Asset Discovery Provenance Tree
View the full discovery provenance tree for any domain asset to understand exactly how and why it appears in your attack surface.
Every asset in Guard records where it came from. The asset's Overview tab shows the seed or integration that led to the asset, and a graph of the assets directly around it. Use it to answer the question: why is this asset in scope?
How discovery chains work
Guard discovers assets in steps. A seed, such as a domain you added, can yield subdomains, IP addresses, and other assets, and each of those can yield more. Guard follows the chain back from any asset to where it started, however many steps that takes.
View where an asset came from
- In Guard, go to Assets.
- Click an asset to open its detail drawer.
- On the Overview tab, find the Origination card.
Each entry in the Origination card shows:
- The source and the origin, for example a seed domain, or the integration that imported the asset.
- First Seen and Last Seen, the dates Guard first and last recorded that discovery.
The card shows the first three entries. Click View All to see the rest, and View Less to collapse the list. An asset that you added as a seed shows Added as seed.
Parent and child assets
Below the Origination card, the Overview tab shows a graph of the asset's direct relationships:
- Parent Assets are the assets this asset was discovered from.
- Child Assets are the assets discovered from this asset.
Use the parent assets to follow the chain back one step at a time, and the Origination card to see where the chain started.