Skip to main content

Discover external assets

Use External Attack Surface Management (EASM) in the Veracode Platform to discover your organization's external attack surface and identify applications. Veracode helps reduce risk by automatically identifying key assets, such as domains, web applications, APIs, IP addresses, and certificates. It also provides a visual representation of discovered findings. EASM scans use domains, FQDNs, URLs, or IP addresses to perform a comprehensive assessment of your environment.

EASM scans use both passive and active crawling to discover known and unknown externally exposed assets. You can choose what to scan and when, based on your priorities or current requirements. EASM scans do not exploit vulnerabilities, submit forms, or perform intrusive actions. The scans simulate the behavior of a standard user browsing a web application.

EASM helps you discover and assess digital assets and touchpoints. These can include everything from integration and data exchange points, such as APIs, to a wide range of web applications. You can choose to scan your organization's entire digital footprint or target specific locations, business units, or individual assets.

Add items to workqueue​

Add IP addresses, IP ranges, domains, FQDNs, or URLs to the workqueue. You can add items manually or upload a CSV file that contains a list of items.

Before you begin:

  • You must have a UI user account with the Security Lead role.
  • The IP address, IP range, domain, FQDN, or URL that you add must not be behind a firewall.

To complete this task:

  1. Sign in to the Veracode Platform.

  2. Select Scans and Analysis > EASM.

  3. From the top-left corner of the screen, use the dropdown to select the required project.

  4. Select Admin & settings or the settings icon settings.

  5. Select Scan management.

  6. Select Workqueue.

  7. To add items, choose one of the following methods:

    • Add items manually: for Domain / URL, enter the IP address, IP range, domain, FQDN, or URL.
    • Upload a CSV file:
      1. Select Import CSV.
      2. To download the template, select Download an example file. Use this provided template to ensure proper formatting.
      3. Select Choose a .csv file and select a CSV file from File Explorer. The file can contain a list of domains, FQDNs, URLs, or IP addresses.
  8. Select Add to workqueue. The items appear in the Workqueue. Each item is assigned a trust score from 0 to 100. This score indicates how confident EASM is that the asset belongs to your organization. Items that are manually added are automatically assigned a trust score of 100.

Start a scan​

Scan your organization's assets using the items in the workqueue. EASM scans are first performed with the default settings. You can customize subsequent scans by changing the scan settings. You can also schedule a scan.

Before you begin:

  • You must add items to the workqueue.
  • You must have a Veracode account with the Security Lead role.

To complete this task:

  1. Sign in to the Veracode Platform.

  2. Select Scans and Analysis > EASM.

  3. From the top-left corner of the screen, use the dropdown to select the required project.

  4. At the top of the page, select the scan settings icon scan_settings_easm.png.

  5. Select Manual scans, then select one of the following scan options:

    • New scan: starts a new scan using the existing work queue. This option generates an updated set of scan results.
    • Update scan: updates the existing scan results.
    note
    • When you update an existing scan or start a new one for the same project, earlier results remain in the dashboard until the new scan is complete.
    • In the report, you might see duplicate vulnerabilities if the same component is found in multiple locations within an application.
    • Update scan is faster and more efficient as it scans only the modified items in the work queue.
    • Run new scans regularly to identify unknown assets and track remediation progress.
    • To permanently remove all work queue items and scan data, submit a support request to Veracode Technical Support.
  6. For the scan to provide a broader view by scanning all the assets related to your organization, select Deep Discovery. To scan a specific item within the same domain only, skip this option.

  7. To reset the workqueue, select Reset Workqueue. EASM scans only the assets that you select.

  8. Select Launch scan.

Monitor the scan progress​

Job history serves as an activity log and task monitoring center. Use it to track active tasks, investigate failures, and review current and previously executed jobs. It provides visibility into automated and background processes across the platform.

You can update scan work queue items while a scan is in progress.

Before you begin:

  • You must have a UI user account with the Security Lead role.

