What it shows

Attack surface page — the Targets / Applications / Certificates tabs and Graph view, the Export Targets button, the Tags / Target type / Exploit known filters, and a target row with its type, severity, and WAF badges.

The page is organized into tabs, each with a count:

  • Targets — the assets you monitor, with the number of services detected on each.
  • Applications — web applications discovered across your targets.
  • Certificates — SSL/TLS certificates found on your assets, so you can spot expiring or misconfigured ones.
  • Graph — a visual map of how your assets relate to each other.

The Last checked timestamp in the top-right shows when this picture was last refreshed.

Reading a row

Each row summarizes one asset:

  • Its name and type (Infrastructure or Web Application)
  • The number of services detected on it
  • Its worst current severity (e.g. MEDIUM)
  • A WAF badge when a web application firewall or CDN sits in front of it
  • When it was last scanned

Expand a row to drill into the detected services and findings.

Filtering

  • Tags — narrow the view to a group of assets.
  • Target type — Infrastructure or Web Application.
  • Exploit known — show only assets carrying an issue with a known public exploit. This is the fastest way to find where real, weaponized risk sits.

Exporting

Click Export Targets to download your attack surface inventory for reporting, audits, or sharing with your team.

Keeping it complete

When Discovery finds new hosts, a banner at the top links you straight to Discovery to review and add them. Adding discovered hosts as targets is what keeps the attack surface map complete — anything you don't monitor is a blind spot.

What's next