How to Trigger an External Scan
Follow these steps to start a new external scan in Pentest Copilot Enterprise.
1. Navigate to Target Asset Page
Go to Attack Surface → Target Asset.

2. Add an Asset
Choose the asset type based on the scan:
Domain → for web applications.
APKFile → for Android applications.
Enter the domain name (e.g.,
example.com).(Optional) If you have a specific starting URL, such as
/login, add it in the Starting URL field.

3. Verify Sandbox Agent Connection
Ensure that the Sandbox Agent is connected and ready.

4. Open Discovery Module
Navigate to Modules → External Assessment → Discovery.

5. Select the Target
Choose the Target Domain you just added.

6. Configure Scan Settings
Click the Settings icon (on the right side of the asset) to configure:
Rate Limit
Custom Headers
Browser Session (if any) Read: Browser Session
7. Schedule the Scan
Click Schedule Scan.
Two options will appear:
Run Discovery first, then the main module (manually start second step).
Trigger External Scan automatically after Discovery (recommended).

8. Select Scan Categories
If you chose Trigger External Scan, a list of Scan Categories will appear.
Select specific categories or choose Select All.
Save the configuration.

9. Run the Assessment
Click Run Assessment to begin the scan.

Track scan status / activity on the Activity page
Last updated