Platform

Everything Umbra does.

Each capability links to its documentation.

Continuous discovery

the port scanner-driven port scans on every target, rescheduled on an operator-tunable cadence with per-target scan windows.

HTTP + TLS deep probe

Status, full headers, response body, page title, TLS cert chain, favicon hash, and a non-HTTP banner grab for every open port.

Product / version fingerprinting

Curated rules + technology detection assign product, version, vendor, category, and CPE to every probed service.

Host OS inference

OS attribution per host, voted from every service-level fingerprint we've collected for it, no banner-spoof fragility.

Geo + ASN enrichment

Country, region, city, ASN, AS-org for every IP, free, powered by an offline DB-IP Lite dataset — no IP is sent to a geolocation API.

Attack-surface map

Visual topology of the whole surface: hosts, services, and their relationships on one pan/zoom canvas. A first-class nav module, not a static export.

Companies + tags

Group targets by acquisition, business unit, or product line. Filter findings by company; share reports per-tenant.

Bulk targets + excludes

Paste 10,000 targets at once, attach per-target exclude lists (IPs / CIDRs) honoured by both the port scanner and ignore rules.

Asset business context

Tag every target with owner, criticality, data classification, and vendor. Risk-ranking finally reflects what hurts the business, not raw CVSS.

Cloud security posture

AWS, Google Cloud & Azure, read-only: world-readable data, privesc to admin, secrets in config, internet-open services. ~75 checks across 37 enumerators.

Attack paths & read-proof

Internet-reachable workload → its identity → the specific data it can read. Public storage proven by an anonymous, credential-free read.

Remediation output

Every finding ships the exact aws / gcloud / az command that removes it, built from its real resource id, with a guardrail: read-only, never auto-applied.

Cloud posture PDF report

Export any scan to a branded PDF: cover, posture summary, and every finding with its fix inline. Same template as the pentest reports.

CVE matching + KEV

Matched against the full NVD corpus, gated by the detected version so patched builds don't false-positive. CISA KEV + EPSS rank what to fix first; matches are tagged version-confirmed vs product-only, and you can mark a CVE not-affected to suppress it.

Per-CVE validation

Click 'Verify' on any CVE. The AI agent runs the exploit chain end-to-end and writes a one-page PoC. Optional auto-verify runs it for you on new actively-exploited (KEV) findings.

Default-credential checks

Deterministic default-credential checks run on demand: no Check spent, and the same result every time, runs the same checks every time.

Cinematic replay + sharing

Step-by-step run timeline with the exact requests/responses; share a public, password-gated link with the team that needs the fix.

Audits and Checks

The two counted units, what each covers, and the long list of things that are never counted.

Lumi: AI security analyst

Named AI persona that ranks your top issues and answers 'why is this severity / what's the fix' from inside each finding drawer.

Deep Audit run

End-to-end paid audit: 56-module DAST scan, AI triage, AI exploration, merged report (one Audit, up to ten related backends, AI processing included).

Active AI Triager

Triager probes ambiguous findings live against the target instead of pattern-matching to false-positive guards. Confirms what's real, rejects what's noise.

Tier 1 · endpoint hypothesis

Reads the scanner's recon model and proposes the endpoints + vuln classes most likely to harbour real bugs. Narrows the search before any probe fires.

Tier 2 · scenario playbooks

Ten scripted scenarios for the classes static rules can't reach: IDOR/BFLA, OAuth redirect bypass, JWT confusion, GraphQL abuse, mass assignment, price manipulation, role tampering, workflow bypass, multi-step ATO, cross-tenant UUID.

Tier 3 · open hunt

Opus-grade open exploration on the full recon bundle (clustered endpoints + JS-derived URLs + discovered params). Hunts for what the scripted scenarios missed.

Live scan timeline

Module-by-module progress: recon iterations, crawl complete, JS endpoint discovery, fuzzbox phases, every scanner module's start + complete, not a frozen progress bar.

Triager review queue

Findings the AI couldn't judge with high confidence land in a per-scan review queue with the original scanner payload + error reason: review, accept, or replay.

Partial-coverage transparency

When a scan hits its time or AI budget mid-run, the report renders with a clear partial-coverage badge. You see what was covered and what wasn't, no silent drop-offs.

AI-orchestrated assessments

Run assessment → the 84-technique assessment catalogue (54 of them native, spending no Checks at all) — a different, broader set than the agent’s internal-network list × N services × 3 safety tiers, fanned out as parallel AI runs with one rollup view. Catalog spans Active Directory, databases & datastores, remote access, cloud & federated identity, network & infrastructure devices, and web & CI/CD.

AD attack-graph

BloodHound-vocabulary principals + edges (MemberOf, AdminTo, GenericAll, WriteDACL, …) populated automatically by the ad_recon technique. No separate collector, no manual import.

One-line install

Linux amd64 / arm64, macOS Apple Silicon, Windows amd64. Paste-once enrollment token, outbound HTTPS only.

