Testing the inventory discovery found
Every assessment begins from an inventory. One inventory was written down by people, at a moment that has since passed; the other is whatever answers when somebody asks. Discovery produces the second one, and the interesting part of it is the part nobody expected. What happens to that part — who reads it, who decides on it, and when — is the whole of this article.
Yash K · · How it is done · about 10 min
Two lists
Every assessment starts from an inventory. The question is which one.
An asset register records what an organisation decided to run. A perimeter records what it ended up running. Those are different documents, and only one of them answers when you ask it a question.
Hand a tester a list and you have set the boundary of what the test can find before the test has started. Everything inside the list gets worked properly; everything outside it is, for the purposes of that report, not there. The report will be accurate and the conclusion will be narrow, and the narrowness will not be visible in the document — a clean result against a list reads exactly like a clean result against an estate. Working the perimeter out instead changes what the boundary is drawn from. The address ranges an organisation announces are routing data. The names resolving into those ranges are public. What actually answers on a given address is a question only asking can settle, and it is the one that produces hosts no list has ever carried, because a live service at an address that no name has ever pointed at never had a way of reaching anybody’s inventory. Discovery run that way returns an inventory of its own, and the two inventories do not match. The part where they fail to match is not noise to be tidied up before the real work begins. It is the first result of the engagement.
The gap
Five ordinary ways a register and a perimeter come apart
None of these is negligence, and none of them is interesting on its own. They are the mechanics of an estate that people work in, and together they are why the second list is never a copy of the first.
A change that outlived its ticket
Something was stood up to get a piece of work over the line, with an end date that everybody understood at the time and nobody wrote down. The work finished. The ticket closed. The host is still answering, and the register has no row for it because the row was never meant to be permanent.
An estate that arrived with somebody else’s conventions
A second organisation’s ranges, naming and provisioning habits are folded into the first. The register gets the parts that were documented on the other side, in the form the other side documented them. What was informal there stays informal here.
A record that outlived the thing it described
The register is a statement of belief about what exists. A decommissioning updates the belief; it does not always update what the outside world can still see, and the two then disagree without anybody being told they disagree.
A system nobody decided to publish
Pre-production and internal systems get their reachability from a configuration rather than from a decision. Nobody chose to put them where a stranger can reach them, which is precisely why nobody entered them on a list of things a stranger can reach.
A host whose owner moved teams
The system is documented, running and known to somebody. That somebody has since changed roles. The register still has the row; what it no longer has is a person who would notice the row being wrong.
Measured
How big a scope actually turns out to be
One figure, from our own engagement archive. The spread is the point, and it is wide enough that scope size is a question to settle rather than an assumption to carry.
Targets per engagement, across our engagement archive As of 2026-09-15
- The number of targets in a single engagement runs from 1 to 266.
- The median is 4. Half of all engagements are four targets or fewer, and that half is the ordinary case rather than the small case.
- The distance between the median and the top of the range is what makes scoping a decision rather than a formality. A scoping model built for four targets and one built for 266 are not the same model, and an estate does not announce in advance which of the two it is.
- The count is of targets that were authorised and worked. It is not a count of what discovery returned, which is a different number and is not measured here.
Deliberately excluded
- It is a spread from our own engagement archive rather than an industry figure, and it says nothing about anybody else’s work.
- It is a count of targets, not a price ladder. One scan is one application or one target at $500, and anything wider than a single target is scoped rather than listed.
- Physical, hardware and wireless testing is out of scope for the platform in every class, so nothing of that kind appears in the count.
Two inputs
Working from the list you were handed, and working from what answers
Two different inputs to the same assessment. They produce results that are evidence of different things.
| The question | Scoped from the asset register | Scoped from what answers |
|---|---|---|
| How the perimeter is established | It is inherited. The assessment knows what the register knows, including the things the register has quietly stopped knowing. | From the ranges you announce, the names resolving into them and the services that respond — reconciled, and put in front of you as a proposal. |
| What happens to a host nobody listed | Nothing. It is not in the scope, so it is not in the report, and the next engagement starts from the same list again. | It is returned with everything else and becomes a decision you take, in writing, before anything on it is touched. |
| Who decides what gets tested | Whoever maintained the register, at whatever moment they last touched it, without this question in front of them. | You do, at scope sign-off, with the discovered list in front of you. |
| What a clean result proves | That nothing on the list was exploitable. Whether the list was the estate is a separate question, and the report is not able to answer it. | That nothing inside the authorised scope was exploitable, where that scope was drawn from what answered rather than from what was remembered. |
| What the next run starts from | The register again, in whatever state it has reached by then. | The scope you authorised, plus whatever discovery has returned since — proposed the same way rather than tested on the strength of the earlier sign-off. |
| What the report is evidence of | The condition of the list on the day it was worked. | The condition of the estate as it answered on the day it was worked. |
How the perimeter is established
- Scoped from the asset register
- It is inherited. The assessment knows what the register knows, including the things the register has quietly stopped knowing.
