.
Account and Access
| Term | UI labels | Meaning |
|---|---|---|
| Organization | ORGANIZATION SETTINGS / Organization Details | Your company's account on the platform. Each user belongs to exactly one organization; there is no switching between organizations. |
| Admin, Member | ADMIN / MEMBER / SET AS ADMIN / SET AS MEMBER | The roles. Only admins see the organization's Settings, Members and Security pages. See Manage members and invitations. |
| Package | … IS NOT INCLUDED IN YOUR PACKAGE / TALK TO US / "This feed is not included in your package" | What your organization has bought. A screen outside your package is covered by a notice whose TALK TO US button opens an e-mail to Deepinfo support. See What you can access. |
| API key, default API key | API Keys / Default API Key / Set as Default / TEAM MEMBER | A key for calling the Deepinfo API at api.deepinfo.com (demo accounts use a different address; see Environments & base URL). Each key belongs to a member, shown under TEAM MEMBER. The default key is marked with a badge and cannot be deleted. The platform also uses it for its own calls to the API. See Create and manage API keys. |
| Quota | QUOTA: / USED: / REMAINING: | Your package's allowance for a group of API endpoints. On API Usage, the bar and the percentage show the share that remains. The period is not shown. See Check API usage and quota. |
| Two-factor authentication, recovery code | Two Factor Authentication / Use a Recovery Code / DOWNLOAD CODE AND CLOSE | A 6-digit code from an authenticator app, asked for at sign-in. Recovery codes let you sign in without the app. Each works once, and you can download them only when you set up two-factor authentication. See Use two-factor authentication. |
Finding Your Way
| Term | UI labels | Meaning |
|---|---|---|
| Sidebar | Group headings EXTERNAL ATTACK SURFACE MANAGEMENT / CYBER THREAT INTELLIGENCE / BRAND RISK PROTECTION / DEEP SEARCH & INSIGHTS; Collapse sidebar / Expand sidebar | The menu on the left. The module items sit under the coloured module group headings, followed by REPORTS, NOTIFICATION CENTER and SETTINGS. Collapsed, the sidebar shows icons and the short group names EASM, CTI, BRP and DSI. See Find your way around. |
| Breadcrumb | For example EASM / ISSUES / ISSUE LIST | The path at the top left of every page, from the module to the page you are on. |
| In-page tabs | OVERVIEW, then a list tab such as ISSUE LIST, then INSIGHTS or SETTINGS | Tabs under a page's title. OVERVIEW holds the key figures, the list tab holds the records, INSIGHTS holds charts and distributions, and SETTINGS holds the area's settings. |
Lists and Records
| Term | UI labels | Meaning |
|---|---|---|
| Quick view, list view | Two icons: an eye and a list | The two layouts of a list: a split pane with the list on the left and the selected record on the right (quick view), or a table (list view). |
| Drawer | OPEN IN NEW TAB | A panel that opens on the right with a record's details. Its tabs are icons down its left side; hover over an icon to see its name. OPEN IN NEW TAB opens the record's full page. |
| Filter, filter rule | Filter chips; SHOW ALL FILTERS / HIDE FILTERS; Must / Must Not / Should | Filters sit above a list as chips. A chip opens a popover where you choose a field, a rule, an operator and a value. The rule includes (Must), excludes (Must Not) or prefers (Should) matching records. API search filters use the same model; see Search & filters. |
| View options | VIEW SETTINGS / View Options / Sort By / Result Per Page / Reset to Default View / SHOWN | A list's display settings: the sort order, the number of rows per page and which columns are shown. |
| Export, export scope | EXPORT / DOWNLOAD / RECORDS (ALL / FILTERED) / FILE FORMAT (CSV / JSON) / EXPORT SCOPE (DEFAULT / BASIC / EXTENDED) | Download a list as a CSV or JSON file: every record, or only the records that match your filters. Some lists also let you choose an export scope. See Search, filter and export lists. |
