Skip to main content

Modify scan settings

You can configure additional scan settings. Use scan parameters to fine-tune and adjust the scan scope based on your requirements.

Prerequisites​

  • You must have a Veracode account with the Security Lead role.

Modify scan settings​

You can adjust scan parameters to fine-tune your scan scope and behavior.

To complete this task:

  1. Sign in to the Veracode Platform.

  2. Select Scans and Analysis > EASM.

  3. From the top-left corner of the screen, use the dropdown to select the required project.

  4. Select Admin & settings or the settings icon settings.png.

  5. Select Scan management.

  6. Select Parameters. You can adjust the scan settings by selecting options in the following categories:

    • Deep Discovery: control how extensively the scan expands beyond the original items. You can turn on passive discovery of related domains and IP addresses. Available settings:

      • Blacklisted IP Ranges
      • Enable IP Range Finding
      • Enable Redirect To
      • Black Listed Findings
      • Enable Other Countries
      • Enable Certificate DB Check
      • Enable Google Analytics
      • Enable Reverse Whois on Company
      • Enable Reverse Whois on Domain
      • Black Listed Company Names
      • Enable Reverse MX Lookup
      • Enable Reverse NS Lookup
      • Enable ASN Check
      • Enable Artificial Intelligence
    • Discovery: specify how the scan uses certificates, WHOIS records, and DNS data during asset identification. You can also include or exclude external service lookups. These settings apply to both Static and Deep Discovery scans. Available settings:

      • Enable Responsive IP Search
      • Enable Subdomain Finder
      • HTTP Ports
      • Port Scanning Black Listed Ips
      • HTTPS Ports
      • Enable Port Scanning
      • White Listed IP Locations
    • Crawling: control how the scan handles web crawling, including depth, timeouts, and limits. These settings are useful for applications and URLs with complex structures. They apply to both Static and Deep Discovery scans. Available settings:

      • Enable Fast http Port Checking
      • Max Concurrent Crawling
      • Render Delay
      • Time To Render
      • Page Timeout
      • Max Number of Pages
      • Enable Number of Pages Per Application
      • Find Application From Certificates
      • Enable Sitemap Check
      • Ignore HTTP Forbidden Status
    note

    Adjust scan settings carefully. These settings affect the scope and duration of the scan. Use Deep Discovery options with caution to avoid identifying assets that don't belong to your organization.

  7. To reset the scan settings to their default values, select Reset to defaults in the top-right corner of the screen.

You can find a detailed explanation for each of the following settings.

  • Blacklisted IP Ranges: excludes the listed IP ranges from IP range discovery.

  • Black Listed Company Names: excludes findings from specified company names.

  • Black Listed Findings: excludes findings that match specific regular expressions (regex patterns). You can also use this feature in reverse mode.

  • Enable Artificial Intelligence: uses AI techniques, such as image recognition, to improve trust level accuracy on discovered domains. (Default value: True)

  • Enable ASN Check: when applicable, collects domains that share an ASN with other trusted domains.

  • Enable Certificate DB Check: checks external certificate data sources to discover additional domains. (Default value: True)

  • Enable Fast http Port Checking: turns on port scanning to check for web applications. Turning off this option prevents potential blocking by firewalls but slows down scanning. (Default value: True)

  • Enable Google Analytics: uses reverse techniques on Google Analytics digital IDs. (Default value: True)

  • Enable IP Range Finding: discovers IP ranges based on trusted company names. Requires at least one entry in the work queue. (Default value: True)

  • Enable Number of Pages Per Application: applies the "Max Number of Pages" setting to each application individually instead of to the entire project. (Default value: True)

  • Enable Other Countries: discovers domains with any top-level domain (TLD). If turned off, only TLDs already present in the work queue are used. (Default value: True)

  • Enable Port Scanning: scans all discovered IP addresses for open ports. (Default value: False)

  • Enable Redirect To: detects URLs that redirect to discovered domains with a trust level of 100%. (Default value: True)

  • Enable Responsive IP Search: identifies applications that respond to HTTP or HTTPS requests by IP address instead of by FQDN. (Default value: True)

  • Enable Reverse MX Lookup: collects domains found in the organization's MX database.

