Skip to main content
All CollectionsPentest
What is tested when I put an asset in Pentested mode?
What is tested when I put an asset in Pentested mode?
Updated over 3 months ago

First thing to know, as we like to keep things simple at Patrowl, when you put an asset in “Pentested” mod, all related services will be Pentested.

Let’s take a basic example, you have just activated Pentested mod for “www.patrowl.io”. The FQDN is resolving to an OVH IPs: 51.210.250.238, and 4 ports are open :

  • Port 22/SSH, Admin

  • Port 80/HTTP, main website, redirection

  • Port 443/HTTPS, main website

  • Port 8080/HTTPS, administration HTTPS.

Then, the 4 services will be continuously Pentested, and the related IP integrated in our Control. Simple !

Warning : when you put a top domain in pentested mod (patrowl.io for instance), all related subdomain will NOT be pentested. Offensive tests will only be limited to patrowl.io. In many cases, top domain are redirecting or hosting services linked to the related www FQDN (www.patrowl.io). We recommend that you give priority to FQDN for Pentested mod whenever possible.

Did this answer your question?