# Deployment
Source: https://docs.snapsec.co/deployments
Deploy Snapsec Suite effortlessly on-prem or in the cloud with full data control and quick setup.
Snapsec Suite offers flexible deployment options designed to match your organization’s infrastructure and compliance needs.
Choose between a **self-hosted On-Premise setup** or a **fully managed Cloud account** — both providing the same unified AppSec experience.
***
## Deployment Options
Host Snapsec Suite within your own infrastructure for complete data ownership and compliance assurance.
Instantly launch a managed Snapsec instance on our secure cloud — ready in minutes.
***
## On-Premise Deployment
* **Data Control:** Full ownership with **0-log retention** — no vulnerability or asset data ever leaves your environment.
* **Setup Time:** Typically **under 1 hour** with guided installation.
* **Requirements:**
* Linux or Windows Server
* 8 GB RAM (minimum)
* Docker installed and running
* **Ideal For:** Enterprises with strict data residency or compliance mandates.
> 💡 Snapsec provides detailed installation scripts and support for both air-gapped and connected environments.
***
## Cloud Deployment
* **Setup Time:** Complete provisioning and onboarding in **less than 10 minutes**.
* **Managed by Snapsec:** All updates, scaling, and monitoring handled automatically.
* **Same Experience:** Identical dashboards, modules, and integrations as the on-prem edition.
* **Ideal For:** Teams seeking instant access, zero maintenance, and rapid scaling.
***
## Security & Privacy Highlights
* Unified platform security across both deployment models.
* Role-based access control and encryption at rest/in transit.
* No shared tenancy for on-prem; dedicated cloud instances for every organization.
* Optional integration with your existing SSO and CI/CD pipelines.
***
## Next Steps
Follow our quickstart guide to set up your organization and start securing your assets today.
# Feature Overview
Source: https://docs.snapsec.co/features/introduction
Explore the key capabilities that power Snapsec’s Suite.
## Vulnerability Management
A comprehensive breakdown of the features offered in Snapsec’s Vulnerability Management module.
Centralized view of all vulnerabilities with live metrics, trends, and remediation analytics.
Manage security tests as assessments with their own metrics, members, and evidence.
Track every finding from discovery to remediation with clear states and ownership visibility.
Monitor SLA performance, detect breaches, and visualize remediation timelines in real time.
Automatically discover and maintain an up-to-date inventory of all your assets across environments.
Handle remediation blockers like business impact or severity revalidation collaboratively.
Link vulnerabilities with change requests, releases, and patch tracking workflows.
Contextual risk scoring for assets based on associated vulnerabilities and exposure.
Connect with Jira, Qualys, Trivy, Nuclei, AIM, and more to automate imports and sync tickets.
Generate executive-ready vulnerability and revalidation reports with rich customization.
Quickly locate vulnerabilities, assets, or assessments using advanced filters and keywords.
Use Snapsec VM as a centralized ticketing layer for any scanner or CI/CD workflow — powered by adapters.
***
## Attack Surface Management
A comprehensive breakdown of the features offered in Snapsec’s Attack Surface Management module.
A centralized view to visualize all discovered assets, ports, certificates, and exposures in real time.
Automatically detect, track, and update every internet-facing asset to keep your inventory always current.
Identify live and inactive subdomains, track WAF status, open ports, and exposure level for each.
Analyze open and closed ports across assets to uncover exposed services and reduce attack vectors.
Monitor SSL/TLS certificates for validity, expiry, and misconfigurations to maintain trust and compliance.
Manage and analyze DNS records (A, MX, TXT, SOA) to detect misconfigurations and takeover risks.
Detect and catalog technologies used across your assets for better risk visibility and patch prioritization.
Automatically surface risky assets like internal IPs or staging portals with severity-based tagging.
Automate exposure classification with custom YAML logic based on asset properties and vulnerability data.
Run manual or scheduled scans to detect new assets and visualize historical discovery trends.
Generate and export detailed PDF reports for exposed assets, open ports, and quarterly ASM summaries.
Sync discovered assets and exposures with Snapsec VM for unified remediation and lifecycle tracking.
***
## Asset Inventory Management
A comprehensive breakdown of the features offered in Snapsec’s Asset Inventory Management module.
Centralized visibility of all assets — APIs, IPs, domains, repositories, registries, certificates, and more.
Connect with tools like Cloudflare, GitHub, OCI, and Postman to auto-discover and sync assets in real time.
Automatically classify assets by environment, owner, and exposure using YAML-based rule automation.
Visualize and manage every layer of your digital ecosystem — from APIs to employees — for complete organizational awareness.
Automatically evaluate asset risk using vulnerability data, exposure status, and contextual associations.
Keep your asset inventory continuously refreshed through self-updating adapters that discover and sync new assets automatically.
Assign, track, and visualize asset ownership across teams, departments, and business units for better governance and accountability.
Public, read-only access to company-wide asset inventory for faster collaboration and transparency.
Empower users to edit and enrich asset information directly — fostering shared visibility and data accuracy across teams.
Visualize cross-asset dependencies and simulate impact to prioritize fixes that reduce the most risk.
Manage staged or retired assets with audit history and secure reactivation controls.
