the port scanner-driven port scans on every target, rescheduled on an operator-tunable cadence with per-target scan windows.
Status, full headers, response body, page title, TLS cert chain, favicon hash, and a non-HTTP banner grab for every open port.
Curated rules + technology detection assign product, version, vendor, category, and CPE to every probed service.
OS attribution per host, voted from every service-level fingerprint we've collected for it, no banner-spoof fragility.
Country, region, city, ASN, AS-org for every IP, free, powered by an offline DB-IP Lite dataset — no IP is sent to a geolocation API.
Visual topology of the whole surface: hosts, services, and their relationships on one pan/zoom canvas. A first-class nav module, not a static export.
Group targets by acquisition, business unit, or product line. Filter findings by company; share reports per-tenant.
Paste 10,000 targets at once, attach per-target exclude lists (IPs / CIDRs) honoured by both the port scanner and ignore rules.
Tag every target with owner, criticality, data classification, and vendor. Risk-ranking finally reflects what hurts the business, not raw CVSS.
AWS, Google Cloud & Azure, read-only: world-readable data, privesc to admin, secrets in config, internet-open services. ~75 checks across 37 enumerators.
Internet-reachable workload → its identity → the specific data it can read. Public storage proven by an anonymous, credential-free read.
Every finding ships the exact aws / gcloud / az command that removes it, built from its real resource id, with a guardrail: read-only, never auto-applied.
Export any scan to a branded PDF: cover, posture summary, and every finding with its fix inline. Same template as the pentest reports.
Matched against the full NVD corpus, gated by the detected version so patched builds don't false-positive. CISA KEV + EPSS rank what to fix first; matches are tagged version-confirmed vs product-only, and you can mark a CVE not-affected to suppress it.
Click 'Verify' on any CVE. The AI agent runs the exploit chain end-to-end and writes a one-page PoC. Optional auto-verify runs it for you on new actively-exploited (KEV) findings.
Deterministic default-credential checks run on demand: no Check spent, and the same result every time, runs the same checks every time.
Step-by-step run timeline with the exact requests/responses; share a public, password-gated link with the team that needs the fix.
The two counted units, what each covers, and the long list of things that are never counted.
Named AI persona that ranks your top issues and answers 'why is this severity / what's the fix' from inside each finding drawer.
End-to-end paid audit: 56-module DAST scan, AI triage, AI exploration, merged report (one Audit, up to ten related backends, AI processing included).
Triager probes ambiguous findings live against the target instead of pattern-matching to false-positive guards. Confirms what's real, rejects what's noise.
Reads the scanner's recon model and proposes the endpoints + vuln classes most likely to harbour real bugs. Narrows the search before any probe fires.
Ten scripted scenarios for the classes static rules can't reach: IDOR/BFLA, OAuth redirect bypass, JWT confusion, GraphQL abuse, mass assignment, price manipulation, role tampering, workflow bypass, multi-step ATO, cross-tenant UUID.
Opus-grade open exploration on the full recon bundle (clustered endpoints + JS-derived URLs + discovered params). Hunts for what the scripted scenarios missed.
Module-by-module progress: recon iterations, crawl complete, JS endpoint discovery, fuzzbox phases, every scanner module's start + complete, not a frozen progress bar.
Findings the AI couldn't judge with high confidence land in a per-scan review queue with the original scanner payload + error reason: review, accept, or replay.
When a scan hits its time or AI budget mid-run, the report renders with a clear partial-coverage badge. You see what was covered and what wasn't, no silent drop-offs.
Run assessment → the 84-technique assessment catalogue (54 of them native, spending no Checks at all) — a different, broader set than the agent’s internal-network list × N services × 3 safety tiers, fanned out as parallel AI runs with one rollup view. Catalog spans Active Directory, databases & datastores, remote access, cloud & federated identity, network & infrastructure devices, and web & CI/CD.
BloodHound-vocabulary principals + edges (MemberOf, AdminTo, GenericAll, WriteDACL, …) populated automatically by the ad_recon technique. No separate collector, no manual import.