To complete this task:

  1. Sign in to the Veracode Platform.
  2. Select Scans and Analysis > EASM.
  3. From the top-left corner of the screen, use the dropdown to select the required project.
  4. Select Admin & settings or the settings icon.
  5. To review your scan progress, select Job history.
  6. When the status of the scan is Completed, you can review the scan items.

View and filter scan status​

Each scan appears in a tabular view that displays detailed metadata, diagnostics, status, duration, and, if applicable, the reason for failure. You can view whether a scan is complete, pending, or failed. You can also sort or filter jobs using the column headings or the search bar by job type, status, or other parameters.

The following table describes each column.

ColumnDescription
TypeSpecifies the type of task that was run.
- TRA: Discovery scan
- TRE: Export
- TRC: Comparison
TriggerIndicates the type of scan.
StatusDisplays the current state of the job. Possible values: Pending, Executing, Failed, Completed, Aborted, Abort Requested.
Created atShows the timestamp when the job was triggered.
Exited atShows the timestamp when the job completed or was stopped.
DurationShows how long the job took to complete.
FailureProvides context for troubleshooting if the job failed.
Abort requested atIndicates when a user manually requested to terminate the job, if applicable.
Delayed untilIndicates the start time for the job.
ArgsLists the parameters passed to the job during execution.

Troubleshoot failed jobs​

If a job fails, the following fields are key for diagnosing the issue:

  • Failure: provides context for troubleshooting and support teams. For example, 9 – License policy does not permit running this scan.
  • Args: shows the parameters passed when the job was executed. Useful for reproducing or understanding edge-case scenarios.

Share these values with the support or engineering team to help resolve recurring findings efficiently.

Review scan items​

After a scan completes, review the results in the Workqueue. A sortable, filterable table lists all discovered items as your new work queue.

Before you begin:

  • You must have a UI user account with the Security Lead role.

To complete this task:

  1. Sign in to the Veracode Platform.
  2. Select Scans and Analysis > EASM.
  3. From the top-left corner of the screen, use the dropdown to select the required project.
  4. Select Admin & settings or the settings icon.
  5. Select Scan management.
  6. Select Workqueue and review the items in the table.
  7. To view the trust score of an item, locate it in the table. In the Trust column, view the assigned score, which ranges from 1 to 100. The trust score indicates Veracode's confidence that the item belongs to your organization. Manually added items have a trust score of 100.
  8. Review the items to ensure that all discovered items are associated with your organization. Items with a trust score above 50 are automatically included in scan results, and items with a trust score of 50 or lower are excluded. Use sort and filter to review items with a trust score above 50. Toggle off any items that don't belong to your organization. Then, check items below 50 and toggle on those that belong to your organization. Update scans as needed.
  9. To permanently remove items that are not needed, at the right end of the table, select the delete icon delete_easm.png. However, the items might reappear in the workqueue if they are rediscovered in future scans.
  10. To manually override the inclusion of an item in the scan results, locate it in the table. In the Used column, toggle the switch. After making manual changes, update the current test. To view insights from the scan results, go to the Findings.

View and filter scan items​

You can sort and filter items, or use the search bar to filter by name, type, or finding category.

The following table describes each column.

ColumnDescription
ItemThe identifier of the discovered asset, such as a domain name or IP address.
TypeThe classification of the item, such as a domain or IP address.
Finding from typeThe method used to discover the item.
Finding fromThe seed item from which the discovery was made.
Finding from detailsThe evidence or reasoning behind the discovery.
StatusThe current state of the item. Possible values: Done, In Progress, Pending, or Ignored.
Status detailsReal-time updates on discovery or scan results.
TrustThe confidence level that the asset belongs to the organization. Items below 50% are excluded by default.
UsedToggle to include or exclude the item from the current scan run.
WhoisWHOIS information for the discovered asset.
DeepIf a Deep Discovery scan ran from that domain, the value is Yes. If a Static scan ran, the value is No.
DurationThe time it took to discover the item.
Created atThe date and time when the discovery started.
Updated atThe date and time when the item was last updated.
CommentA field to add notes or justifications for specific items.

