---
title: "Using scope and VPN"
description: "How target scope and VPN setup frame authorized DrowAI task activity."
section: "Setup"
updated: 2026-06-18
tags: ["scope","vpn","setup"]
source: "/user-guide/scope-and-vpn"
---

# Using scope and VPN

How target scope and VPN setup frame authorized DrowAI task activity.

Scope and connectivity define the boundaries of a task. They help DrowAI and
the operator stay focused on authorized targets.

## Target scope

Target scope can include approved hosts, domains, IP ranges, URLs, objectives,
exclusions, timing limits, rate constraints, or other assessment notes. Keep
scope concise and explicit.

Public examples should use mock targets or lab systems only. Do not publish
real customer scope, private IP plans, credentials, or internal network notes.

## Scope files

Scope files are useful when the assessment context is longer than a few lines.
The task form can load text or Markdown scope files into the scope field. DrowAI
can also show parsed scope details, including targets, objectives, constraints,
methodology notes, testing depth, and raw scope content when parsing fails.

## VPN setup

VPN configuration is available during task creation. The task form supports
HackTheBox, TryHackMe, and custom providers, and can load an OVPN/config/text
file or accept manual OpenVPN-style configuration text.

VPN setup should be treated as task-specific connectivity for approved lab or
customer environments. Do not publish reusable VPN profiles, credentials,
private endpoints, or customer configuration.