Assets
| Term | UI labels | Meaning |
|---|---|---|
| Asset | Tabs DOMAINS / SUBDOMAINS / IP ADDRESSES / WEBSITES; filter values Domain / Subdomain / IP Address / Website | Something you monitor: a domain, a subdomain, an IP address or a website. A website's name includes its port (host:port). See Browse your asset inventory. |
| Inventory ("portfolio") | Inventory / Add to Portfolio / "… in your portfolio" | Your monitored assets. Where the platform says "portfolio", it means the same thing. |
| Main asset | MAIN ASSET / SET AS MAIN ASSET / REVERT TO NORMAL ASSET | An asset you mark as main. The platform describes it as "the primary asset for all related assets, configurations, and reports." |
| Seems inactive | SEEMS INACTIVE / THIS … IS CURRENTLY INACTIVE | The platform's message says it found no active DNS records or WHOIS information for the asset; for a subdomain, no DNS records. |
| Parked, Redirected, Login page, IDN | Parked / Redirected / Login Page / IDN: | Icons next to an asset's name. The Parked and Redirected tooltips show the name the asset redirects to. Login Page means the asset has a login page. IDN: marks an internationalized name and shows its punycode form. Parked assets are shown muted in tables. |
| Asset weight | ASSET WEIGHT / SYSTEM WEIGHT / NEW WEIGHT / SET ASSET WEIGHT | How important an asset is to your organization. The system calculates a SYSTEM WEIGHT, which can be above 100. With SET ASSET WEIGHT you can set your own weight, from 1 to 100. The weight affects your organization's security score. |
| Security score, rating | SECURITY RATING / SCORE / A to F | The EASM security score and its letter grade: A from 800, B from 700, C from 600, D from 500, E from 400 and F from 300. Below 300, or without a score, the grade shows -. See How security scores work. |
| Scan | SCAN NOW / START PORT SCAN / LAST CHECK DATE | An on-demand rescan of an asset (SCAN NOW) or of its ports (START PORT SCAN). LAST CHECK DATE shows when the asset was last checked. On an asset's page, SCAN NOW is unavailable for 5 minutes after a manual scan. |
| Historical records | SHOW HISTORICAL … RECORDS / Compare Dates (Up to 3 Records) | Earlier snapshots of an asset's WHOIS, DNS, SSL, website info and open ports. You can compare up to three dates side by side. |
| Expiry status | ACTIVE / EXPIRES SOON / EXPIRED / INVALID CERTIFICATE | The status of an SSL certificate or a domain registration: more than a month left, less than a month left, expired, or an invalid certificate. |
| Port state | OPEN / OPEN FILTERED / CLOSED / CLOSED FILTERED / FILTERED / UNFILTERED | The state of a scanned port. The OPEN PORTS tab shows open ports by default. |
| Creation method | MANUALLY ADDED / MANUALLY APPROVED / AUTO APPROVED | How an asset entered your inventory. |
Discovery
| Term | UI labels | Meaning |
|---|---|---|
| Discovery, discovered asset | DISCOVERED ASSETS / IN REVIEW / APPROVED / IGNORED / ADD TO MY ASSETS / IGNORE / UNDO IGNORE | A discovered asset is a candidate that discovery rules found around your attack surface. It stays IN REVIEW until it is approved into your assets (with ADD TO MY ASSETS, or automatically by Auto Approval) or ignored. UNDO IGNORE reverses an ignore. See Review discovered assets. |
| Smart and custom discovery rules | SMART DISCOVERY RULES / SMART MONITORING RULES / Custom Rules | Smart rules are managed by Deepinfo; you can switch them on or off and tune them. Custom rules are discovery rules you build from filters. All of them are on the SETTINGS tab of DISCOVERY. |
| Seed asset, seed value | MANAGE EXCLUDED SEED ASSETS / MANAGE EXCLUDED SEED VALUES | The assets and values a smart rule starts from. A rule skips the seeds you exclude. |
