Before You Scan
Confirm these items before scanning a production target:Choose the Right Scope
Web UI Workflow
- Open Assets.
- Add or select the asset you want to assess.
- Review the asset detail page for discovery signals.
- Choose Start scan.
- Confirm the scan name and target list.
- Enable subdomain coverage only when the domain and discovered hosts are in scope.
- Add authentication context if the application requires login.
- Start the scan and monitor progress on the scan detail page.

Authentication Options
For step-by-step authenticated scan guidance, see Authenticated Scanning.
CLI Equivalents
Use CLI when the scan needs to run from automation, a scheduled task, CI/CD, or a repeatable analyst workflow.
See CLI Reference for full command details.
Scan Output
VulnScan stores standard Web UI, CLI, and scheduled scans in the workspace database. The scan source remains visible for audit and troubleshooting. Supported export formats:
PDF exports run as background jobs. Closing the browser does not cancel the export.
Scheduling Strategy
Use recurring scans when the target is important enough to monitor continuously. Recommended starting point:
Avoid scanning large scopes during peak business traffic unless the target owner has approved it.
Configuration Checklist
Before clicking Start scan, verify:- The scan target exactly matches the intended hostname, URL, IP, or CIDR.
- The target is inside the active license scope.
- The asset detail page shows the expected discovery context.
- Authenticated applications have a valid test session or token.
- The scan source and output requirements are clear.
- The team knows who will triage Critical and High findings.
- PDF export notifications are configured if stakeholders need a downloadable report later.