Schedule a scan​

Automatically schedule recurring scans to ensure continuous and up-to-date coverage. Define frequency and timing to run scans without manual intervention and maintain consistent monitoring.

Before you begin:

  • You must have a UI user account with the Security Lead role.

To complete this task:

  1. Sign in to the Veracode Platform.
  2. Select Scans and Analysis > EASM.
  3. From the top-left corner of the screen, use the dropdown to select the required project.
  4. At the top of the page, select the scan settings icon.
  5. Select Automatic New Scan.
  6. To configure an automatic scan, turn on Next scheduled for.
  7. Select the frequency for scans:
    • Weekly: select this to run scans weekly. To complete this task:
      1. In the scheduling options, select Weekly.
      2. To select the preferred day of the week, open the Day of week dropdown and select the required day.
      3. Use the time selector to specify when the scan should run.
      4. For the scan to provide a broader view by scanning all the assets related to your organization, select Deep Discovery. To scan a specific item within the same domain only, skip this option.
      5. To reset the workqueue, select Reset Workqueue. EASM scans only the assets that you select.
    • Monthly: select this to run scans monthly. To complete this task:
      1. In the scheduling options, select Monthly.
      2. To select the preferred month of the year, open the Day of month dropdown and select the required month.
      3. Use the time selector to specify when the scan should run.
      4. For the scan to provide a broader view by scanning all the assets related to your organization, select Deep Discovery. To scan a specific item within the same domain only, skip this option.
      5. To reset the workqueue, select Reset Workqueue. EASM scans only the assets that you select.
    • Quarterly: select this to run scans quarterly. To complete this task:
      1. In the scheduling options, select Quarterly.
      2. Select the preferred Month in quarter. To select the preferred day of the month, open the Day of month dropdown and select the required day.
      3. Use the time selector to specify when the scan should run.
      4. For the scan to provide a broader view by scanning all the assets related to your organization, select Deep Discovery. To scan a specific item within the same domain only, skip this option.
      5. To reset the workqueue, select Reset Workqueue. EASM scans only the assets that you select.
    • Yearly: select this to run scans yearly. To complete this task:
      1. In the scheduling options, select Yearly.
      2. Select the preferred Month. To select the preferred day of the month, open the Day of month dropdown and select the required day.
      3. Use the time selector to specify when the scan should run.
      4. For the scan to provide a broader view by scanning all the assets related to your organization, select Deep Discovery. To scan a specific item within the same domain only, skip this option.
      5. To reset the workqueue, select Reset Workqueue. EASM scans only the assets that you select.
  8. Select Save and Schedule.

Stop a scan​

You might choose to stop a scan for several reasons, including typographical errors and incorrect domain entries. In some cases, the scan might return a high number of false positives, such as domains that are no longer in scope. This can happen when an organization divests a subsidiary but hasn't updated DNS records or related configurations.

Before you begin:

  • You must have a UI user account with the Security Lead role.
  • The status of the scan must be Pending or In Progress.

To complete this task:

  1. Sign in to the Veracode Platform.
  2. Select Scans and Analysis > EASM.
  3. From the top-left corner of the screen, use the dropdown to select the required project.
  4. At the top of the page, select the scan settings icon.
  5. To stop a scan that is in the Starting or Executing status, select Abort.

Best practices​

The ideal scan cadence depends on your organization's size, risk profile, and how often you remediate findings. Run scans regularly to detect new or changed assets, identify misconfigurations, and monitor remediation progress.

The following table provides best practice recommendations.

Risk levelRecommended scan frequency
High risk (e.g., financial services, healthcare, technology companies, or environments with frequent changes)Run a full scan monthly. Run targeted scans daily or weekly for critical areas.
Moderate risk (most medium-sized organizations)Run a full scan monthly.
Low risk (small, stable organizations with minimal internet-facing assets)Run a scan every one to three months.