| Auto approval | Auto Approval / AUTO APPROVAL | On a discovery rule: assets in review that match the rule are approved automatically. On a BRP detection rule: suspicious domains that match the rule are marked as fraudulent automatically. |
| Global Blacklist | Global Blacklist | A list that Deepinfo's data team manages and updates. It excludes generic values to reduce false-positive discoveries. |
| Ignored Assets (discovery) | Ignored Assets | A list in the discovery settings. Domains, subdomains and IP addresses on it never appear in discovery lists, even when a rule finds them. |
Issues and Vulnerabilities
| Term | UI labels | Meaning |
|---|---|---|
| Issue type, issue | ISSUES / GROUP BY ISSUE TYPES | An issue type is a kind of finding, such as an expired SSL certificate. An issue is one issue type found on one asset. The issue list is grouped by issue type by default. See Triage issues. |
| Issue category | CATEGORY / CATEGORY STATS | A group of related issue types. |
| Severity | CRITICAL / HIGH / MEDIUM / LOW / INFORMATION | The severity levels of issue types and issues. |
| State | ACTIVE: NEWLY DETECTED / UNRESOLVED / REAPPEARED; INACTIVE: NOT APPLICABLE / VERIFIED RESOLVED / IGNORED / RISK ACCEPTED / MARKED AS RESOLVED / MARKED AS FALSE POSITIVE; SHOW INACTIVES | Where an issue, or a CVE on one asset, stands. The states are grouped as active or inactive. The platform sets NEWLY DETECTED, UNRESOLVED, REAPPEARED, NOT APPLICABLE and VERIFIED RESOLVED. Users set the others. Lists show only active records until you tick SHOW INACTIVES. See Change the state of issues and vulnerabilities. |
| State actions | CHANGE STATUS / IGNORE / ACCEPT RISK / MARK AS RESOLVED / MARK AS FALSE POSITIVE / REVERT IT / UNDO / CHANGE STATE / CHANGE ALL STATUS | The actions that set a user state, on one record or in bulk. Only states set by a user can be reverted. A change shows a few seconds after you confirm it. |
| Active days | ACTIVE DAYS | The days between an issue's first and last detection, not its age up to today. After 30 days the value turns red with a fire icon. |
| Issue duration, fix duration, issue age | AVERAGE ISSUE DURATION / AVERAGE FIX DURATION / AVERAGE ISSUE AGE | Averages, in days. |
| Proof | PROOF | The evidence for an issue, shown as JSON. |
| Classifications | CLASSIFICATIONS | The compliance frameworks an issue type maps to, such as OWASP Top 10 2021, PCI 3.2, CAPEC, CWE, HIPAA and WASC. |
| Vulnerability (CVE), asset vulnerability | VULNERABILITIES / CVE ID | A CVE that affects at least one of your assets. Its state is changed per asset, not for the CVE as a whole. See Prioritize vulnerabilities. |
| Certain, Potential | CERTAIN / POTENTIAL | Certain: "This vulnerability has been verified through testing and confirmed as valid." Potential: "This vulnerability has been identified through testing but not yet confirmed." |
| CVSS score | SCORE/SEVERITY / CVSS SCORE | The CVE's CVSS base score, from 0 to 10, with its severity. CVSS v3 is used, or v2 when v3 is missing. |
| EPSS | EPSS / EPSS SCORE | The CVE's EPSS value, shown as a percentage. |
| Exploitable (CISA KEV) | EXPLOITABLE / EXP. / CISA KEV CATALOG | Shown when the CVE is in the CISA KEV catalog. |
| Classification chips | C/I/A: H/L/N / OWASP … | C/I/A shows the CVE's impact on confidentiality, integrity and availability, as the first letter of each impact level. OWASP shows its OWASP category. |
| New vulnerability | NEW | "This vulnerability was first detected on your assets in the last 7 days." |
| Technology version | LATEST VERSION / VERSION SCOPE (Out of Date) / EOL | The latest known version of a technology, a filter for technologies on an out-of-date version, and the product's end-of-life table. |
Cyber Threat Intelligence (CTI)
| Term | UI labels | Meaning |
|---|---|---|
| Compromised employee | COMPROMISED EMPLOYEE DATA / COMPROMISED EMPLOYEES | An employee account on your domains that was found in leaked credential data. See Investigate compromised employees. |
