Skip to main content
Method · Discovery and scope

Testing the inventory discovery found

Every assessment begins from an inventory. One inventory was written down by people, at a moment that has since passed; the other is whatever answers when somebody asks. Discovery produces the second one, and the interesting part of it is the part nobody expected. What happens to that part — who reads it, who decides on it, and when — is the whole of this article.

Yash K · · How it is done · about 10 min

Two lists

Every assessment starts from an inventory. The question is which one.

An asset register records what an organisation decided to run. A perimeter records what it ended up running. Those are different documents, and only one of them answers when you ask it a question.

Hand a tester a list and you have set the boundary of what the test can find before the test has started. Everything inside the list gets worked properly; everything outside it is, for the purposes of that report, not there. The report will be accurate and the conclusion will be narrow, and the narrowness will not be visible in the document — a clean result against a list reads exactly like a clean result against an estate. Working the perimeter out instead changes what the boundary is drawn from. The address ranges an organisation announces are routing data. The names resolving into those ranges are public. What actually answers on a given address is a question only asking can settle, and it is the one that produces hosts no list has ever carried, because a live service at an address that no name has ever pointed at never had a way of reaching anybody’s inventory. Discovery run that way returns an inventory of its own, and the two inventories do not match. The part where they fail to match is not noise to be tidied up before the real work begins. It is the first result of the engagement.

The gap

Five ordinary ways a register and a perimeter come apart

None of these is negligence, and none of them is interesting on its own. They are the mechanics of an estate that people work in, and together they are why the second list is never a copy of the first.

Provisioning

A change that outlived its ticket

Something was stood up to get a piece of work over the line, with an end date that everybody understood at the time and nobody wrote down. The work finished. The ticket closed. The host is still answering, and the register has no row for it because the row was never meant to be permanent.

Acquisition

An estate that arrived with somebody else’s conventions

A second organisation’s ranges, naming and provisioning habits are folded into the first. The register gets the parts that were documented on the other side, in the form the other side documented them. What was informal there stays informal here.

Records

A record that outlived the thing it described

The register is a statement of belief about what exists. A decommissioning updates the belief; it does not always update what the outside world can still see, and the two then disagree without anybody being told they disagree.

Intent

A system nobody decided to publish

Pre-production and internal systems get their reachability from a configuration rather than from a decision. Nobody chose to put them where a stranger can reach them, which is precisely why nobody entered them on a list of things a stranger can reach.

Ownership

A host whose owner moved teams

The system is documented, running and known to somebody. That somebody has since changed roles. The register still has the row; what it no longer has is a person who would notice the row being wrong.

Measured

How big a scope actually turns out to be

One figure, from our own engagement archive. The spread is the point, and it is wide enough that scope size is a question to settle rather than an assumption to carry.

Targets per engagement, across our engagement archive As of 2026-09-15
  • The number of targets in a single engagement runs from 1 to 266.
  • The median is 4. Half of all engagements are four targets or fewer, and that half is the ordinary case rather than the small case.
  • The distance between the median and the top of the range is what makes scoping a decision rather than a formality. A scoping model built for four targets and one built for 266 are not the same model, and an estate does not announce in advance which of the two it is.
  • The count is of targets that were authorised and worked. It is not a count of what discovery returned, which is a different number and is not measured here.

Deliberately excluded

  • It is a spread from our own engagement archive rather than an industry figure, and it says nothing about anybody else’s work.
  • It is a count of targets, not a price ladder. One scan is one application or one target at $500, and anything wider than a single target is scoped rather than listed.
  • Physical, hardware and wireless testing is out of scope for the platform in every class, so nothing of that kind appears in the count.

Two inputs

Working from the list you were handed, and working from what answers

Two different inputs to the same assessment. They produce results that are evidence of different things.

The questionScoped from the asset registerScoped from what answers
How the perimeter is established It is inherited. The assessment knows what the register knows, including the things the register has quietly stopped knowing. From the ranges you announce, the names resolving into them and the services that respond — reconciled, and put in front of you as a proposal.
What happens to a host nobody listed Nothing. It is not in the scope, so it is not in the report, and the next engagement starts from the same list again. It is returned with everything else and becomes a decision you take, in writing, before anything on it is touched.
Who decides what gets tested Whoever maintained the register, at whatever moment they last touched it, without this question in front of them. You do, at scope sign-off, with the discovered list in front of you.
What a clean result proves That nothing on the list was exploitable. Whether the list was the estate is a separate question, and the report is not able to answer it. That nothing inside the authorised scope was exploitable, where that scope was drawn from what answered rather than from what was remembered.
What the next run starts from The register again, in whatever state it has reached by then. The scope you authorised, plus whatever discovery has returned since — proposed the same way rather than tested on the strength of the earlier sign-off.
What the report is evidence of The condition of the list on the day it was worked. The condition of the estate as it answered on the day it was worked.

