Discover external assets
Use External Attack Surface Management (EASM) in the Veracode Platform to discover your organization's external attack surface and identify applications. Veracode helps reduce risk by automatically identifying key assets, such as domains, web applications, APIs, IP addresses, and certificates. It also provides a visual representation of discovered findings. EASM scans use domains, FQDNs, URLs, or IP addresses to perform a comprehensive assessment of your environment.
EASM scans use both passive and active crawling to discover known and unknown externally exposed assets. You can choose what to scan and when, based on your priorities or current requirements. EASM scans do not exploit vulnerabilities, submit forms, or perform intrusive actions. The scans simulate the behavior of a standard user browsing a web application.
EASM helps you discover and assess digital assets and touchpoints. These can include everything from integration and data exchange points, such as APIs, to a wide range of web applications. You can choose to scan your organization's entire digital footprint or target specific locations, business units, or individual assets.
Add items to workqueue
Add IP addresses, IP ranges, domains, FQDNs, or URLs to the workqueue. You can add items manually or upload a CSV file that contains a list of items.
Before you begin:
- You must have a UI user account with the Security Lead role.
- The IP address, IP range, domain, FQDN, or URL that you add must not be behind a firewall.
To complete this task:
-
Sign in to the Veracode Platform.
-
Select Scans and Analysis > EASM.
-
From the top-left corner of the screen, use the dropdown to select the required project.
-
Select Admin & settings or the settings icon
.
-
Select Scan management.
-
Select Workqueue.
-
To add items, choose one of the following methods:
- Add items manually: for Domain / URL, enter the IP address, IP range, domain, FQDN, or URL.
- Upload a CSV file:
- Select Import CSV.
- To download the template, select Download an example file. Use this provided template to ensure proper formatting.
- Select Choose a .csv file and select a CSV file from File Explorer. The file can contain a list of domains, FQDNs, URLs, or IP addresses.
-
Select Add to workqueue. The items appear in the Workqueue. Each item is assigned a trust score from
0to100. This score indicates how confident EASM is that the asset belongs to your organization. Items that are manually added are automatically assigned a trust score of100.
Start a scan
Scan your organization's assets using the items in the workqueue. EASM scans are first performed with the default settings. You can customize subsequent scans by changing the scan settings. You can also schedule a scan.
Before you begin:
To complete this task:
-
Sign in to the Veracode Platform.
-
Select Scans and Analysis > EASM.
-
From the top-left corner of the screen, use the dropdown to select the required project.
-
At the top of the page, select the scan settings icon
.
-
Select Manual scans, then select one of the following scan options:
- New scan: starts a new scan using the existing work queue. This option generates an updated set of scan results.
- Update scan: updates the existing scan results.
note- When you update an existing scan or start a new one for the same project, earlier results remain in the dashboard until the new scan is complete.
- In the report, you might see duplicate vulnerabilities if the same component is found in multiple locations within an application.
- Update scan is faster and more efficient as it scans only the modified items in the work queue.
- Run new scans regularly to identify unknown assets and track remediation progress.
- To permanently remove all work queue items and scan data, submit a support request to Veracode Technical Support.
-
For the scan to provide a broader view by scanning all the assets related to your organization, select Deep Discovery. To scan a specific item within the same domain only, skip this option.
-
To reset the workqueue, select Reset Workqueue. EASM scans only the assets that you select.
-
Select Launch scan.
Monitor the scan progress
Job history serves as an activity log and task monitoring center. Use it to track active tasks, investigate failures, and review current and previously executed jobs. It provides visibility into automated and background processes across the platform.
You can update scan work queue items while a scan is in progress.
Before you begin:
- You must have a UI user account with the Security Lead role.
To complete this task:
- Sign in to the Veracode Platform.
- Select Scans and Analysis > EASM.
- From the top-left corner of the screen, use the dropdown to select the required project.
- Select Admin & settings or the settings icon.
- To review your scan progress, select Job history.
- When the status of the scan is Completed, you can review the scan items.
View and filter scan status
Each scan appears in a tabular view that displays detailed metadata, diagnostics, status, duration, and, if applicable, the reason for failure. You can view whether a scan is complete, pending, or failed. You can also sort or filter jobs using the column headings or the search bar by job type, status, or other parameters.
The following table describes each column.
| Column | Description |
|---|---|
| Type | Specifies the type of task that was run. - TRA: Discovery scan- TRE: Export- TRC: Comparison |
| Trigger | Indicates the type of scan. |
| Status | Displays the current state of the job. Possible values: Pending, Executing, Failed, Completed, Aborted, Abort Requested. |
| Created at | Shows the timestamp when the job was triggered. |
| Exited at | Shows the timestamp when the job completed or was stopped. |
| Duration | Shows how long the job took to complete. |
| Failure | Provides context for troubleshooting if the job failed. |
| Abort requested at | Indicates when a user manually requested to terminate the job, if applicable. |
| Delayed until | Indicates the start time for the job. |
| Args | Lists the parameters passed to the job during execution. |
Troubleshoot failed jobs
If a job fails, the following fields are key for diagnosing the issue:
- Failure: provides context for troubleshooting and support teams. For example,
9 – License policy does not permit running this scan. - Args: shows the parameters passed when the job was executed. Useful for reproducing or understanding edge-case scenarios.
Share these values with the support or engineering team to help resolve recurring findings efficiently.
Review scan items
After a scan completes, review the results in the Workqueue. A sortable, filterable table lists all discovered items as your new work queue.
Before you begin:
- You must have a UI user account with the Security Lead role.
To complete this task:
- Sign in to the Veracode Platform.
- Select Scans and Analysis > EASM.
- From the top-left corner of the screen, use the dropdown to select the required project.
- Select Admin & settings or the settings icon.
