First thing to know, as we like to keep things simple at Patrowl, when you put an asset in “Pentested” mod, all related services will be Pentested.
Let’s take a basic example, you have just activated Pentested mod for “www.patrowl.io”. The FQDN is resolving to an OVH IPs: 51.210.250.238, and 4 ports are open :
Port 22/SSH, Admin
Port 80/HTTP, main website, redirection
Port 443/HTTPS, main website
Port 8080/HTTPS, administration HTTPS.
Then, the 4 services will be continuously Pentested, and the related IP integrated in our Control. Simple !
Warning : when you put a top domain in pentested mod (patrowl.io for instance), all related subdomain will NOT be pentested. Offensive tests will only be limited to patrowl.io. In many cases, top domain are redirecting or hosting services linked to the related www FQDN (www.patrowl.io). We recommend that you give priority to FQDN for Pentested mod whenever possible.