How the perimeter is established

Scoped from the asset register
It is inherited. The assessment knows what the register knows, including the things the register has quietly stopped knowing.
Scoped from what answers
From the ranges you announce, the names resolving into them and the services that respond — reconciled, and put in front of you as a proposal.

What happens to a host nobody listed

Scoped from the asset register
Nothing. It is not in the scope, so it is not in the report, and the next engagement starts from the same list again.
Scoped from what answers
It is returned with everything else and becomes a decision you take, in writing, before anything on it is touched.

Who decides what gets tested

Scoped from the asset register
Whoever maintained the register, at whatever moment they last touched it, without this question in front of them.
Scoped from what answers
You do, at scope sign-off, with the discovered list in front of you.

What a clean result proves

Scoped from the asset register
That nothing on the list was exploitable. Whether the list was the estate is a separate question, and the report is not able to answer it.
Scoped from what answers
That nothing inside the authorised scope was exploitable, where that scope was drawn from what answered rather than from what was remembered.

What the next run starts from

Scoped from the asset register
The register again, in whatever state it has reached by then.
Scoped from what answers
The scope you authorised, plus whatever discovery has returned since — proposed the same way rather than tested on the strength of the earlier sign-off.

What the report is evidence of

Scoped from the asset register
The condition of the list on the day it was worked.
Scoped from what answers
The condition of the estate as it answered on the day it was worked.

The proposal

What the scope proposal asks you, host by host

Discovery proposes; the authorisation is yours. In the fully autonomous model that sign-off is the last human action of the engagement, which is exactly why the proposal is written to be read rather than skimmed.

01 On both lists

A host you already knew you had

What the proposal says
The address, the name that resolved to it, and the service answering on it — set beside what you supplied, so the two can be matched rather than assumed to agree.
The decision that is yours
Whether it is in. Agreement on this half is what the rest of the proposal gets measured against.
What runs afterwards
Scanning and exploitation inside the authorised scope, without checking in again. That is what the sign-off bought.
02 On one list only

A host the register does not have

What the proposal says
The same fields, plus the fact that nothing you supplied accounts for it. It is presented as a question. It is not presented as a finding, because at this stage nothing on it has been touched.
The decision that is yours
In, out, or held until you have established whose it is. Holding it is a real answer and it is recorded as one.
What runs afterwards
Only what you authorised. What was refused is as legible in the audit trail afterwards as what was allowed.

States

Four things that can happen to a host discovery returned

The unexpected part of the inventory is not a finding and it is not a to-do list. It is a set of decisions, and every one of them has a state that somebody can point at later.

Four things that can happen to a host discovery returned
StateWhat it meansWhat follows
Proposed Returned by discovery and put in front of you with the address, the name if it has one, and what answered on it. Nothing on it has been touched and nothing will be. Waits for your decision.
Authorised You signed it into the scope. From that point it is worked like every other target in that scope, against the same standards, and anything it produces arrives with the request, the response, the steps that reproduce it, a CVSS v4.0 vector and a CWE. Tested.
Held You have not decided, and until you do it stays an open question rather than becoming a gap. A held host is recorded as held, so the question survives into the next run instead of expiring with this one. Not tested. Stays on the record.
Not yours to authorise Terminal An address inside a range you announce that somebody else operates. Authorisation has to come from whoever is able to give it, and nobody else’s signature substitutes for that. Excluded. Nothing is tested on somebody else’s authority.
Key
  • Returned by discovery, awaiting your decision
  • Inside the scope you signed off
  • Open, and recorded as open
  • Outside the engagement until an authorisation covers it
  • TerminalNo state follows this one

The difference

Assessing what you remember, or assessing what you run

The choice here is not between more testing and less of it. It is a choice about which document the test takes as its input, and it is made once, at scoping, before anybody has written a test case. Take the register and the assessment inherits every assumption inside it, including the assumptions that stopped being true. Take what answers and the assessment starts from a list that was produced by asking, then hands that list back for a decision that belongs to you rather than to the run — which is why the proposal comes before the testing and not after it. A register that disagrees with a perimeter is telling you something specific, and reconciling the two is work worth doing for its own sake. What changes is what the report at the end is evidence of. One of them describes a list. The other describes an estate.

See what discovery returns before you decide what to test

One scan is one application or one target, and the entry price is $500. A perimeter is more than one target, so it is scoped against what discovery returns.