Tag, group, and export your inventory data seamlessly for audits, reporting, or analytics.
***
## Vulnerability Scanner
A comprehensive breakdown of the features offered in Snapsec’s Vulnerability Scanner module.
A centralized dashboard showing real-time vulnerability metrics, detection trends, affected assets, and top findings — instant visibility into your security posture.
Every finding includes severity badges, asset context, environment details, state, and metadata to help teams focus on what truly matters.
Findings synced to Snapsec VM automatically inherit SLA timelines, breach alerts, and remediation rules without manual work.
Maintain a complete catalog of all scannable assets across your infrastructure with real-time health and scan coverage.
Organize assets by Prod/Dev/Cloud Units or custom groups to run structured, repeatable scans at scale.
All detected issues stored in one place with advanced search, filtering, suppression, and historical insights.
Send findings directly into VM workflows or external tools like Jira for end-to-end remediation tracking.
Schedule weekly, monthly, or custom recurring scans to ensure continuous visibility across your assets.
***
## Web Application Scanner
A comprehensive breakdown of the features offered in Snapsec’s Web Application Scanner module.
Unified visibility into all API requests across projects — including methods, URLs, collections, and vulnerability counts.
A consolidated view of all detected API vulnerabilities with severity, status, timestamps, suppression, and scan mappings.
Create and manage isolated Test, Dev, Sandbox, and custom environments, each with its own variable set.
Automatically apply environment-specific values (URLs, tokens, IDs) to requests and scans for accurate, context-aware testing.
Build and modify custom API security rules using YAML — supporting transforms, response checks, and CWE-based detection logic.
Monitor every API scan with progress, rules applied, and vulnerability results in a single centralized view.
Create reusable scan profiles with consistent headers (Authorization, API keys) for authenticated and repeatable testing.
Integrations with Postman, Swagger, and other adapters to auto-import and sync API definitions — keeping endpoints updated for accurate, real-time security scanning.
***
## Explore Live Demo
Follow our quickstart guide to set up your organization and start securing your assets today.
# Snapsec Suite
Source: https://docs.snapsec.co/index
A centralized AppSec platform unifying discovery, vulnerability management, intelligence, and protection across your entire ecosystem.
## Welcome to Snapsec Suite
Snapsec is a unified platform designed to help you **discover, assess, and manage security risks** across your entire environment.
Each module focuses on a specific part of the security lifecycle — but they all work together seamlessly through a shared data layer.
Start by selecting a module below based on what you want to do.
***
## Choose Your Starting Point
Track vulnerabilities, manage remediation workflows, enforce SLAs, and monitor progress across teams.
Discover and monitor external-facing assets, subdomains, and exposures in real time.
Build and manage a centralized inventory of assets with ownership, tagging, and contextual intelligence.
Run automated scans using integrated scanners and import findings directly into your workflow.
Test and monitor web applications and APIs for vulnerabilities through continuous scanning.
***
## How Everything Connects
Snapsec modules are designed to work together — not in isolation.
* **ASM → AIM**
Discovered assets automatically become part of your inventory
* **AIM → VM**
Assets are enriched with vulnerability context and ownership
* **VS → VM**
Scan results are converted into actionable vulnerabilities
* **VM → WAS / VS**
Issues can be re-tested and validated continuously
This creates a **single, connected workflow** from discovery to remediation.
***
## Suggested Workflow
If you're new, follow this flow:
1. **Start with ASM**
Discover what assets exist
2. **Move to AIM**
Organize and assign ownership
3. **Run scans via VS or WAS**
Identify vulnerabilities
4. **Manage everything in VM**
Track, prioritize, and remediate issues
***
## What You Can Do Next
Dive into detected issues and start managing remediation workflows.
Understand what exists in your environment and who owns it.
Launch scans and start identifying security issues.
Track exposed assets and detect changes in real time.
***
## Explore Live Demo
Access the full Snapsec Suite and explore each module in action.
# Integrations
Source: https://docs.snapsec.co/integrations/vm/index
List of all integrations supported in Snapsec VM.
Issue tracking and project management integration.
Comprehensive vulnerability management and assessment.
Network vulnerability scanning and assessment integration.
Import vulnerabilities from CSV files.
Asset and inventory management integration.
Upload vulnerability data manually.
Fast template-based scanner for APIs, applications, and infrastructure.
Scanner for containers, IaC, dependencies, secrets, and cloud configs.
Lightweight static analysis tool for code security.
Python-focused static analysis for security flaws.
Semantic static analysis for deep vulnerability detection.
Code quality and security analyzer.
Dynamic application security testing.
Container vulnerability analysis tool.
Container vulnerability scanner.
SBOM generation for containers and filesystems.
Secret scanning tool for repositories.
Git repository secret detection.
Secret detection in repos and CI/CD pipelines.
Policy-as-code scanning for IaC.
Terraform security scanning.
IaC security scanning tool.
Multi-cloud security auditing.
Cloud configuration posture scanning.
AWS security assessment tool.
Kubernetes security scanning and compliance.
Kubernetes CIS benchmark evaluation.
Kubernetes penetration testing.
Vulnerability detection in third-party libraries.
Python dependency vulnerability checker.
Node.js dependency vulnerability scanner.
