Documentation

Docs

Concept overviews and step-by-step guides for every part of Umbra. For programmatic access, see the Partner API.

65 articles · 14 sections
Getting started · 5 min → Asset-pool model Audits and Checks Install the agent

Start here

1 article
Getting started
guide

From signup to your first vulnerability report in five minutes.

/docs/getting-started

Concepts

2 articles
The asset-pool model
concept

Why we count tracked hosts, not discovered hosts, and how to swap them.

/docs/asset-pool
AI validation
concept

What the agent does, what it costs, how to set ceilings.

/docs/ai-validation

AI exploit engine

4 articles
Default-credential checks
feature

Deterministic default-credential checks run on demand (no Check spent, and the same result every time).

/docs/features/default-credentials
Cinematic replay + sharing
feature

Step-by-step run timeline with the exact requests and responses; share via password-gated public link.

/docs/features/cinematic-replay
Audits and Checks
feature

The two counted units, what each one covers, what is never counted, and where to see your remaining allowance.

/docs/features/ai-cost-controls
Lumi, your AI security analyst
feature

A named AI persona that explains findings, suggests next steps, and answers why-does-this-matter questions without sending you to a search engine.

/docs/features/lumi

Attack-surface mapping

8 articles
Continuous discovery
feature

Recurring the port scanner port-scans across your entire target surface, on operator-tunable cadence.

/docs/features/continuous-discovery
HTTP + TLS deep probe
feature

Status, headers, body, title, favicon hash, TLS cert chain, banner (for every open port).

/docs/features/deep-probing
Product / version fingerprinting
feature

Every probed service gets product, version, vendor, category, and CPE, driven by curated rules and technology detection.

/docs/features/fingerprinting
Host OS inference
feature

Per-host OS attribution voted from every service-level fingerprint we've collected.

/docs/features/os-detection
Geo + ASN enrichment
feature

Country, region, city, ASN, AS-org for every IP (free, offline, on every scan).

/docs/features/geo-enrichment
Companies + tags
feature

Group targets by business unit, acquisition, or product. Filter findings per-tenant; share scoped reports.

/docs/features/companies-tags
Bulk targets + excludes
feature

Paste 10,000 targets at once. Attach per-target exclude lists honoured by both scanner and ignore rules.

/docs/features/bulk-targets
Asset business context
feature

Tag every target with owner, criticality, data classification, and vendor. Risk-ranking finally reflects what hurts the business, not raw CVSS.

/docs/features/asset-context

Vulnerability intelligence

2 articles
CVE matching + KEV
feature

Every fingerprinted service gets matched against NVD + curated advisory feeds + curated intel; CISA KEV listings surface first.

/docs/features/cve-intel
Per-CVE validation
feature

Click 'Verify' on any CVE. The AI agent runs the exploit chain end-to-end and writes a one-page PoC.

/docs/features/per-cve-validation

Scanning

1 article
Deep Audit
feature

End-to-end paid web application audit. The scanner sweeps the app, AI triages every finding, AI hunts for what scanners miss (IDOR, OAuth bypass, business logic). One Audit per scan, up to ten related backends included, capped AI cost, no surprise bills.

/docs/features/deep-audit

Cloud posture

4 articles
Cloud security posture
feature

Read-only across AWS, Google Cloud & Azure. Umbra finds the exposure a port scan can't see (world-readable data proven with an anonymous read, identities that can escalate to admin, secrets in config, internet-open services) and the attack paths that chain them to your data. Every finding ships with the exact command that fixes it.

/docs/features/cloud-inventory
Cloud attack paths & read-proof
feature

Umbra chains cloud findings into data-terminating attack paths (an internet-reachable workload → the identity it runs as → the specific data it can read) and proves public storage by fetching it with no credentials.

/docs/features/cloud-attack-paths
Cloud remediation output
feature

Every cloud finding ships with its concrete, resource-specific fix: the exact aws / gcloud / az command that removes the exposure, built from the finding's own evidence, with a guardrail to check before you apply it.

/docs/features/cloud-remediation
Cloud posture PDF report
feature

Export any cloud scan to a branded PDF (cover page, posture summary, per-finding detail with the exact remediation inline, and sign-off), the same report template as the internal-pentest and web-audit exports.

