---
title: "Infrastructure"
canonical: "https://kb.cynergy.app/space/GS/902496287/Infrastructure"
format: markdown
---
#### On the Infrastructure tab, you will see the subdomains found during the discovery scan. Next to the domain's name, you will see if it is behind a WAF. Next, you will see the hosts, the ports, print screens of the subdomain, and the technologies running on this specific subdomain.

![image](media://24762b16-8a82-464b-b5e5-b5e10c4cb4be)

 Per each IP address, you can get additional information such as:

Organization association

ASN, Network Address, and Geolocation 

![image-20240124-171507.png](media://dd4fbd6a-8dc3-4181-b93b-ae26195f02c1)


You can filter the list by port, and exclude port, IP, and technology.

![image](media://17281a68-e1ae-4f0b-8696-6aaad81647f2)

 

Next to that, you will be able to filter the results by subdomains that have issues, hide the subdomains that are unresolved, and show only new subdomains that had been discovered during the discovery scan.

![image](media://92b8d26b-25d6-4061-af86-43cc66d02b8f)

 

By clicking on the CSV report, you will be able to download the CSV report.

![image](media://b41ed666-e207-4249-825e-f52a04adf717)

 

By Clicking on "add asset" you will be able to add subdomain or IPs in a one-by-one manner or via a CSV upload

![image](media://10c7dc39-15a1-42af-b089-9a6da579fb48)

 

By clicking on the name of the subdomain you will be able to create 4 types of scans:

![image](media://a4c107e0-e518-40b6-990a-587cd96ed741)

 

**Deep scan**

- Extended ports and services scans - scanning for all services in all TCP ports
- The deep identification process of technologies and versions
- Identify related technologies CVEs data and CVSS score

**Automated exploitation**

- Launch a fully automated process that validates each CVE by exploiting each discovered vulnerability
- Collecting screenshot evidence of each successful exploitation (CVE) to minimize false-positive and false-negative results

**Vulnerability assessment**

- The extended data collection process
- Deep enumeration of accessible services of each target
- Analyzing implemented technologies
- Identify CMS applications and launch multiple dedicated scanners
- Launch multi-step vulnerability scanners against OWASP and Bug-Bounty vulnerabilities

**Hijack checker**

- Scan for subdomain hijack / Takeover vulnerability for a subdomain