Web Application Scanning for identifying web security vulnerabilities.
Enterprise-grade static application security testing (SAST).
Task and remediation workflow management integration.
Web server vulnerability and misconfiguration scanner.
Web application security scanner for vulnerability discovery.
Project and remediation tracking integration.
***
## Supported Integrations
Snapsec Vulnerability Management integrates with a wide range of security, cloud, DevSecOps, and workflow tools to centralize vulnerability data and streamline remediation workflows.
Integrations automatically normalize findings from multiple sources into a unified vulnerability management workflow.
***
## Explore Live Demo
See how Snapsec aggregates findings from scanners, cloud platforms, code analysis tools, and ticketing systems into a single vulnerability management platform.
# Account & Administrator
Source: https://docs.snapsec.co/products/admin/account-and-adminstrator
Manage personal profile, authentication, security preferences, notifications, and workspace appearance from a single control center.
## Overview
The **Account & Settings** page acts as the central control center for user identity, security posture, and workspace personalization within Snapsec.\
It allows users to manage their personal profile, secure their account, configure preferences, and control notification behavior — all from one unified interface.
This page is designed to balance **usability, security, and governance**, ensuring users can manage their account without impacting organizational controls.
***
## Personal Information
The **Personal Info** section allows users to manage their individual profile details.
### What You Can Manage
* Profile photo (JPEG / PNG)
* First name and last name
* Basic identity details associated with the account
These details are reflected across assessments, reports, comments, and activity logs to maintain accurate attribution.
***
## Login & Security
The **Login & Security** section focuses on protecting account access and preventing unauthorized usage.
### Password Management
* Update current password securely
* Enforce confirmation for password changes
* Immediate application across all sessions
### Two-Factor Authentication (2FA)
* **OTP via Email** — Receive one-time passwords by email
* **Authenticator App (TOTP)** — Use apps like Google Authenticator or Authy
Enabling 2FA significantly reduces the risk of account compromise.
Security changes take effect immediately and may require re-authentication on active sessions.
***
## Advanced Settings
The **Advanced Settings** section allows users to customize how Snapsec behaves and communicates.
***
### Preferences
Configure localization and regional preferences:
* **Language** — Interface language
* **Time Zone** — Used across reports, SLAs, and activity timelines
* **Currency** — Display currency for billing and cost-related views
These settings ensure consistent reporting and time-based accuracy.
***
### Appearance
Customize the visual appearance of your workspace:
* **Dark Mode**
* **Light Mode**
* **System Default**
Appearance settings apply instantly and help align Snapsec with user accessibility or system preferences.
***
### Notifications
Control how and when Snapsec notifies you about important events.
#### Email Notifications
* Critical
* High
* Medium
* Low
* Remediation updates
* Status changes
#### Slack Notifications
* Severity-based alerts
* Remediation updates
* Status changes
Notifications can be fine-tuned to avoid alert fatigue while ensuring critical issues are never missed.
***
## Delete Account
Users can permanently delete their account from this section.
### Important Notes
* Deletion is **irreversible**
* All personal data associated with the account is permanently removed
* Organizational access may be revoked immediately
Account deletion cannot be undone. Ensure all responsibilities are transferred before proceeding.
***
## Why This Matters
* **Security-first access control** with strong authentication and 2FA
* **Clear identity attribution** across vulnerabilities, reports, and activities
* **Personalized workspace experience** without affecting org-wide policies
* **Granular notification control** to stay informed without overload
Account & Settings ensures every user operates securely, efficiently, and with full control over their Snapsec experience.
***
## Explore Live Demo
Experience how Snapsec API keys power secure integrations, automation, and scalable security workflows—no signup required.
# Developer Access
Source: https://docs.snapsec.co/products/admin/api-keys
Manage developer authentication, API access, and Model Context Protocol (MCP) integrations for AI-powered development environments.
# Developer Access
## API Keys
## Overview
The **API Keys** module allows organizations to securely authenticate applications, adapters, and integrations with Snapsec.
API keys act as a **trusted access mechanism**, enabling programmatic communication between Snapsec services and external systems without exposing user credentials.
This module is essential for teams building integrations, automating workflows, or extending Snapsec’s capabilities across environments.
***
## Public API Key
Each workspace is issued a **Public API Key** that can be used to authenticate requests.
### Key Capabilities
* **Secure Authentication** — Verifies the identity of calling applications.
* **Easy Access** — Copy or regenerate the key directly from the UI.
* **Controlled Exposure** — Designed for programmatic use without sharing user credentials.
The API key acts as a gateway for all supported Snapsec integrations.
***
## What You Can Do With API Keys
API keys unlock multiple integration and automation use cases:
### Connect Adapters
Link adapters across applications to enable seamless data exchange between Snapsec modules and external tools.
### Access Secure Routes
Authenticate requests to protected APIs, ensuring only authorized services can access sensitive endpoints.
### Automate Integrations
Trigger events, sync data, and orchestrate workflows across connected systems without manual intervention.
### Monitor Usage
Track API activity, request frequency, and integration performance to maintain visibility and security.
