Asset Management
Escape records every discovered external or internal Asset in a single ASM.
This section explains how the platform enriches each Asset, tracks its lifecycle, and lets you make bulk edits.
Attribute Enrichment & Fingerprinting¶
Escape enriches each Asset with attributes supported by the discovery data. Use these attributes to understand the Asset and prioritize testing.
| Attribute | What It Shows | Typical Uses |
|---|---|---|
| Reachability | Public or Private Locations that can reach the Asset | Filter by Internet exposure or private network access |
| Environment | Production, Staging, or Development | Distinguish development services from production services |
| Framework Technology | Detected frameworks and runtimes | Identify outdated stacks |
| Cloud Hosting | Detected hosting provider | Track cloud-hosted and self-hosted Assets |
| WAF | Detected web application firewall | Review firewall coverage |
| Captcha Provider | Detected captcha service | Review frontend protections |
| Authentication | Detected authentication technology or access requirements | Review service access |
| Code Owners | Owner email addresses from connected repositories | Contact the people responsible for the code |
All attributes are searchable and filterable; you can also export them via the API.
Asset Status Lifecycle¶
| Status | Meaning | Effect on scans & alerts |
|---|---|---|
| Monitored | Asset is in scope and actively scanned. | Findings generated and routed. |
| Deprecated | Asset isn't reachable anymore (decommissioned). | Findings marked as resolved, kept for audit |
| Out Of Scope | Legitimate Asset but excluded by policy (such as Third-Party Assets for instance). | Findings marked as resolved, kept for audit |
| False Positive | Discovery error or duplicate entry. | Findings marked as resolved, kept for audit |
| Third Party | Third-party service displayed in the asm but not scanned. | Findings marked as resolved, kept for audit |
Status changes apply immediately to both ASM surface tests and queued DAST runs. Asset status can also be determined automatically by allowlist/blocklist rules in the Global Configuration: see Scope Management for details.
After 30 days without being seen, MONITORED Assets are automatically updated to DEPRECATED, unless their status was set manually or they're attached to a DAST or AI Pentesting profile.
Manually Set Status¶
Manually set status keeps you in control of an Asset's status. Discovery scans and workflow runs preserve the status you've chosen.
Manually set status is automatically enabled when:
- You create an asset through the platform or API (receives
MONITOREDstatus) - You explicitly set any status through the UI or API, including
FALSE_POSITIVE
You can still manually change the status of assets with manually set status at any time.
Bulk Editing & Tagging¶
- Select multiple Assets with Shift-click or table filters.
- Use the Bulk Edit actions to update:
- Status (such as Monitored or Deprecated)
- Projects: Assign the selected Assets to one or more projects. This replaces their current project assignments.
- Custom Tags: reusable labels (each with a name and color) for additional grouping.
- Save your changes. Edits are recorded in the audit log for traceability.
Bulk edits can also be scripted via the REST API (bulkUpdateAssets, POST /v3/assets/bulk-update). Select Assets with a where filter containing assetIds, types, or statuses.
Project Propagation¶
When Escape discovers a new asset under an existing one, such as a subdomain under a domain or an endpoint under a subdomain, that new asset automatically inherits the projects of its parent. Only assets within the parent's scope are affected: for example, subdomain.example.com and https://api.example.com/ inherit projects from example.com, but an unrelated domain that was discovered via example.com doesn't.
In Organization Settings → General, find Propagation Rules and turn on Disable project propagation to stop inheritance. With this setting off, child Assets inherit their parent's projects.
Tip
When project propagation is disabled, you can use Workflows to assign projects to newly discovered assets automatically. Configure a workflow with the Asset Found trigger and an Update Asset action.