Documentation Pentest Filling assets

Filling assets

Asset types, accepted formats and best practices.

Assets are the pentest targets: URLs, IPs, domains or mobile apps that will be tested.

You type the address and the platform identifies the asset type. Check the tag that shows up next to it and adjust if needed. A single test can mix types.

Accepted formats

HAS accepts the formats below. Use only a-z 0-9 . - / : _ characters:

Network ranges (192.168.1.0/24) are not accepted as a single asset: list the addresses to be tested. If a server manages the network, list that server.

Invalid assets show up highlighted in red. One entry per asset, confirmed with Enter. For several at once, paste the list separated by commas or line breaks: each address becomes an asset.

Assets per test limit

Best practices