| Exposed credential | EXPOSED CREDENTIALS / CREDENTIAL / SHOW PASSWORD | One leaked login of an employee: the site or service, the account and the password. Passwords are masked until you reveal them with SHOW PASSWORD or the eye icon; revealing shows the password in plain text in your browser. See Review exposed credentials. |
| Credential state | STATE, for example ACTIVE · UNRESOLVED or ACTIVE · NEWLY DETECTED; IGNORED / RISK ACCEPTED / MARKED AS RESOLVED / MARKED AS FALSE POSITIVE; CHANGE STATE / CHANGE ALL STATES / REVERT STATE; SHOW INACTIVES | Where an exposed credential stands: ACTIVE or INACTIVE, with a detail, like an issue state. You can ignore a credential, accept its risk, or mark it as resolved or as a false positive, one at a time or in bulk; these states are inactive. REVERT STATE undoes a state you set. Inactive credentials are hidden until you tick SHOW INACTIVES. Client and payment credentials have a STATE too. See Change the state of exposed credentials. |
| Compromised client credential | COMPROMISED CLIENT CREDENTIALS / COMPROMISED CLIENTS | A login of one of your clients or customers that was found in breach data: the username and the site it belongs to. The list does not show passwords. See Review compromised client credentials. |
| Compromised payment credential | COMPROMISED PAYMENT CREDENTIALS / COMPROMISED PAYMENTS / PAN / CONFIDENCE / TIMES SEEN | A payment card that was found in breach data. The list shows the card number (PAN), CONFIDENCE, SOURCE, HACKISHNESS, TIMES SEEN, STATE and LAST SEEN. See Review compromised payment credentials. |
| Risk level (CTI) | CRITICAL / HIGH / MEDIUM / LOW | An employee's priority. The platform describes it as "Composite priority based on credential, role, and recency." |
| Password strength | VERY WEAK / WEAK / MEDIUM / STRONG / VERY STRONG; AVG STRENGTH SCORE | A five-level strength label for a leaked password. AVG STRENGTH SCORE is the average strength of an employee's passwords, out of 10. |
| Exposure velocity, trend | VELOCITY / TREND / EXPOSURE SPAN | Part of an employee's security profile, which shows "how long the exposure has run and whether the rate is rising." VELOCITY is in credentials per month (cred/mo); TREND shows the direction, for example STABLE. |
| Executive | Is Executive / EXECUTIVE | A flag you set on an employee. Executives are shown with a VIP icon. |
| Target service attributes | CORPORATE / MFA BY DEFAULT (ENFORCED / NOT ENFORCED) / RISK TIER | Properties of the site or service a leaked credential belongs to. |
| Hackishness | HACKISHNESS / Hackishness | A score shown on dark-web search results and on compromised payment records. |
| Dark-web source | SOURCE TYPE / SOURCE GROUP | Where a dark-web result comes from: the type, such as Discord, Onion or Telegram, and the group, such as Forums, Markets or Pastes. See Search the dark web. |
Brand Risk Protection (BRP)
| Term | UI labels | Meaning |
|---|---|---|
| Suspicious domain | SUSPICIOUS DOMAINS | A lookalike domain that your detection rules found. It waits for your review. See Review suspicious domains. |
| Fraudulent domain | FRAUDULENT DOMAINS / MARK AS FRAUDULENT / REMOVE FROM FRAUDULENT DOMAINS | A suspicious domain you confirmed as fraudulent. It moves to the FRAUDULENT DOMAINS tab. See Track fraudulent domains. |
| Ignored domain | IGNORED DOMAINS / UNDO IGNORE | A suspicious domain you dismissed. UNDO IGNORE restores it. See Restore ignored domains. |
| Risk Score (BRP) | RISK SCORE / INFORMATION / LOW / MEDIUM / HIGH / CRITICAL | A score from 0 to 100 for a detected domain, in bands: INFORMATION from 1 to 20, LOW above 20 up to 40, MEDIUM above 40 up to 60, HIGH above 60 up to 80, CRITICAL above 80. It is not on the same scale as the security score. |
| Indicators | DNS / DNS MX / SSL / HTTP | Four signals shown for a detected domain. An icon is dark when the signal is present and light when it is not. |
