Suggested Domains

Tenable Attack Surface Management continually analyzes internet data to produce a list of suggested domains that might be related to your organization. You can use the Suggested domains page to verify that your organization is aware of every domain it owns. While Tenable Attack Surface Management automatically adds most assets to your inventory, some assets require further verification to confirm ownership.

To view your suggested domains:

  1. In the upper right corner, click the button.

    The Suggested domains page appears. When there are new domain suggestions to review, the button turns yellow.

    The Suggested domains page shows the following details:

    Columns Description
    Name Domain names that Tenable Attack Surface Management suggests you may own.
    Type The type of suggestion. Suggestion types can be ASN, brand, domain, IP, IP range, subdomain, or nameserver.
    Rules

    The logic based on which Tenable Attack Surface Management suggested the domain name. Hover over the column to view the details of the logic. By default, the most recent suggestions are displayed first.

    Suggestion Date The date on which Tenable Attack Surface Management suggested the domain name.
  2. On the Suggested domains page, you can sort the assets list as follows:

    • Filter the table to view specific suggestions.

      1. At the top of the table, click Add Filter.

        The Add Filter drop-down appears.

      2. Use the Search for Filters box or select the filter from the list. For example, Name.

        The list of operators appears.

      3. Select the operator. For example, contains.

      4. Type the value of the filter, if needed.

      5. Click Done.

      6. (Optional) To add another filter, click Add Filter.

        1. Repeat steps from 2 to 5.

          Tenable Attack Surface Management adds a new third filter to the list with the following options:

          • that match all filters —  Lists only the assets that match all the filters.

          • that match any filters — Lists assets that match any one of the filters.

        2. Select one of the options and click Done.

          Tenable Attack Surface Management shows the filtered results.

    • Click the column header to sort the table view. For example, sorting the Rules column lists the domain names with multiple rules detected.

Prioritizing the Suggested Domains List

Tenable Attack Surface Management can suggest thousands of domain names. To prioritize domain names based on the likelihood of ownership:

  • Sort the Rules column to view the suggestions with the most matching rules.

  • Filter the Suggested domains table to view organization-specific assets.

Add Suggested Domains to an Inventory

Once you confirm that the suggested domains belong to your organization, you can add them to your inventory.

To add suggested domains to your inventory:

  1. In the Suggested domains table, select check boxes next to the domain names you want to add to your inventory.

    Tenable Attack Surface Management displays a menu bar at the top of the table.

  2. Do one of the following:

    Description Action
    Add to the current selected inventory Click the Add to this inventory button.
    Add to a different inventory Click the Add to this inventory drop-down arrow, and select an inventory from the list.

Tenable Attack Surface Management adds the domain name to the selected inventory.

Archive Suggested Domains

You can archive suggested domains to omit them from the Suggested domains list.

To archive suggested domains:

  1. In the Suggested domains table, select check boxes next to the domain names to archive.

    Tenable Attack Surface Management displays a menu bar at the top of the table.

  2. Click Archive.

    Tenable Attack Surface Management archives the selected domains and removes these domain names from the suggested domains list.

  3. (Optional) To view archived suggestions:

    1. Click the button.

      A menu appears.

    2. Select Archived suggestions.

      The Archived suggestions page appears. To go back to the Suggested domains page, click the button.

Suggestion Blocklist

You can add domain names, email addresses, hostname, or CIDR (Classless Inter-Domain Routing) to Suggestion Blocklist to exclude them from the suggested domains list.

To add items to blocklist:

  1. In the Suggested domains page, click the button.

    A menu appears.

  2. Select Blocklisted items.

    The Suggestion blocklist items window appears with the following details:

    Column Description
    Value The domain name, email address, CIDR, or hostname for the suggestion.
    Type The type of suggestion — email, domain, hostname, or CIDR.
    Extra Additional information about the suggestion value.
  3. (Optional) Use the Search blocklisted items box to search for specific blocklisted items.

  4. To add a blocklist item, click Add an additional blocklist item.

    The Add an additional blocklist item window appears.

  5. In the Suggestion type drop-down box, select one of these suggestion types: domain, email, hostname, or CIDR.

  6. In the Value box, type a suggestion value.

  7. Click Add.

    Tenable Attack Surface Management adds the entry to the blocklisted items list and displays the Suggestion blocklist items window.

  8. Click Close to exit the window.