Scope

Nothing is scanned by accident

Every scan runs against an explicit allow-list of approved targets, so the only systems ever touched are ones somebody deliberately put in scope.

Overview

Approved targets only

Scope is what separates security testing from something nobody authorised. A scanning tool pointed at the wrong host is a serious incident, so Argus Pentest does not accept an arbitrary address at scan time: a target has to be added to an allow-list first, as a deliberate act, and a scan can only reference something already on that list.

What it does

Authorisation before capability

A target must be added to the allow-list before it can be scanned.

Scans reference approved targets rather than arbitrary addresses.

Scope is a configured, reviewable list rather than a runtime argument.

The role a target is scanned as is part of its configuration.

Discovery widens coverage of an approved target, never the target set.

How it works

How a target enters scope

1Someone adds the target to the approved allow-list
2The role and credentials it scans as are configured
3A scan is launched against that approved target
4Coverage grows within it, never beyond it
FAQ

Common questions

Can a scan be pointed at any URL?

No. A scan can only reference a target already on the approved allow-list, so putting a system in scope is always a separate, deliberate step.

Is this appropriate for systems we do not own?

The tool is built for testing your own applications. Adding a target is an assertion that you are authorised to test it.

Explore more

More of what Argus Pentest does

Get started

See an authenticated scan of your own application

Request a demo to watch a scan log in to an approved target and work the surface behind the sign-in form.