***
## API Key FAQs
The **FAQ section** answers common questions related to API usage and security, including:
* What the API key is used for
* Whether one key can support multiple adapters or apps
* How to rotate or regenerate keys
* Environment scoping (dev / staging / prod)
* Steps to take if a key is compromised
* How to limit API key capabilities
These FAQs help teams adopt APIs safely while following best security practices.
***
## Support & Assistance
If you need help with API integrations, security concerns, or advanced use cases, the **Contact Support** section provides direct access to the Snapsec support team for personalized assistance.
***
## Why This Matters
API keys enable **secure automation and extensibility** across Snapsec:
* Eliminates the need for shared credentials
* Enables scalable integrations across teams and products
* Supports automation-driven security workflows
* Provides visibility and control over programmatic access
Proper API key management ensures integrations remain powerful, auditable, and secure.
***
## MCP Access
The **MCP (Model Context Protocol) Access** module allows organizations to securely connect AI-powered development environments with Snapsec. It provides centralized configuration, IDE-specific setup guides, and visibility into active MCP connections, enabling developers to interact with Snapsec directly from their preferred coding environment.
***
## MCP Configuration
The **MCP Configuration** page is used to enable and manage organization-wide MCP access.
Administrators can:
* Enable or disable MCP integration for the organization
* Configure supported IDEs and AI clients
* Access ready-to-use configuration snippets
* Follow IDE-specific setup instructions
* Secure connections using existing Snapsec API keys
Supported clients include:
* Antigravity
* Codex CLI
* Cursor
* Visual Studio Code
* Windsurf
* Zed
Each client provides a complete configuration snippet, setup guide, prerequisites, and security recommendations for establishing a secure connection.
Store API keys securely using environment variables or a secrets manager. Avoid embedding credentials directly in configuration files.
***
## MCP Sessions
The **MCP Sessions** page provides real-time visibility into all active MCP connections established within the organization.
For every session, Snapsec displays:
* Connected IDE or client
* Device type
* Associated user
* Current session status
* Number of vulnerability requests
* Session creation time
This centralized view helps administrators monitor usage, audit connected clients, and verify active developer access.
***
## Session Filtering
Sessions can be filtered to quickly locate connections associated with specific users.
Available filters allow administrators to:
* View sessions for individual users
* Identify unassigned sessions
* Simplify auditing of active MCP connections
* Monitor developer activity across connected IDEs
Filtering makes it easier to investigate usage, troubleshoot connections, and review organization-wide MCP activity.
***
## Why Use MCP Access?
MCP Access enables secure AI-assisted development by connecting supported IDEs directly with Snapsec.
Key benefits include:
* Centralized MCP management
* Secure AI development workflows
* Ready-to-use IDE configurations
* Organization-wide access control
* Real-time session visibility
* Secure authentication using Snapsec API keys
***
## Explore Live Demo
Experience how Snapsec securely connects AI development environments through Model Context Protocol (MCP).
# Company Profile
Source: https://docs.snapsec.co/products/admin/company-profile
Configure and manage your organization’s identity, legal details, and branding across the Snapsec platform.
## Overview
The **Company Profile** section defines your organization’s identity inside Snapsec.\
It acts as the authoritative source for company-level information that appears across reports, dashboards, exports, and shared assets.
This configuration ensures that every security artifact generated from Snapsec—whether internal or external—correctly represents your organization with consistent metadata and branding.
***
## Company Profile Details
The Company Profile page is divided into two primary areas: **General Information** and **Branding**.
***
### General Information
This section captures core organizational identifiers used for governance, reporting, and compliance.
**Fields included:**
* **Company Name** — Official organization name displayed across the platform.
* **Phone Number** — Primary contact reference for administrative or audit purposes.
* **VAT Number** — Tax identifier used for billing and regulatory documentation.
* **Registration Number** — Legal business registration reference.
* **Remote Company ID** — Internal or external identifier used for integrations or enterprise mappings.
These details help ensure traceability and accuracy when generating executive reports, audit exports, or compliance evidence.
***
### Branding
Branding settings control how your organization is visually represented across Snapsec-generated content.
**Branding options include:**
* **Company Logo** — Displays your corporate logo across dashboards and reports.
* **Company Logo URL** — External reference for hosted logo assets.
* **Primary Brand Color** — Main accent color used across UI elements and documents.
* **Secondary Brand Color** — Supporting color for visual consistency.
Branding ensures that all exported reports, PDFs, and shared views maintain your organization’s identity—especially important for client-facing or executive deliverables.
***
## Why This Matters
* **Consistent identity** across reports, dashboards, and exports
* **Professional, branded reporting** for clients and executives
* **Accurate organizational metadata** for compliance and audits
* **Centralized control** over company-wide presentation
Company Profile ensures Snapsec reflects **your organization — not just your data**.
***
## Explore Live Demo
Experience how Snapsec applies organization-wide settings across security workflows in real time.
# Departments
Source: https://docs.snapsec.co/products/admin/departments
Create, manage, and organize organizational departments and their associated teams within Snapsec.
## Overview
The **Departments** module helps organizations structure users into logical business units such as *IT*, *HR*, *Sales*, or *Engineering*.\
Departments act as the **top-level organizational layer**, enabling better ownership, access control, reporting alignment, and team management across Snapsec.
