Prioritizing requires a list, and the list comes from the scope. Registered network ranges, assets with scanning credentials, domains handed over at kick-off. It is a deliberate cut, and it is what makes scanning predictable and auditable.
The side effect shows up outside. The company that arrived with an acquisition and kept its own domain, the admin panel published alongside an integration, the staging environment raised for a demo and left running: none of them was declared, so none of them is ordered by any score.
CSURFACE starts from the root domain, with no prior list. It discovers what answers on the internet, attributes each asset to its owner by technical trace and by legal ownership, and validates exploitability over what it found, delivering the finding with the evidence the target itself returned.
The two coexist, and the useful reading is the gap between the two lists: the one your program already orders, and the one answering on the internet right now.