| Match type | Exact / Contains / Fuzzy / Fuzzy Contains / Confusable Exact / Confusable Contains / Confusable Fuzzy / Confusable Fuzzy Contains | How a detection rule matches its keyword against domain names. The default is Contains. |
| Keywords and TLDs | KEYWORD / HELPER KEYWORDS / NEGATIVE KEYWORDS / TLD MUST BE / TLD MUST NOT BE | The inputs of a BRP detection rule. KEYWORD is required and has at least 3 characters. TLD MUST BE and TLD MUST NOT BE take extensions from a fixed list. See Set up detection rules. |
| Start detection | From Now On / Include Past | Whether a new detection rule starts from now (From Now On, the default) or also covers the past (Include Past). It cannot be changed after the rule is created. |
| Ignored Assets (BRP) | Ignored Assets | A list in the BRP settings. Domains and subdomains on it never appear as detected, even when a detection rule matches them. |
Deep Search & Insights (DSI)
| Term | UI labels | Meaning |
|---|---|---|
| DSI | DEEP SEARCH & INSIGHTS / DSI | The sidebar group of search and research tools: DOMAIN INTELLIGENCE, DOMAIN SEARCH, VULNERABILITY INTELLIGENCE, VULNERABILITY SEARCH, INSTANT LOOKUP and FEEDS. Its breadcrumbs start with DSI, which is also its short name in the collapsed sidebar. See Deep Search & Insights (DSI). |
| Page tabs | Duplicate / New Tab to The Right / Close Tab / Close Other Tabs / Close Tabs to the Right | Browser-like tabs in Domain Search, Vulnerability Search, Instant Lookup and Dark Web Search. They are saved in your browser, so they survive a reload. |
| Reverse lookup | SEE OTHERS / Domain with same IP Address / Domain with same Name Server / Domain with same Mail Exchanger / Domain with same Email | Other domains that share an IP address, name server, mail server or registrant e-mail with the domain you are looking at. See Domain details and reverse lookups. |
| Instant lookup | LOOKUP / PARSED / RAW | A real-time query about a single target: WHOIS, DNS, SSL, webdata, technology, screenshot or port scan. PARSED and RAW switch between the formatted result and the JSON. See Run instant lookups. |
| Feeds | DAILY FEEDS / EXCLUSIVE FEEDS / CUSTOM FEEDS | Bulk data files you can download, such as the domains registered each day. See Download data feeds. |
Reports and Notifications
| Term | UI labels | Meaning |
|---|---|---|
| General report, CSV/JSON report | GENERAL REPORTS / CSV AND JSON REPORTS / .PDF | A general report is a PDF that the platform generates from your data. A CSV/JSON report downloads a whole dataset as a file. See Reports. |
| Reports history | REPORTS HISTORY | The copies of a report type generated so far, listed in the report's drawer. Each copy is a snapshot of your data at the time it was generated. |
| Scheduled report | SCHEDULED REPORTS / SCHEDULE A REPORT / SCHEDULE NEW REPORT | A PDF report that the platform generates daily, weekly or monthly and e-mails to the members you choose. See Schedule a report. |
| Notification rule | Notification Rules / Event Type / Rule Settings / Filters / Reviews / SCOPE | A rule that e-mails chosen members when an event happens. It has one event, optional filters, a frequency and at least one recipient. The rules list shows the event in the SCOPE column. See Notification Center. |
| Frequency | INSTANT / HOURLY / DAILY / WEEKLY / MONTHLY | How often a notification rule sends e-mails. Scheduled reports offer DAILY, WEEKLY and MONTHLY. |
| Delivery channel | Email / Slack / Webhook | How a rule's notifications are delivered. Only Email can be used; Slack and Webhook are shown but not available. |
| E-mail preferences, notification rules | SETTINGS › USER SETTINGS › Notifications vs NOTIFICATION CENTER | E-mail preferences choose which Deepinfo e-mails you receive: announcements, newsletter, product updates and training. Notification rules send alerts about your organization's data. See Choose which Deepinfo e-mails you receive. |