Assets
Viewing and managing the assets that make up your attack surface
The Assets page is where you can see everything Ethiack's attack surface management capabilities have identified for your organization. For each asset you can see which tests it is in scope for, its current risk level, and how important it is to your organization.
Asset information at a glance
| Field | Description |
|---|---|
| Asset | The asset value, e.g. admin.acme.org |
| Risk level | The overall risk associated with the asset based on its findings |
| Importance | How business-critical the asset is to your organization |
| Tests | The tests this asset is currently in scope for |
Sorting assets
You can sort assets by the following criteria:
- Risk (default showing highest risk first)
- Value
- Date added
- Importance
Filtering assets
By Asset Properties
You can filter assets by querying their properties directly:
- Value — search by the asset identifier, e.g.
admin.acme.org - Ports — filter by open ports detected on the asset
- Services and technologies — filter by services or technologies identified on the asset
Filters can be combined using AND or OR logic, giving you precise control over what you see. For example, you can find all assets running a specific technology on a specific port, or any asset matching either of two different values.
By Test
You can also filter the asset list by test to see only the assets that are in scope for a particular engagement.
Bulk editing
To make changes across multiple assets at once:
- Select the assets you want to update individually, or use the select-all option at the top of the list.
- Choose one of the available bulk actions:
- Add to or remove from a test scope — control which tests the selected assets are part of
- Update importance level — adjust how business-critical the assets are considered
- Delete — remove the selected assets from your surface