Before you begin
- The parent application must be active.
- Use only an HTTP or HTTPS public URL on its standard port.
- Do not include credentials, query parameters, fragments, private addresses, or internal destinations.
- Confirm that your organization owns the target or has explicit written permission to assess it.
Register the target
- Open Applications and select the Add target tab.
- Select the active Application that owns the target.
- Enter the Exact public URL. Griffin derives the exact origin and starting path tree from this value.
- Choose Type: website, web application, or API.
- Choose Environment: production, staging, development, test, or other.
- Review and approve all four observational checks: availability and redirects, transport and TLS, security response headers, and cookie attribute flags.
- Optionally enter Additional restrictions such as an approved window, contact, or ticket. Restrictions can narrow scope but cannot expand it.
- Complete the required ownership or authorization attestation shown by the form, then select Register target.
Target example
Understand the enforced scope
Griffin limits the target to one exact public origin and the selected starting path with descendants.
- Subdomains, other origins, and paths outside the starting path are excluded.
- Private or internal destinations are excluded.
- Authentication, credentials, crawling, link discovery, forms, and state changes are excluded.
- Exploit payloads, active testing, response bodies, and secret values are excluded.
Continue to authorization
- Wait for the Target registered in pending authorization state confirmation.
- Open Inventory, find the target, and select Review access.
- Complete written authorization and technical ownership verification before attempting activation or a scan.