/docs/features/cloud-report

Deep Audit

7 articles
Active AI Triager
feature

Triager probes ambiguous scanner findings live against the target instead of pattern-matching to false-positive guards. Confirms what's real, drops what's noise.

/docs/features/ai-triager-active
AI Explorer · Tier 1 endpoint hypothesis
feature

Reads the scanner's recon model and proposes the endpoints + vuln classes most likely to harbour real bugs. Narrows the search before any probe fires.

/docs/features/ai-explorer-tier1
AI Explorer · Tier 2 scenario playbooks
feature

Ten scripted scenarios for the classes static rules can't reach (IDOR, OAuth bypass, JWT confusion, GraphQL abuse, mass assignment, price manipulation, role tampering, workflow bypass, multi-step ATO, cross-tenant UUID).

/docs/features/ai-explorer-tier2
AI Explorer · Tier 3 open hunt
feature

Opus-grade open exploration on the full recon bundle (clustered endpoints + JS-derived URLs + discovered params). Hunts for what the scripted scenarios missed.

/docs/features/ai-explorer-tier3
Deep Audit · live scan timeline
feature

Module-by-module progress for an in-flight audit (recon iterations, crawl complete, JS endpoint discovery, fuzzbox phases, every scanner module's start + complete).

/docs/features/deep-audit-live-timeline
Deep Audit · Triager review queue
feature

Findings the AI couldn't judge with high confidence land in a per-scan review queue with the original scanner payload and the AI's error reason: review, accept, or replay.

/docs/features/deep-audit-review-queue
Deep Audit · partial-coverage transparency
feature

When a scan hits its time or AI budget mid-run, the report renders with a clear partial-coverage badge. You see what was covered and what wasn't, no silent drop-offs.

/docs/features/deep-audit-partial-coverage

Internal Network Agent

9 articles
Internal agent (one-line install)
feature

5 MB Go binary. Linux amd64/arm64, macOS Apple Silicon, Windows amd64. Outbound HTTPS only.

/docs/features/agent-installation
Recurring internal scans + scan windows
feature

Schedule internal CIDR scans on a cadence; optionally restrict to a maintenance window; auto-reprobe when services flip to gone.

/docs/features/agent-recurring-scans
AI exploit network leg (HTTP)
feature

The cloud AI routes every internal-target HTTP request through the agent. RFC1918 web apps + admin panels become first-class for exploit validation. For non-HTTP protocols (Postgres / MySQL / Redis / Mongo / SSH), see the companion TCP relay.

/docs/features/agent-ai-relay
Binary-protocol testing via the agent (TCP)
feature

Same relay as the HTTP leg, raw bytes. AI sends Postgres / MySQL / Redis / MongoDB / SSH wire-protocol packets through the agent into the customer network. Auth-method discovery, banner grabs, default-credential testing on internal databases, not just HTTP services.

/docs/features/agent-tcp-relay
CIDR allowlist enforced at the agent
feature

Defence in depth above the cloud-side scope check. Heartbeat-pushed CIDR list, locally enforced; refuses out-of-scope tasks without a single socket touched.

/docs/features/agent-scope-allowlist
Signed auto-update + rollback
feature

sha256 + ed25519 verification before swap; auto-rollback if the new binary doesn't heartbeat within 5 minutes.

/docs/features/agent-auto-update
Captured task logs
feature

Every task ships a timestamped log buffer back to the dashboard. Click 'Logs' on a task row to read it inline.

/docs/features/agent-task-logs
Agent ops (healthz, uninstall, proxy, pinning)
feature

Loopback /healthz, --uninstall, HTTPS proxy support, --pinned-version override, JSON config file.

/docs/features/agent-ops
System service install (systemd / launchd / Windows SCM)
feature

One-line --install registers the agent as a system service that persists across reboots, survives SSH disconnects, and exposes a clean --disable / --enable / --status / --uninstall lifecycle. Linux + macOS + Windows.

/docs/features/agent-daemon

Internal pentest

2 articles
Internal pentest assessments
feature

One click. A whole catalog of techniques fires against every live service the agent has discovered. Three safety tiers, one rollup view, every finding tagged by the technique that produced it.

