Scan target url or not with urls found in a previous spider or present in a session. Active scanning as user attempts to find potential vulnerabilities by using known attacks against the selected targets (this is done while the user is authenticated).