Recurring internal scans + scan windows

Schedule internal CIDR scans on a cadence, optionally restricted to a maintenance window; auto re-probe when services flip to gone.

AI exploit network leg (HTTP)

The cloud AI routes every internal-target HTTP request through the agent. RFC1918 web apps + admin panels become first-class for exploit validation.

Binary-protocol testing via the agent

Same relay, raw bytes. AI talks Postgres, MySQL, Redis, MongoDB, SSH and friends through the agent: auth-method discovery + banner grabs on internal databases.

CIDR allowlist enforced at the agent

Pushed on every heartbeat; the agent refuses to probe outside its authorised scope, defence in depth above the cloud-side check.

Signed auto-update + rollback

sha256 + ed25519 verification before swap; auto-rollback if the new binary doesn't heartbeat within 5 minutes.

Captured task logs

Every task ships a timestamped log buffer back to the dashboard. Click 'Logs' on a task row to read it inline.

Health, uninstall, proxy, pinning

Loopback /healthz, --uninstall, HTTPS proxy support, --pinned-version override, JSON config file.

System service install (systemd / launchd / Windows SCM)

One-line --install registers the agent as a proper system service that persists across reboots and SSH disconnects. Linux + macOS + Windows; --disable / --enable / --status lifecycle commands included.

SmartSearch grammar

20+ tokens across services / hosts / findings / targets: product, port, cve_severity, internal, compromised, has_cve, and more.

Natural-language query

Type 'critical CVEs on internal apache'. Claude Haiku translates to the tokenised query in <1s.

Inline help drawers

Every major view has a right-side drawer with full token documentation + click-to-run examples. Discoverable, not tucked away.

Findings dashboard

Every AI-verified finding across the surface, filterable by severity / kind / company / agent / internal-vs-external.

Findings lifecycle

Stateful findings (open → in_progress → fixed → verified), assignee, due date, history, bulk actions. The operating system for a remediation program.

Executive report (board-ready)

Org-level PDF for the board: posture KPIs, opened-vs-closed trend chart, top remediations, top open risks. Print → Save as PDF.

Per-target full findings report

One page per target: every host, every service, every verified finding, ready to hand off.

Management report (per-run)

Non-technical executive summary of a single AI run: multilingual, print-ready, shareable.

Weekly email digest

One email a week with critical / high open, fixed-this-week, MTTR, top 5 open risks. Same data as the executive dashboard, delivered to the inbox.

Compliance evidence pack

Map Umbra's data to SOC 2, ISO 27001, NIS2, and GDPR Article 32 control IDs. Generate the artifact, hand it to your auditor, no spreadsheet reconciliation.

Shareable compliance pack

Mint a password-gated public link to a redacted compliance evidence pack. Hand it to your customer's security team instead of writing a questionnaire response.

Activity feed + What's new

Every state change in the org. Filter by time window, type, or scope. The audit trail for security ops.

ChatOps (Slack)

OAuth-bound Slack app with five slash commands: /umbra services, /umbra findings, /umbra ask (NL), /umbra run, /umbra report. MS Teams + Discord on the roadmap.

Notification channels + rules

Slack, email digests, and generic outbound webhooks. Per-channel severity filters; suppression rules for the noisy categories.

Rules starter pack

One click creates the three notification rules every workspace wants on day one: exploitable / KEV / critical, with sensible rate limits.

One-click ticket creation

Create a Jira or GitHub Issues ticket from any finding: title, severity, PoC excerpt, replay link pre-filled. Linear on the roadmap.

Bidirectional ticket sync

Jira + GitHub Issues webhooks: close the ticket, the finding closes; close the finding, the ticket transitions. Operator-tunable status maps for any custom workflow.

SIEM outbound (Splunk + Sentinel)

Stream every Umbra finding into Splunk HEC or Microsoft Sentinel as a structured event. Correlate against the rest of your SecOps feeds.

Workspaces + SSO

Per-org isolation. Google + Microsoft OIDC sign-in. Email invites with role pre-selection.

Module access control

Per-org module bundles gate what a plan unlocks; on top, an org-admin can restrict a teammate to specific modules (allow-by-default, server-enforced): lock a user to Deep Audit only. The Essential+ granular-access differentiator.

Roles + audit log

viewer / member / admin / owner. Every privileged action (target add/remove, AI run, agent revoke) logged with actor + timestamp + scope.

Audit log viewer

Filter / search / paginate every privileged action in the workspace. CSV export for SOC2 / ISO27001 auditors. org_admin-gated.

Self-serve billing

Paddle-backed: subscribe, top up AI dollars, upgrade plan, all from the workspace settings. Cancel at any time.

Partner API (v1) + per-org keys

Bearer-token authenticated read API at /api/v1/... (pull findings, targets, host inventory as JSON). Org admin mints keys; partner consumes them.