/docs/features/assessments
AD attack-graph
feature

BloodHound-style principals + edges, populated automatically by AD reconnaissance techniques. See who is admin to what, who is a member of which group, and which ACL edges enable escalation.

/docs/features/ad-attack-graph

Reports and visibility

10 articles
Findings dashboard
feature

Every AI-verified finding across the surface, filterable by severity, kind, company, agent, internal-vs-external.

/docs/features/findings-dashboard
Findings lifecycle
feature

Stateful findings with status, assignee, due date, history: the operating system for a remediation program.

/docs/features/findings-lifecycle
Per-target full findings report
feature

One page per target: every host, every service, every verified finding, ready to hand off.

/docs/features/target-reports
Management report
feature

Executive-grade summary (counts, trends, KEV exposure, compromised-host index, print-ready).

/docs/features/management-report
Activity feed + What's new
feature

Every state change in the org: filterable by time window, type, or scope.

/docs/features/activity-feed
Executive report
feature

Org-level, board-ready PDF: posture KPIs, opened-vs-closed trend, top remediations, top open risks. Print → Save as PDF.

/docs/features/executive-report
Executive dashboard
feature

"What to fix this week": KPI tiles, top-10 priority issues, MTTR, all on one card above the findings list.

/docs/features/executive-dashboard
Weekly email digest
feature

One email a week with the workspace's posture (critical / high open, fixed-this-week, MTTR, top 5 open risks). Same data as the executive dashboard, delivered to the inbox.

/docs/features/weekly-digest
Compliance evidence pack
feature

Map Umbra's data to specific SOC 2, ISO 27001, NIS2, and GDPR Article 32 control IDs and hand the artifact to your auditor (no spreadsheet reconciliation).

/docs/features/compliance-evidence-pack
Shareable compliance pack
feature

Mint a password-gated public link to a redacted compliance evidence pack. Hand it to your customer's security team instead of writing a questionnaire response.

/docs/features/compliance-share

Integrations

7 articles
ChatOps (Slack)
feature

OAuth-bound Slack app with five slash commands for investigation, exploitation, and reporting, without opening the dashboard.

/docs/features/chatops
Notification channels + rules
feature

Slack webhooks, email digests. Per-channel severity filters; suppression rules for the noisy categories.

/docs/features/notifications
Rules starter pack
feature

One click creates the three notification rules every workspace wants on day one, no manual rule-engine learning curve.

/docs/features/rules-starter-pack
Ticket integrations
feature

One-click tickets to Jira, Linear, or GitHub from any finding. PoC + reproduction steps pre-filled.

/docs/features/tickets
Bidirectional ticket sync
feature

Jira and GitHub Issues: close the ticket, the finding closes. Close the finding, the ticket transitions. Custom status maps per workspace.

/docs/features/bidirectional-sync
SIEM outbound (Splunk + Sentinel)
feature

Stream every Umbra finding into Splunk HEC or Microsoft Sentinel: one event per finding, correlated against the rest of your SecOps feeds.

/docs/features/siem-export
Partner API (v1)
feature

Bearer-token authenticated read API for B2B partners + integrators. Pull findings, targets, host inventory, and deep audit reports as JSON.

/docs/features/partner-api

Workspaces and access

5 articles
Workspaces + SSO
feature

Per-org isolation. Google + Microsoft OIDC sign-in. Email invites with role pre-selection.

/docs/features/workspaces-sso
Roles + audit log
feature

viewer / member / admin / owner, plus per-user module access. Every privileged action logged with actor, timestamp, and scope.

/docs/features/roles-audit
Audit log viewer
feature

Org-scoped audit-trail UI, every privileged action, filterable by action / actor / date, with a CSV export for SOC2 / ISO27001 auditors.

/docs/features/audit-log
Self-serve billing
feature

Paddle-backed checkout. Subscribe, upgrade, and manage your plan from workspace settings.

/docs/features/pricing-billing
Module access & entitlements
feature

Two layers of module gating: per-org bundle entitlement (what the plan sells) and per-user module grants (an org-admin restricts a teammate to specific modules). Allow-by-default, dependency-closed, server-enforced, fails closed.

/docs/features/module-access
Can’t find it?

Your targets and findings are readable over the Partner API, and Lumi answers most “how do I” questions from inside the app.

Partner API Start free