Each department can contain multiple teams, department leads, and members—allowing security operations to scale cleanly across large organizations.
***
## Departments List
This view displays all existing departments within your organization.
### What You See Here
* **Department Name** — Logical business unit (e.g., IT Department).
* **Description** — Short context about the department’s responsibility.
* **Team Count** — Number of teams associated with the department.
* **Quick Access** — Click any department to view its internal structure.
This list gives admins instant visibility into how users and teams are distributed across the organization.
***
## Department FAQs
The **FAQs section** answers common administrative and structural questions related to departments.
### Covered Topics Include
* What a department represents in Snapsec
* How to create or delete departments
* Whether departments can contain multiple teams
* Who is allowed to manage departments
* Limits on the number of departments
This section is designed to reduce onboarding friction for administrators and clarify organizational modeling decisions.
***
## Inside a Department
When you click on a department, you are taken to its **detailed view**.
### Department Details
* **Department Lead** — Primary owner responsible for the department.
* **Department Name** — Editable name of the department.
* **Description** — Functional summary of the department’s role.
All fields are editable (subject to permissions), ensuring departments stay aligned with organizational changes.
***
## Teams Within a Department
Below the department details, you’ll find the **Teams table**, listing all teams mapped to this department.
### Team Information Includes
* **Team Name**
* **Team Description**
* **Team Lead**
* **Total Members**
* **Actions** — Remove or manage teams
This structure allows granular ownership while maintaining department-level accountability.
***
## Adding a Team to a Department
Admins can assign new or existing teams to a department using the **Add Team** action.
### Use Cases
* Expanding department responsibilities
* Reorganizing teams after internal changes
* Aligning teams with reporting or access boundaries
This ensures departments remain flexible as organizations evolve.
***
## Update Department Teams
The **Update Department Teams** modal provides a controlled way to manage team assignments.
### What You Can Do
* Add multiple teams to a department
* Remove teams that no longer belong
* Update mappings without affecting team members directly
Changes take effect immediately across reporting, access control, and ownership views.
***
## Why This Matters
Departments provide the **foundation for structured access control and accountability** inside Snapsec.
* Enables clean separation of responsibilities
* Improves ownership for vulnerabilities and assessments
* Aligns security workflows with real-world org structures
* Scales seamlessly as teams and users grow
Well-defined departments ensure Snapsec mirrors how your organization actually operates.
***
## Explore Live Demo
Experience how Snapsec organizes departments, teams, and users to deliver scalable security governance.
# Integration
Source: https://docs.snapsec.co/products/admin/integrations
Learn how to connect Snapsec Suite with IBM QRadar to stream security and audit events in real time.
## What is QRadar Integration
The **QRadar Integration** allows Snapsec Suite to send all system-generated security and audit events directly to **IBM QRadar SIEM**.
Once connected, QRadar can ingest Snapsec events for:
* Centralized logging
* Correlation with other security signals
* Threat detection and investigations
* Compliance and audit visibility
This integration helps security teams gain **real-time visibility** into activities happening across the Snapsec platform from within their existing SIEM workflows.
***
## What Events Does Snapsec Send
Snapsec sends **all system events** to QRadar, including but not limited to:
* User management events (create, update, delete)
* Authentication and authorization actions
* Asset changes
* Vulnerability lifecycle events
* Configuration changes
* Integration and automation activities
* Administrative and audit actions
All events are transmitted in a **structured, consistent schema** to ensure reliable parsing and correlation inside QRadar.
***
## Event Schema
Snapsec sends events in JSON format using the following schema:
```json theme={null}
{
"type": "audit",
"action": "create_user",
"request": {
"url": "/v1/users",
"params": {},
"query": {},
"headers": {
"user-agent": "curl/8.0.1"
}
},
"response": {
"body": {
"id": "u_123",
"status": "created"
},
"headers": {
"content-type": "application/json"
}
},
"metadata": {
"ip": "203.0.113.10",
"userId": "admin_1",
"traceId": "abc-xyz"
},
"timestamp": "2026-01-27T10:15:30.000Z"
}
```
### Field Overview
* **type**\
The category of the event.\
Example: `audit`
* **action**\
The specific action performed within Snapsec.\
Example: `create_user`, `delete_asset`
* **request**\
Details about the API request that triggered the event, including:
* URL
* Parameters
* Query values
* Request headers
* **response**\
The result of the action, including:
* Response body
* Response headers
* **metadata**\
Additional contextual information such as:
* IP address of the actor
* User ID who performed the action
* Trace ID for request correlation
* **timestamp**\
The exact time when the event occurred, formatted in ISO 8601.
## How to Connect Snapsec with QRadar
Log in to **Snapsec Suite** and click on your profile icon in the top-right corner.
Select **Integrations** from the settings sidebar.
Locate **QRadar** from the list of available integrations and click on it.
Provide the following information:
* QRadar URL
* Bearer Token
Click **Save** to enable the integration.\
Once completed, QRadar will appear under **Installed Adapters**, confirming the connection.
## Verification
After installation, verify the integration using the following checks:
* Confirm the adapter status is shown as **Installed** in Snapsec.
* Check **QRadar logs** to ensure Snapsec events are being received.
