Before you start
- You must own or have explicit written authorisation to test the domain
- The domain must be reachable from the public internet (VPN-only and localhost targets are not supported)
- Your plan must have at least one free target slot — check Tests to see how many slots you’ve used. Slot counts and cooldowns per plan are in Limits & Quotas
- Your email address must be verified. If you signed up with email and password, check your inbox or resend the verification from Settings → Account
Add the target
1
Open New Environment
Go to Tests → New Environment.
2
Enter the domain
Enter the domain name — for example,
app.example.com — without a protocol prefix.3
Set permission tier
Select the initial permission tier. Start with Read-only for a first assessment.
4
Add target
Click Add Target.
Activate and run the first scan
1
Open the environment
From the Tests page, click on the environment you just created.
2
Activate
Click Activate. The discovery scan begins within a few minutes and the status changes to Running.
3
Wait for discovery
Discovery completes in 5–15 minutes depending on the application size. The environment detail page then shows the discovered endpoint inventory.
Approve active probing
To go beyond passive discovery, approve a higher permission tier:1
Open Approvals
Go to the environment detail page → Approvals.
2
Review tier description
Read what each tier does. See How Live BattleTest works for details.
3
Approve the tier
Click Approve next to the tier you want to enable and confirm.
4
Start a new scan
Start a new scan from the Tests page.
Add multiple domains to one environment
An environment can cover multiple domains belonging to the same application — for example,api.example.com and app.example.com. From the environment detail page, click Add domain and enter additional hostnames. All domains in one environment share the same target slot.
Run a scan immediately (bypass cooldown)
Each plan enforces a minimum time between scans: 4 hours on Startup, 2 hours on Observability. To scan sooner — for example, immediately after a deploy:1
Open the environment
Go to the environment detail page.
2
Bypass cooldown
Click Run scan now (visible when a cooldown is active).
3
Confirm purchase
Confirm the $49 one-time purchase. The scan starts immediately.
The cooldown bypass applies to a single scan on a single target. The regular cooldown resumes after the bypassed scan completes. If you bypass cooldowns frequently, upgrading to Observability (2-hour cooldown) is more cost-effective.