  • Enable Reverse NS Lookup: collects domains found in the organization's NS database.

  • Enable Reverse Whois on Company: finds domains using reverse WHOIS lookups based on company name. (Default value: True)

  • Enable Reverse Whois on Domain: finds domains using reverse WHOIS lookups where a domain used its email address for registration.

  • Enable Sitemap Check: attempts to locate and crawl sitemap files to discover more URLs. (Default value: True)

  • Enable Subdomain Finder: discovers all subdomains related to identified domains.

  • Find Application From Certificates: discovers new applications from certificate data found in known applications, using Subject Alternative Name (SAN) attributes. (Default value: True)

  • HTTP Ports: specifies HTTP ports for web application discovery. You can add additional ports to find hidden interfaces. (Default value: 80,8080)

  • HTTPS Ports: specifies HTTPS ports for web application discovery. You can add additional ports to find hidden interfaces. (Default value: 443,8443)

  • Ignore HTTP Forbidden Status: the scanner performs a brief initial connection before rendering a webpage. Some websites detect this as automated activity and return a "Forbidden" response. When this option is turned on, the scanner continues and attempts to render the page even if it receives a Forbidden status.

  • Max Concurrent Crawling: sets the number of web pages crawled in parallel. Lower values reduce the risk of being blacklisted or blocked. (Default value: 20)

  • Max Number of Pages: sets the maximum number of pages the scanner can crawl. Applies to the entire project if you turn off Enable Number of Pages Per Application. (Default value: 60)

  • Page Timeout: sets the timeout duration for HTTP connections, in seconds. (Default value: 10)

  • Port Scanning Black Listed Ips: excludes specified IP addresses from port scanning. (Default value: none)

  • Render Delay: adds a delay (in seconds) after a page loads to allow full content retrieval, especially for slower applications. (Default value: 5)

  • Time To Render: sets the maximum time (in seconds) the scanner waits for a page to fully load in render mode. (Default value: 60)

  • White Listed IP Locations: includes only specified IP locations in the discovery process.

Create a business unit​

You can create a business unit to view assets relevant to teams, subsidiaries, or clients. Business units support a hierarchical structure with a maximum of two levels (root level and sub-units).

note

Business units in EASM are not linked to the business units in the Veracode Platform.

To complete this task:

  1. Sign in to the Veracode Platform.
  2. Select Scans and Analysis > EASM.
  3. From the top-left corner of the screen, use the dropdown to select the required project.
  4. Select Admin & settings or the settings icon.
  5. Select the Business Units tab.
  6. For Add a business unit, enter a name for the new business unit.
  7. Select the dropdown and choose a parent unit. You can select Root level to create a top-level business unit, or select an existing root unit to create a sub-unit under it.
    note

    You can create sub-units only under a root unit (maximum two levels allowed in the hierarchy).

  8. Select Add.

Delete a business unit​

You can delete business units that you no longer require.

To complete this task:

  1. Sign in to the Veracode Platform.
  2. Select Scans and Analysis > EASM.
  3. From the top-left corner of the screen, use the dropdown to select the required project.
  4. Select Admin & settings or the settings icon.
  5. Select the Business Units tab.
  6. Next to the business unit you want to delete, select Delete.
  7. Select Confirm.

Assign domains to business units​

You can assign domains to specific business units to organize your assets by team, subsidiary, or client. You can assign domains individually or in bulk.

To complete this task:

  1. Sign in to the Veracode Platform.
  2. Select Scans and Analysis > EASM.
  3. From the top-left corner of the screen, use the dropdown to select the required project.
  4. Select Admin & settings or the settings icon.
  5. Select the Business Units tab.
  6. In the Domains section on the right, select the checkbox next to one or more domains to assign them to a business unit.
  7. Select the business unit you want to assign the selected domains to.
  8. Select Assign selected.
  9. To assign individual domains, use the Business Unit dropdown in each row to select a different business unit for that domain.