* Verify that events are **parsed and indexed correctly** inside QRadar for search and correlation.
***
## Explore Live Demo
Experience how Snapsec API keys power secure integrations, automation, and scalable security workflows—no signup required.
# Members Management
Source: https://docs.snapsec.co/products/admin/members
Manage users, roles, invitations, and access control across your organization.
## Overview
The Members section is where you control **who has access to your platform and what they can do**.
It covers:
* Member management
* Role-based access control
* Quick account creation
* Invitations (email + link)
* Activity visibility
***
## Members List
### What You Can Do
* View all members and their roles
* Track status (Active / Inactive)
* See recent activity
* Access quick actions
***
## Column Customization
You can toggle columns like:
* Member
* Team
* Department
* Role
* Status
* Recent Activity
***
## Roles & Access Control
### Role Definitions
* **Administrator**\
Full control over the platform, including users, settings, and all modules
* **Manager**\
Can manage vulnerabilities, workflows, and team-level operations
* **Member**\
Standard user with access to assigned tasks and resources
* **Developer**\
Focused access for fixing vulnerabilities and working on technical items
* **Auditor**\
Read-only access for reviewing reports, findings, and compliance
***
## Quick Account Setup
Create a user instantly by entering:
* Email
* Name
* Role
* Team
No invite flow needed — account is created immediately.
***
## Invite Members
Send invitations directly:
1. Enter email
2. Assign role
3. Assign team
4. Click **Invite**
User joins after accepting the invite.
***
## Invite via Link
* Generate a unique invite link
* Share it with your team
* Users can join instantly
⚠️ Keep the link secure — it grants access.
***
## Invited Members
You can:
* See pending invites
* Track status
* Manage access before acceptance
***
## Invite Workflow Overview
This helps teams onboard users quickly without manual setup.
***
## Pending Registrations
Track users who:
* Haven’t completed signup
* Haven’t activated their account
***
## Pending Registration Details
Useful for:
* Following up with users
* Cleaning inactive invites
***
## Edit Member
You can update:
* Role
* Team
* Assigned modules
* Product access
***
## Remove Member
Removing a member:
* Immediately revokes access
* Removes them from all assigned resources
***
## Product Access Control
Each member can have access to specific modules:
* Vulnerability Management
* Vulnerability Scanning
* Web Application Security
* Asset Inventory
* Attack Surface Management
This ensures **least-privilege access** across the platform.
***
## Key Value
* Centralized user control
* Clear role-based access
* Flexible onboarding (instant + invite)
* Secure collaboration across teams
***
## Explore Live Demo
Experience how Snapsec API keys power secure integrations, automation, and scalable security workflows—no signup required.
# Security
Source: https://docs.snapsec.co/products/admin/security
Monitor active sessions, review device access, and audit security events across your Snapsec workspace.
## Overview
The **Security** section provides visibility and control over how users access your Snapsec workspace.\
It is designed to help organizations monitor login activity, identify suspicious behavior, and maintain a complete audit trail of security-relevant actions.
This section answers three critical questions:
* **Who is accessing the workspace?**
* **From which devices and locations?**
* **What actions are being performed?**
Together, these controls help enforce accountability, detect anomalies, and support compliance requirements.
***
## Current Sessions
The **Current Sessions** view displays all active and recent user logins across the organization.
### What You Can See
* **User identity** — name and role (Admin / Member)
* **Last login time** — when the session was initiated
* **Browser & OS** — Chrome, Firefox, Windows, Linux, etc.
* **Login device** — Desktop or other device types
This allows administrators to quickly identify:
* Unexpected logins
* Duplicate or concurrent sessions
* Access from unfamiliar platforms
***
## Device Security
The **Device Security** section focuses on *where* access is coming from.
Each entry represents a device that has successfully authenticated to the workspace.
### Why This Matters
* Helps detect compromised or shared credentials
* Identifies stale or unused access paths
* Supports device-level access reviews during audits
Administrators can regularly review this list to ensure that only trusted devices are accessing sensitive environments.
***
## Security Logs
**Security Logs** provide a complete, immutable audit trail of actions performed within the platform.
### Logged Information Includes
* **Event title** — what action occurred
* **User** — who performed the action
* **HTTP method** — GET, POST, PUT, etc.
* **Action type** — read, write, update
* **Origin & URL** — API or UI source
* **IP address** — source of the request
* **Timestamp** — exact time of activity
These logs are essential for:
* Incident investigations
* Compliance and audit reviews
* Detecting misuse or abnormal behavior
Security logs are read-only and cannot be modified, ensuring audit integrity.
***
## FAQs
### 1. What is this API key used for?
API keys authenticate requests and identify calling applications or adapters.\
They allow secure access to protected routes and integrations.
### 2. Can I use one API key for multiple adapters or apps?
Yes, a single API key can be reused across multiple adapters unless restricted by policy.
### 3. How do I rotate or regenerate my API key?
API keys can be regenerated from the **API Keys** section.\
Rotating keys regularly is recommended for security hygiene.
### 4. Are API keys tied to specific environments (dev/staging/prod)?
Keys can be scoped or labeled per environment depending on your internal access strategy.
### 5. What should I do if a key is leaked or compromised?
Immediately rotate the key and review security logs to identify any unauthorized usage.
