#156 · Private Asset Detection Now Available in Escape ASM
We've expanded our risk detection capabilities to identify private assets across your attack surface — assets whose addresses are not resolvable on the public internet.

What's new¶
When scanning your assets, we now automatically flag any asset whose IP address or domain name resolves to a private or non-routable address. These assets will appear in your ASM dashboard, so your team can review and act on them.
What counts as a private asset¶
An asset is considered private if its address falls into any of the following categories:
- Local domains — any .local domain, including Kubernetes services (.svc.cluster.local)
- Private IP ranges — 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16, as well as their IPv6 equivalents
- Loopback addresses — localhost, 127.0.0.0/8, and ::1
- CGNAT range — 100.64.0.0/10
Why it matters¶
Private assets appearing in your external attack surface can indicate misconfigured services, unintended internal exposure, or infrastructure leaking details about your internal network topology. Identifying them early helps your team prioritize remediation and reduce the risk of internal systems being inadvertently reachable or discoverable.
What to do¶
Review any private assets flagged in your ASM (Attack Surface Management) dashboard and assess whether their presence is expected. If not, investigate the underlying service configuration and ensure internal resources are not inadvertently exposed.