Asset Intelligence

Understand the product surface, the main concepts, and where to go deeper.

Asset Intelligence helps you understand what internet-facing assets exist, how they are exposed, what has changed, and which observations matter from a security and trust perspective. In practice, those assets begin as monitored domains and public IP addresses.

For a product-level overview, see the Asset Intelligence page. To compare available limits and retention by plan, see pricing.

It is designed to answer practical questions such as:

  • What assets are currently in scope?
  • What services, pages, DNS records, and certificates are associated with them?
  • What changed recently?
  • Which changes are simply observations, and which should be treated as issues?
  • How should teams interpret that information over time?

What Asset Intelligence is

Asset Intelligence is not just an inventory. It is a living view of internet-facing reality.

A basic inventory tells you what should exist. Asset Intelligence helps you see what is actually observable, how that picture evolves, and where that evolution may deserve attention.

This matters because asset posture is rarely static. Domains gain new pages. Services appear on new ports. DNS records change. Certificates are replaced. Similar domains emerge. What matters operationally is often not the existence of a thing, but the fact that it is new, changed, unexpected, or no longer present.

What you can see in the product

Asset Intelligence is organized so teams can move from summary to evidence.

Asset overview

The overview is the starting point for understanding an asset's current state. It brings together current posture, recent activity, and related context so you can orient quickly before moving deeper.

Recent activity is usually easiest to read in two lanes:

  • operational events for material changes across the monitored surface
  • intelligence events for lower-noise discovery signals such as curated similar-domain observations

The overview also includes an Exposure Score that summarizes current posture from findings, exposed surface breadth, and monitoring freshness. Reviewed dispositions affect that score differently: false positives and not-applicable findings are excluded, while accepted-risk findings can still carry reduced posture weight. The score history can be reviewed over time within the history window available to the team.

Exposure Map

The Exposure Map shows observed relationships between the monitored asset, subdomains, ports and services, pages, resources, and external dependencies. It gives teams a relationship view of the current surface before they drill into the supporting evidence.

Ports

The Ports area shows discovered open ports and related transport context. It helps answer which services are externally reachable and whether new network-facing behavior has appeared.

Port coverage depends on the asset's verification and active-scan configuration:

  • until a domain is verified, Kantoku checks only the default HTTP and HTTPS ports, 80 and 443
  • after verification, active TCP scanning must be enabled individually for each domain, subdomain, or IP target
  • enabling an apex domain does not automatically enable its discovered subdomains
  • IP assets require confirmation that your organization owns, controls, or is authorized to scan the address
  • the Asset Intelligence plan determines how many TCP ports can be included in active scanning
  • the plan also limits how many targets can have active TCP scanning enabled at the same time: 25 on Starter, 250 on Growth, and 1,000 on Scale

Hostnames on shared CDN or cloud infrastructure are limited to TCP ports 80 and 443 unless the selected endpoints are also authorized as IP assets for the team.

When coverage is limited because verification or active-scan configuration is incomplete, the Ports area shows a notice with the action needed to expand coverage. A port that is not included in the configured scan range should not be interpreted as confirmed closed.

Subdomains

The Subdomains area shows hostnames discovered within a monitored domain's scope. The default view focuses on subdomains that are currently observed in DNS evidence.

Previously observed subdomains are retained as historical evidence when their DNS records disappear. Use the Include historical control when you need to review those earlier observations. DNS labels used to publish service configuration, such as DKIM selectors, remain DNS-record evidence rather than being presented as host subdomains.

Pages

The Pages area helps you understand the observed web surface of an asset. Kantoku monitors the default root page and same-origin redirect targets automatically where applicable, and teams can also add specific paths for custom page monitoring when an important page should be tracked directly.

Some custom pages can also use an authentication profile. Authentication profiles let a team define how Kantoku should reach a protected page, such as by signing in through a login form or sending required request headers. When an authentication profile is attached to a custom page, authenticated browser collection and screenshot capture can show the page as it appears after that access step succeeds.

Depending on the page and monitoring mode, page evidence can include screenshots, technologies, HTTP headers, cookies, resources, console logs, and page services.

Use the page view when you need to answer questions such as:

  • what the page looked like when it was observed
  • which frameworks, libraries, or third-party tools were detected
  • which headers were returned by the server
  • which cookies were present before and after consent handling
  • which resources were loaded by the page
  • whether the browser logged warnings, errors, or other runtime messages
  • which durable third-party services appear to be in use on the page
  • whether an authenticated page is being observed with the expected access context

Page content hash monitoring can be controlled per page when teams want to decide whether body changes should create page content change events for that monitored path.

Technologies

The Technologies area centralizes web technologies detected across monitored asset pages. It helps teams review which frameworks, libraries, analytics tools, consent tools, CDNs, and similar web technologies appear across their monitored surface without opening each page individually.

Technology evidence is page-oriented, so it is best read alongside page evidence such as resources, headers, cookies, and console logs.

Access controls and WAFs

If your environment uses a WAF, bot protection, or source-IP allowlisting, Kantoku collection may need to be explicitly permitted. When required, allowlist the current Kantoku source IPs used for collection. The current list is available here.