- Select Scan management.
- Select Workqueue and review the items in the table.
- To view the trust score of an item, locate it in the table. In the Trust column, view the assigned score, which ranges from
1to100. The trust score indicates Veracode's confidence that the item belongs to your organization. Manually added items have a trust score of100. - Review the items to ensure that all discovered items are associated with your organization. Items with a trust score above
50are automatically included in scan results, and items with a trust score of50or lower are excluded. Use sort and filter to review items with a trust score above50. Toggle off any items that don't belong to your organization. Then, check items below50and toggle on those that belong to your organization. Update scans as needed. - To permanently remove items that are not needed, at the right end of the table, select the delete icon
. However, the items might reappear in the workqueue if they are rediscovered in future scans.
- To manually override the inclusion of an item in the scan results, locate it in the table. In the Used column, toggle the switch. After making manual changes, update the current test. To view insights from the scan results, go to the Findings.
View and filter scan items
You can sort and filter items, or use the search bar to filter by name, type, or finding category.
The following table describes each column.
| Column | Description |
|---|---|
| Item | The identifier of the discovered asset, such as a domain name or IP address. |
| Type | The classification of the item, such as a domain or IP address. |
| Finding from type | The method used to discover the item. |
| Finding from | The seed item from which the discovery was made. |
| Finding from details | The evidence or reasoning behind the discovery. |
| Status | The current state of the item. Possible values: Done, In Progress, Pending, or Ignored. |
| Status details | Real-time updates on discovery or scan results. |
| Trust | The confidence level that the asset belongs to the organization. Items below 50% are excluded by default. |
| Used | Toggle to include or exclude the item from the current scan run. |
| Whois | WHOIS information for the discovered asset. |
| Deep | If a Deep Discovery scan ran from that domain, the value is Yes. If a Static scan ran, the value is No. |
| Duration | The time it took to discover the item. |
| Created at | The date and time when the discovery started. |
| Updated at | The date and time when the item was last updated. |
| Comment | A field to add notes or justifications for specific items. |
Schedule a scan
Automatically schedule recurring scans to ensure continuous and up-to-date coverage. Define frequency and timing to run scans without manual intervention and maintain consistent monitoring.
Before you begin:
- You must have a UI user account with the Security Lead role.
To complete this task:
- Sign in to the Veracode Platform.
- Select Scans and Analysis > EASM.
- From the top-left corner of the screen, use the dropdown to select the required project.
- At the top of the page, select the scan settings icon.
- Select Automatic New Scan.
- To configure an automatic scan, turn on Next scheduled for.
- Select the frequency for scans:
- Weekly: select this to run scans weekly. To complete this task:
- In the scheduling options, select Weekly.
- To select the preferred day of the week, open the Day of week dropdown and select the required day.
- Use the time selector to specify when the scan should run.
- For the scan to provide a broader view by scanning all the assets related to your organization, select Deep Discovery. To scan a specific item within the same domain only, skip this option.
- To reset the workqueue, select Reset Workqueue. EASM scans only the assets that you select.
- Monthly: select this to run scans monthly. To complete this task:
- In the scheduling options, select Monthly.
- To select the preferred month of the year, open the Day of month dropdown and select the required month.
- Use the time selector to specify when the scan should run.
- For the scan to provide a broader view by scanning all the assets related to your organization, select Deep Discovery. To scan a specific item within the same domain only, skip this option.
- To reset the workqueue, select Reset Workqueue. EASM scans only the assets that you select.
- Quarterly: select this to run scans quarterly. To complete this task:
- In the scheduling options, select Quarterly.
- Select the preferred Month in quarter. To select the preferred day of the month, open the Day of month dropdown and select the required day.
- Use the time selector to specify when the scan should run.
- For the scan to provide a broader view by scanning all the assets related to your organization, select Deep Discovery. To scan a specific item within the same domain only, skip this option.
- To reset the workqueue, select Reset Workqueue. EASM scans only the assets that you select.
- Yearly: select this to run scans yearly. To complete this task:
- In the scheduling options, select Yearly.
- Select the preferred Month. To select the preferred day of the month, open the Day of month dropdown and select the required day.
- Use the time selector to specify when the scan should run.
- For the scan to provide a broader view by scanning all the assets related to your organization, select Deep Discovery. To scan a specific item within the same domain only, skip this option.
- To reset the workqueue, select Reset Workqueue. EASM scans only the assets that you select.
- Weekly: select this to run scans weekly. To complete this task:
- Select Save and Schedule.
Stop a scan
You might choose to stop a scan for several reasons, including typographical errors and incorrect domain entries. In some cases, the scan might return a high number of false positives, such as domains that are no longer in scope. This can happen when an organization divests a subsidiary but hasn't updated DNS records or related configurations.
Before you begin:
- You must have a UI user account with the Security Lead role.
- The status of the scan must be Pending or In Progress.
To complete this task:
- Sign in to the Veracode Platform.
- Select Scans and Analysis > EASM.
- From the top-left corner of the screen, use the dropdown to select the required project.
- At the top of the page, select the scan settings icon.
- To stop a scan that is in the Starting or Executing status, select Abort.
Best practices
The ideal scan cadence depends on your organization's size, risk profile, and how often you remediate findings. Run scans regularly to detect new or changed assets, identify misconfigurations, and monitor remediation progress.
The following table provides best practice recommendations.
| Risk level | Recommended scan frequency |
|---|---|
| High risk (e.g., financial services, healthcare, technology companies, or environments with frequent changes) | Run a full scan monthly. Run targeted scans daily or weekly for critical areas. |
| Moderate risk (most medium-sized organizations) | Run a full scan monthly. |
| Low risk (small, stable organizations with minimal internet-facing assets) | Run a scan every one to three months. |