Discovery: how Strike maps your attack surface
Last updated: September 17, 2026
Your attack surface isn't static. New endpoints appear, applications change, infrastructure evolves, and what was in scope yesterday may not reflect what's exposed today.
Before you can test your attack surface, you need to know what's actually there.
Strike's Discovery capabilities automatically map what needs to be tested, turning a moving attack surface into a clear, reviewable scope that stays aligned with your environment.
What Discovery is
Before Strike tests anything, we need to know what's actually there to test. Discovery is the automated process that maps your attack surface: the endpoints, pages, and access points that make up an application, API, or infrastructure asset, so that your Threat Emulation covers what matters, not a guess.
Discovery isn't a separate product or an extra step you have to manage. It's how Strike turns "test our platform" into a defined, sized, reviewable scope, without you having to enumerate every endpoint by hand.
How it works
1. You provide an entry point.
A domain, an API base URL, or an IP, plus, optionally, test credentials, specific flows you want covered (login, payments, admin), or an API spec (Swagger/Postman) if you have one. The more you give us, the more precisely Discovery can map your surface.
2. Discovery runs.
Strike's Discovery agent crawls from that entry point, identifying pages, endpoints and, for infrastructure assets, associated subdomains and hosts. Most runs complete in about an hour; larger or more complex environments can take longer.
3. Your surface is sized, and it's yours to review.
Once Discovery completes, you see exactly what was found. You can exclude anything that shouldn't be tested, at any time. What Discovery returns becomes the defined scope for your Threat Emulation: nothing more, nothing less.
4. Your Threat Emulation runs on exactly that scope.
Testing covers the surface Discovery mapped and you confirmed. Nothing outside that scope gets tested without your knowledge.
What it means for you
You stay in control of scope. Discovery proposes, you decide. Anything you exclude stays excluded. Strike never re-adds it on your behalf.
No surprise costs. Discovery itself doesn't consume credits, whether it runs before you sign or inside an active Threat Emulation. If Discovery finds more surface than what you're currently testing, that's presented as an opportunity for a future run, never tested or billed automatically within your current scope.
Discovery keeps working for you. On recurring Threat Emulations, Discovery re-runs to catch what's changed: new endpoints that appeared, or ones that disappeared, so your coverage stays current as your systems evolve, without you having to re-map anything manually.
You're never blocked by it. If Discovery can't fully map an asset, for example an unusual authentication setup or a system it can't reach yet, you can always define your own scope manually and move forward. Discovery is there to make scoping faster and more accurate, not to gate your testing.
Setup is a one-time investment. Once Discovery has a clean entry point and, if needed, working credentials, it keeps mapping your surface on every subsequent run.