- Scoped from what answers
- From the ranges you announce, the names resolving into them and the services that respond — reconciled, and put in front of you as a proposal.
What happens to a host nobody listed
- Scoped from the asset register
- Nothing. It is not in the scope, so it is not in the report, and the next engagement starts from the same list again.
- Scoped from what answers
- It is returned with everything else and becomes a decision you take, in writing, before anything on it is touched.
Who decides what gets tested
- Scoped from the asset register
- Whoever maintained the register, at whatever moment they last touched it, without this question in front of them.
- Scoped from what answers
- You do, at scope sign-off, with the discovered list in front of you.
What a clean result proves
- Scoped from the asset register
- That nothing on the list was exploitable. Whether the list was the estate is a separate question, and the report is not able to answer it.
- Scoped from what answers
- That nothing inside the authorised scope was exploitable, where that scope was drawn from what answered rather than from what was remembered.
What the next run starts from
- Scoped from the asset register
- The register again, in whatever state it has reached by then.
- Scoped from what answers
- The scope you authorised, plus whatever discovery has returned since — proposed the same way rather than tested on the strength of the earlier sign-off.
What the report is evidence of
- Scoped from the asset register
- The condition of the list on the day it was worked.
- Scoped from what answers
- The condition of the estate as it answered on the day it was worked.
The proposal
What the scope proposal asks you, host by host
Discovery proposes; the authorisation is yours. In the fully autonomous model that sign-off is the last human action of the engagement, which is exactly why the proposal is written to be read rather than skimmed.
A host you already knew you had
- What the proposal says
- The address, the name that resolved to it, and the service answering on it — set beside what you supplied, so the two can be matched rather than assumed to agree.
- The decision that is yours
- Whether it is in. Agreement on this half is what the rest of the proposal gets measured against.
- What runs afterwards
- Scanning and exploitation inside the authorised scope, without checking in again. That is what the sign-off bought.
A host the register does not have
- What the proposal says
- The same fields, plus the fact that nothing you supplied accounts for it. It is presented as a question. It is not presented as a finding, because at this stage nothing on it has been touched.
- The decision that is yours
- In, out, or held until you have established whose it is. Holding it is a real answer and it is recorded as one.
- What runs afterwards
- Only what you authorised. What was refused is as legible in the audit trail afterwards as what was allowed.
Adjacent
Where the scope decision goes next
Three questions this article raises and does not settle. Each has its own page, and none of them is a prerequisite for the others.
What a scope and authorisation has to name
The clauses the sign-off actually records: the domains and ranges, which discovered hosts are in, and which of the three approval gates you have released ahead of time. Every action the platform takes afterwards is checked against that document rather than against somebody’s reading of the situation.
CadenceWhat happens to a scope you have already signed
A standing scope is one the next run starts from rather than renegotiates, which is what continuous penetration testing changes about the interval between engagements. A single scoped engagement is a finished piece of work on its own.
The sibling productWhere ShadowMap sits, and where it does not
ShadowMap does discovery as its own job, continuously, on its own subscription. B-52’s external network class runs its own discovery as phase one and needs nothing bought first. The direction between them runs one way: ShadowMap discovers, and B-52 tests what it finds.
States
Four things that can happen to a host discovery returned
The unexpected part of the inventory is not a finding and it is not a to-do list. It is a set of decisions, and every one of them has a state that somebody can point at later.
| State | What it means | What follows |
|---|---|---|
| Proposed | Returned by discovery and put in front of you with the address, the name if it has one, and what answered on it. Nothing on it has been touched and nothing will be. | Waits for your decision. |
| Authorised | You signed it into the scope. From that point it is worked like every other target in that scope, against the same standards, and anything it produces arrives with the request, the response, the steps that reproduce it, a CVSS v4.0 vector and a CWE. | Tested. |
| Held | You have not decided, and until you do it stays an open question rather than becoming a gap. A held host is recorded as held, so the question survives into the next run instead of expiring with this one. | Not tested. Stays on the record. |
| Not yours to authorise Terminal | An address inside a range you announce that somebody else operates. Authorisation has to come from whoever is able to give it, and nobody else’s signature substitutes for that. | Excluded. Nothing is tested on somebody else’s authority. |
- Returned by discovery, awaiting your decision
- Inside the scope you signed off
- Open, and recorded as open
- Outside the engagement until an authorisation covers it
- TerminalNo state follows this one
The difference
Assessing what you remember, or assessing what you run
The choice here is not between more testing and less of it. It is a choice about which document the test takes as its input, and it is made once, at scoping, before anybody has written a test case. Take the register and the assessment inherits every assumption inside it, including the assumptions that stopped being true. Take what answers and the assessment starts from a list that was produced by asking, then hands that list back for a decision that belongs to you rather than to the run — which is why the proposal comes before the testing and not after it. A register that disagrees with a perimeter is telling you something specific, and reconciling the two is work worth doing for its own sake. What changes is what the report at the end is evidence of. One of them describes a list. The other describes an estate.