Assets and groups

Choose useful group boundaries

Prefer groups that map to an operational decision. Examples:

  • Production customer portal

  • Public APIs

  • Acquired company perimeter

  • Mobile backend

  • PCI scope

An asset can belong to several groups, so you do not need to choose one permanent taxonomy.

Create a group with seeds

Open Assets and select New group. Enter a unique group name and zero or more seeds.

For DNS seeds, recon discovers subdomains and adds verified hosts to the group. Alkonos accepts a root domain, hostname, URL, or IP address and normalizes it before storing the asset.

Add a host

  1. Open an asset group.

  2. Select Add assets.

  3. Choose Host.

  4. Enter the domain, hostname, URL, or IP address.

  5. Choose the destination group.

  6. Keep Mark as seed — discover subdomains enabled when this host should expand the inventory.

  7. Keep Run recon now enabled for immediate discovery.

Disable Mark as seed when you want to track only the exact host. Disable Run recon now when adding the membership is enough for now.

Add a repository

A repository must be visible through a connected forge installation.

  1. Connect GitHub, Bitbucket, or Forgejo under Settings → Integrations.

  2. Open the target asset group and select Add assets.

  3. Choose Repository.

  4. Select the forge installation and repository.

  5. Submit the form.

Alkonos creates or reuses the repository asset, links it to the group, then indexes branches, pull requests, issues, and repository statistics asynchronously.

Work with the group inventory

The group page supports:

  • Search by asset name.

  • Filter by host or repository, pinned state, HTTP status, screenshot, active TLS, open vulnerabilities, or test credentials.

  • Sort by name, recency, relevance, or vulnerability count.

  • Pin important assets. The first pinned host also becomes the group cover host.

  • Select multiple assets for a bulk scan or bulk removal.

  • Export hosts, repositories, or vulnerabilities.

Select a host row to inspect ports, vulnerabilities, traffic, credentials, infrastructure observations, schedules, and scan agents. Select a repository row to inspect branches, pull requests, issues, vulnerabilities, and code scans.

Inventory-wide asset view

The Assets tab shows canonical assets across all visible groups. It supports filters for asset type, HTTP status, open vulnerabilities, screenshots, and active TLS.

Use this view when the question spans groups, such as “show every host with a 5xx response” or “scan these selected internet-facing services.”

Remove or delete

  • Remove from group deletes only the selected membership. Other groups containing the asset are unchanged.

  • Delete group deletes the group and all its memberships. Canonical assets remain available through other groups.

  • Disconnect integration removes the installation credentials and routes. It does not replace deliberate cleanup of asset-group membership.

Schedule a host scan

  1. Open a host and select the service port.

  2. Open the Schedule tab.

  3. Choose a one-time run or a recurring interval.

  4. Save the schedule.

Recurring presets range from every six hours to monthly. Existing schedules can be paused, resumed, changed, or removed.