### 6. Can I limit what an API key can do?
Yes. Permissions and scopes can be applied to restrict access to only required actions.
## Why This Matters
Security is not just about prevention — it is about **visibility and traceability**.
By combining session monitoring, device awareness, and detailed logs, Snapsec enables organizations to:
* Detect suspicious access early
* Enforce accountability across teams
* Maintain compliance with security and audit standards
* Respond faster during security incidents
This turns workspace access from a blind spot into a **controlled, observable system**.
***
## Explore Live Demo
Jump straight into the live environment and see how Snapsec unifies access control, activity logging, and security visibility — all from a single dashboard.
# Teams
Source: https://docs.snapsec.co/products/admin/teams
Create, organize, and manage teams within departments to control access, ownership, and collaboration across your organization.
## Overview
The **Teams** module allows organizations to group users into functional units within departments.\
Teams help define **ownership**, **responsibility**, and **access boundaries** across products, assessments, and workflows.
Each team belongs to a department and can have a designated **team lead**, multiple members, and a clear scope of responsibility.
***
## Teams List
The Teams page displays all teams configured in the organization, along with their department association and member visibility.
Each team card shows:
* **Team name**
* **Parent department**
* **Short description**
* **Member avatars and count**
This view gives administrators a quick snapshot of how users are organized across the organization.
***
## Teams — FAQs
### Common Questions
* **What is a team?**\
A team is a group of users working together under a department with shared responsibilities.
* **How do I create a new team?**\
Teams are created within a department by authorized administrators or department leads.
* **Can a team belong to multiple departments?**\
No. Each team is associated with a single department to maintain clear ownership.
* **Who can manage teams?**\
Team Leads, Department Admins, and System Administrators.
* **Can users belong to multiple teams?**\
Yes. A user can be part of multiple teams if required.
***
## Viewing a Team
Clicking on a team opens the **Team Details** page.
### Team Info Section
This section provides editable metadata about the team:
* **Team Lead** — The primary owner of the team
* **Team Name** — Display name used across the platform
* **Description** — Explains the team’s role or responsibility
These fields help define accountability and ownership across workflows.
***
## Team Members
Below the Team Info section is the **Members Table**, listing all users assigned to the team.
Each row displays:
* **Member name**
* **Email address**
* **Lead status**
* **Actions** (remove member)
The table supports search, pagination, and column controls for easier management.
***
## Adding Members to a Team
Use the **Add Members** button to assign new users to the team.
* You can add multiple users at once
* Members immediately inherit team-level access and visibility
* Changes apply across all linked products and workflows
***
## Update Team Members
The **Update Team Members** modal allows you to:
* Add or remove users using a searchable multi-select
* Review current assignments before saving
* Apply changes instantly across the system
This modal ensures fast, controlled updates without navigating away from the team view.
***
## Why This Matters
Teams form the foundation of **access control**, **ownership**, and **collaboration** in Snapsec.
By organizing users into teams, organizations can:
* Assign responsibility clearly
* Control access at scale
* Align security workflows with real-world team structures
* Maintain clean audit trails and accountability
***
## Explore Live Demo
Jump straight into the live environment and see how Snapsec manages teams, departments, and access — all from a single control plane.
# Advanced Search
Source: https://docs.snapsec.co/products/aim/advanced-search
Build powerful queries to filter, segment, and analyze assets across your inventory.
## Overview
**Advanced Search** enables precise filtering across your entire asset inventory using structured and nested query logic.
***
## 1. Access Advanced Search
Use the **Query Wizard** to move beyond basic filters and build complex queries.
***
## 2. Query Wizard
The Query Wizard allows you to:
* Apply predefined presets
* Build custom filters
* Combine multiple conditions
***
## 3. Building Queries
You can:
* Select fields (IP, domain, owner, etc.)
* Apply conditions (equals, contains, etc.)
* Group rules with AND / OR logic
***
## 4. Filtered Results
Once applied, results update instantly to reflect matching assets.
***
## 5. Deep Asset View
From results, you can:
* Open asset details
* Analyze security posture
* Explore relationships and metadata
***
## Why This Matters
* Quickly isolate high-risk assets
* Segment infrastructure by context
* Reduce noise in large inventories
* Enable targeted investigation
***
## Explore Live Demo
Instantly explore how Snapsec AIM helps you filter and investigate assets in real time.
# Agent Settings
Source: https://docs.snapsec.co/products/aim/agent-settings
Configure, install, and manage agents across different operating systems to ensure continuous asset data ingestion.
## Overview
The **Agent Settings** module allows you to install, configure, and manage agents across multiple operating systems.
Agents are responsible for collecting asset data and sending it to the platform in real time. This section provides installation commands, prerequisites, and operational controls for managing agents efficiently.