DNS, certificates, and registration

These areas provide visibility into resolution, trust material, reverse DNS, and mail transport posture. They help teams review DNS records, certificate history, PTR records, and email-security signals such as SPF, DKIM, DMARC, CAA, and MTA-STS.

The DNS record inventory shows canonical record names, expandable values, provider context, and links to related DNS events. For A and AAAA records, the Value pattern summarizes the previous 30 days as no observed changes, one change, or rotating values. This describes how the address evidence behaved during that period; it is not a security rating.

Some of these signals are direct security findings. Others are posture or ownership review signals. For example, provider-managed reverse DNS may be expected for hosted infrastructure, while MTA-STS issues usually indicate mail-security maturity or policy completeness rather than an exposed application vulnerability.

Registration evidence adds ownership and allocation context. For domains, registrar details can include registration metadata, contacts, and the monitored domains associated with that registrar. For public IP addresses, network registration evidence can show the registered range, handle, name, dates, and contact context. Changes to this IP registration evidence can appear as low-priority events for review.

Similar domains

The Similar Domains area surfaces lookalike and adjacent-domain intelligence around a monitored domain.

Events and findings

These areas help you move from observation to interpretation:

  • Events explain change.
  • Findings highlight conditions that may require review, tracking, or disposition.

In practice, recent events can also be separated into operational and intelligence views so teams can review important surface changes without losing curated discovery history.

Event and finding integrations can notify teams when important activity appears. Email notification rules can filter findings by severity and operational or intelligence events by priority, then deliver matching activity immediately or as an hourly, daily, or weekly digest. Slack finding rules deliver matching activity immediately. For the full workflow, see Events and Findings.

Reports

Reports package the current picture for sharing when it needs to be communicated outside the live product views. They can also help communicate recent change categories, including page-service changes, without requiring other stakeholders to navigate the live interface.

Snapshots

Snapshots preserve observed states over time so teams can review what changed, when it changed, and how long the history is available under their plan. Repeated observations that confirm the same state can still refresh monitoring freshness, even when they do not create a new changed-state snapshot.

Collection coverage and frequency

Asset Intelligence does not use one universal refresh interval for every signal. Collection cadence depends on both the plan and the type of evidence being collected.

The table below summarizes the current typical cadence by plan:

Signal Starter Growth Scale
DNS Daily Every 12 hours Every 6 hours
Certificates Continuous Continuous Continuous
TLS Daily Every 12 hours Every 6 hours
TCP ports Top 100 daily Top 1,000 every 12 hours Top 1,000 every 6 hours; full range within 7 days
HTTP ports Daily Every 12 hours Every 6 hours
Browser capture Daily Every 12 hours Every 6 hours
Technology detection Daily Every 12 hours Every 6 hours
RDAP Daily Daily Daily
Newly registered domain checks Daily Daily Daily
Favicon Daily Daily Daily
Screenshot Daily Daily Daily

In practice, this means higher plans refresh the core surface more frequently, while some supporting evidence remains on a daily cadence across all plans.

For Scale, full TCP coverage is spread across seven daily scan groups. The frequently used Top 1,000 ports are checked every six hours, while one part of the remaining TCP range is checked each day.

Certificate discovery includes continuous Certificate Transparency log monitoring, with scheduled backfill and reconciliation work used to keep certificate history complete.

Use this as a practical guide to how often new observations are usually revisited, not as a point-in-time processing guarantee.

How to read Asset Intelligence

Asset Intelligence is most useful when it is read as a time-aware product rather than a static catalog.

At any moment, an asset can contain a mix of:

  • stable conditions that have been known for some time
  • newly observed conditions
  • changed conditions
  • conditions that have disappeared
  • conditions that are noteworthy enough to become findings

That distinction matters. A stable open port and a newly exposed open port may both be visible, but they do not mean the same thing. A long-known similar domain and a newly observed lookalike domain do not carry the same operational weight.

This is also why Asset Intelligence separates some discovery-heavy signals from the main operational timeline. A newly observed lookalike domain may be worth seeing, but it is not the same kind of change as a newly exposed service, changed certificate, or shifted page behavior.

Use the pages below for the deeper parts of the product:

  • Core concepts explains assets, exposure, pages, signals, and how Asset Intelligence should be interpreted over time.
  • Events and findings explains how change is recorded, when a condition becomes a finding, and how to read the difference.
  • Similar domains and reports explains curated lookalike monitoring, reporting, and how to communicate the current picture.

A good working pattern

A practical way to use Asset Intelligence is:

  1. start from the asset overview to understand the current picture
  2. review recent events to understand what changed
  3. review findings to understand what may need attention
  4. inspect supporting evidence in ports, pages, DNS, certificates, and similar domains
  5. add custom pages for important paths that should be monitored directly
  6. generate a report when the current picture needs to be shared

What Asset Intelligence is for

Asset Intelligence is for understanding internet-facing reality with more context than a basic inventory or periodic scan can provide.

It helps teams:

  • maintain a current picture of exposed assets
  • understand what changed and when
  • separate observation from interpretation
  • investigate findings with supporting evidence
  • communicate posture more clearly across technical and non-technical stakeholders