Filling assets
Asset types, accepted formats and best practices.
Assets are the pentest targets: URLs, IPs, domains or mobile apps that will be tested.
You type the address and the platform identifies the asset type. Check the tag that shows up next to it and adjust if needed. A single test can mix types.
Accepted formats
HAS accepts the formats below. Use only a-z 0-9 . - / : _ characters:
- Full URL:
https://app.company.com/login - Domain:
company.comorapp.company.com - IP:
203.0.113.45 - IP with port:
203.0.113.45:8080
Network ranges (192.168.1.0/24) are not accepted as a single asset: list the addresses to be tested. If a server manages the network, list that server.
Invalid assets show up highlighted in red. One entry per asset, confirmed with Enter. For several at once, paste the list separated by commas or line breaks: each address becomes an asset.
Assets per test limit
- Maximum of 100 assets per test, regardless of plan. For larger scopes, talk to your HackerSec contact.
- Plan balance: on Pay-per-test, each asset increases the price. On Monthly or Annual, it consumes your quota.
Best practices
- Be specific. Instead of
company.com, preferapp.company.com/dashboardif the focus is the authenticated area. - One asset per entry when typing. For several, paste the list at once.
- A server that manages several resources counts as one asset. If you want a specific resource tested separately, list it too.
- Check the asset tag and fix it if it's wrong.
- Don't put assets in the "Goal" field. The system blocks submissions if addresses are detected there.
- List both addresses. A website and its API can be tested together, but each one needs its own entry.