- Primeros pasos
- Ejecutar su primer escaneo
Run your first scan
Open the page in the table that matches your target, for example Scan a Web Application for a URL. The last column lists what to have ready.
Choose what to scan
| What do you want to scan? | Open this page | What you need |
|---|---|---|
| A mobile app from a store | Scan a Mobile Application from the Store | The store (PlayStore, AppStore or AppGallery) and the app's name, package name, bundle name or bundle ID. A country, if the app is only available in some places. |
| A mobile app from a file | Scan a Mobile Application from a File | The app file for Android, iOS or HarmonyOS. An iOS file must be a non-encrypted IPA, as listed in Mobile Scan Prerequisites. An SBOM or lock file is optional. |
| An iOS app from TestFlight | Scan an iOS Mobile Application using TestFlight | The TestFlight public URL. |
| A web application | Scan a Web Application | The URL or domain to scan. Enter one target per line to scan several. |
| A web API with a schema file | Scan a Web API with an API schema file | The API endpoint and the schema file, in GraphQL, WSDL or OpenAPI format. HTTP headers, such as an API key, are optional. |
| Source code in a Git repository | Source Code Scanning | A source code integration (GitHub, GitLab, Bitbucket, Azure DevOps or Self-Hosted Git), an AI provider (Cyber Models or BYOK) and an effort level. |
| A mobile app and its SBOM or lock file | Scans with SBOM or Lockfile | The app file (.apk, .aab or .ipa) and an SBOM or lock file, such as SPDX, CycloneDX or package-lock.json. The page lists every supported file. |
| A network | Scan Networks | One or more IPv4 or IPv6 addresses or ranges, one per line. |
| Several assets at once | Run a Multi Asset Scan | At least one asset and at most one mobile app, an AI provider (Cyber Models or BYOK) and an effort level. To scan code without a Git provider, add a Repository Archive asset. |
| Assets already in your inventory | Scan assets from the inventory | An asset listed under Attack Surface, then Assets. |
| An app behind a login | Authenticated scans | A test account on the target and its credentials. The 2FA method, if the login needs a code. Network access from the scanner to the target. For mobile, the app. |
Before your first scan
- Account. Create an account with your email address and password, then start from the New Scan menu. See Getting started.
- Organisation. Scans belong to an organisation. To work in a separate organisation, see Create an organisation and Switch organisation.
- AI provider. Deep Agentic, multi-asset, Mobile Shielding and source code scans need Cyber Models tokens or your own key (BYOK). See What does a scan consume from my plan or wallet?
- Mobile apps. See Mobile Scan Prerequisites for supported formats and protections that affect testing.
- Private targets. Allow the scanner IP addresses. If the target is not internet facing, see Scanning Internal Web Applications.
After the scan
You can open the results while the scan is still running. Click a finding to see its recommendation, references and technical details. To tell confirmed findings from potential ones, and to check coverage and fixes, read Understand Scan Results.
To share the results, see Generate a PDF report and Share a scan report.