Linux amd64 / arm64, macOS Apple Silicon, Windows amd64. Paste-once enrollment token, outbound HTTPS only.
Schedule internal CIDR scans on a cadence, optionally restricted to a maintenance window; auto re-probe when services flip to gone.
The cloud AI routes every internal-target HTTP request through the agent. RFC1918 web apps + admin panels become first-class for exploit validation.
Same relay, raw bytes. AI talks Postgres, MySQL, Redis, MongoDB, SSH and friends through the agent: auth-method discovery + banner grabs on internal databases.
Pushed on every heartbeat; the agent refuses to probe outside its authorised scope, defence in depth above the cloud-side check.
sha256 + ed25519 verification before swap; auto-rollback if the new binary doesn't heartbeat within 5 minutes.
Every task ships a timestamped log buffer back to the dashboard. Click 'Logs' on a task row to read it inline.
Loopback /healthz, --uninstall, HTTPS proxy support, --pinned-version override, JSON config file.
One-line --install registers the agent as a proper system service that persists across reboots and SSH disconnects. Linux + macOS + Windows; --disable / --enable / --status lifecycle commands included.
20+ tokens across services / hosts / findings / targets: product, port, cve_severity, internal, compromised, has_cve, and more.
Type 'critical CVEs on internal apache'. Claude Haiku translates to the tokenised query in <1s.
Every major view has a right-side drawer with full token documentation + click-to-run examples. Discoverable, not tucked away.
Every AI-verified finding across the surface, filterable by severity / kind / company / agent / internal-vs-external.
Stateful findings (open → in_progress → fixed → verified), assignee, due date, history, bulk actions. The operating system for a remediation program.
Org-level PDF for the board: posture KPIs, opened-vs-closed trend chart, top remediations, top open risks. Print → Save as PDF.
One page per target: every host, every service, every verified finding, ready to hand off.
Non-technical executive summary of a single AI run: multilingual, print-ready, shareable.
One email a week with critical / high open, fixed-this-week, MTTR, top 5 open risks. Same data as the executive dashboard, delivered to the inbox.
Map Umbra's data to SOC 2, ISO 27001, NIS2, and GDPR Article 32 control IDs. Generate the artifact, hand it to your auditor, no spreadsheet reconciliation.
Mint a password-gated public link to a redacted compliance evidence pack. Hand it to your customer's security team instead of writing a questionnaire response.
Every state change in the org. Filter by time window, type, or scope. The audit trail for security ops.
OAuth-bound Slack app with five slash commands: /umbra services, /umbra findings, /umbra ask (NL), /umbra run, /umbra report. MS Teams + Discord on the roadmap.
Slack, email digests, and generic outbound webhooks. Per-channel severity filters; suppression rules for the noisy categories.
One click creates the three notification rules every workspace wants on day one: exploitable / KEV / critical, with sensible rate limits.
Create a Jira or GitHub Issues ticket from any finding: title, severity, PoC excerpt, replay link pre-filled. Linear on the roadmap.
Jira + GitHub Issues webhooks: close the ticket, the finding closes; close the finding, the ticket transitions. Operator-tunable status maps for any custom workflow.
Stream every Umbra finding into Splunk HEC or Microsoft Sentinel as a structured event. Correlate against the rest of your SecOps feeds.
Per-org isolation. Google + Microsoft OIDC sign-in. Email invites with role pre-selection.
Per-org module bundles gate what a plan unlocks; on top, an org-admin can restrict a teammate to specific modules (allow-by-default, server-enforced): lock a user to Deep Audit only. The Essential+ granular-access differentiator.
viewer / member / admin / owner. Every privileged action (target add/remove, AI run, agent revoke) logged with actor + timestamp + scope.
Filter / search / paginate every privileged action in the workspace. CSV export for SOC2 / ISO27001 auditors. org_admin-gated.
Paddle-backed: subscribe, top up AI dollars, upgrade plan, all from the workspace settings. Cancel at any time.
Bearer-token authenticated read API at /api/v1/... (pull findings, targets, host inventory as JSON). Org admin mints keys; partner consumes them.