***
## Installation (Linux)
### Prerequisites
* Root or sudo access
* `curl` installed
* Systemd for service management
### Steps
1. Run the installation command
2. Verify installation using systemctl
***
## Agent Management (Linux)
### Available Commands
* **Check Status** — Verify if the agent is running
* **View Logs** — Monitor real-time logs
* **Restart Agent** — Restart the service
* **Stop Agent** — Stop agent execution
* **Uninstall Agent** — Remove agent and disable service
***
## Installation (Windows)
### Prerequisites
* Administrator privileges
* PowerShell 5.1 or higher
* Internet connectivity
### Steps
1. Execute PowerShell installation command
2. Verify using Windows service check
***
## Agent Management (Windows)
### Available Commands
* **Check Status** — Get-Service
* **View Logs** — Read agent log file
* **Restart Agent** — Restart-Service
* **Stop Agent** — Stop-Service
* **Uninstall Agent** — Remove service completely
***
## Installation (macOS)
### Prerequisites
* Administrator access
* Homebrew (optional for service management)
* curl installed
### Steps
1. Run installation script via terminal
2. Verify using brew services
***
## Agent Management (macOS)
### Available Commands
* **Check Status** — Verify via brew services
* **View Logs** — Tail log files
* **Restart Agent** — Restart service
* **Stop Agent** — Stop service
* **Uninstall Agent** — Remove binary and service
***
## Agent Ingestion Control
Agent ingestion can be toggled directly from the interface.
* **Enabled** — Agents actively send data
* **Disabled** — Data collection is paused
This allows controlled ingestion during maintenance or troubleshooting.
***
## Why This Matters
* Ensures continuous asset visibility across environments
* Standardizes agent deployment across OS platforms
* Simplifies troubleshooting using built-in commands
* Provides full lifecycle control of agents
***
## Explore Live Demo
Experience how Snapsec AIM enables seamless agent deployment, real-time monitoring, and cross-platform management from a single interface.
# Agents
Source: https://docs.snapsec.co/products/aim/agents
Monitor and manage registered agents responsible for asset discovery, data collection, and real-time updates within your infrastructure.
## Overview
The **Agents** module provides visibility into all registered agents that continuously collect and update asset data across your infrastructure.
It enables teams to monitor agent health, activity, and ensure data ingestion pipelines remain active and reliable.
***
## Registered Agents
This view lists all agents currently connected to the platform.
### Key Information
* **Hostname** — Device or system running the agent
* **IP Address** — Network identifier of the agent
* **OS / Platform** — Operating system (Windows, Linux, Darwin, etc.)
* **Version** — Installed agent version
* **Status** — Current operational state (Active/Inactive)
* **Last Heartbeat** — Last communication timestamp
***
## Agent Status & Health
Agents continuously send heartbeat signals to indicate availability.
### What It Means
* **Active** — Agent is online and reporting data
* **Recent heartbeat** — Confirms real-time connectivity
* **Delayed heartbeat** — May indicate connectivity or system issues
This ensures asset data remains fresh and continuously updated.
***
## Agent Actions
Each agent includes an action menu for management operations.
### Available Action
* **Delete Agent**\
Removes the agent from the system and stops further data collection from that source
***
## Why This Matters
* Ensures continuous asset discovery across environments
* Helps identify inactive or failing agents quickly
* Maintains accuracy of asset inventory data
* Provides control over data collection sources
***
## Explore Live Demo
See how Snapsec AIM tracks agent activity, monitors health in real time, and ensures continuous asset visibility across your infrastructure.
# Alerts
Source: https://docs.snapsec.co/products/aim/alerts
Create automated alerting rules to detect policy violations and notify stakeholders in real-time.
## Overview
Violations and Alerts enable you to detect risky or non-compliant assets and trigger real-time notifications.
These rules continuously evaluate asset data and notify relevant teams when defined conditions are met — helping you respond faster to security and compliance issues.
***
## Alerts List
This screen provides a centralized view of all alert rules.
### Key Elements
* **Name & Description** — Defines what the alert detects
* **Enabled Toggle** — Activate or disable alerts instantly
* **Matched Assets** — Assets currently violating the rule
* **Created On** — Rule creation timestamp
* **Actions Menu** — Manage alert behavior
***
## Create a Violation Rule
To create a new alert:
1. Click **Create Violation**
2. Open the guided policy builder
3. Define rule conditions and alert behavior
***
## Guided Policy Builder
This builder allows you to define when an alert should trigger.
### Rule Configuration
* **Rule Name** — Unique name for the alert
* **Description** — Optional explanation
### Conditions
Define trigger logic:
* Select a field
* Choose an operator (equals, contains, etc.)
* Provide a value
### YAML Preview
A real-time YAML representation is generated for transparency and advanced users.
***
## Configure Alert Channels
Once conditions are defined, configure how alerts are delivered.
### Email Channel
* **Recipients** — Comma-separated email addresses
* **Subject** — Alert title
* **Template** — Custom notification message
Supports dynamic variables like:
* `{{matchedAssetCount}}`
* `{{ruleName}}`
* `{{matchedAssets}}`
This ensures alerts are contextual and actionable.
***
## Manage Alerts
Each alert includes the following actions:
* **Edit Alert** — Modify conditions or channels
* **Execute Now** — Run the rule instantly
* **Delete Rule** — Remove the alert
***
## Execute All Rules
Use **Execute All Rules** to evaluate all alert conditions across your assets at once.
This ensures your alerts reflect the latest asset state.
***
## Why This Matters
* Detects security risks in real-time
* Automates incident awareness
* Reduces manual monitoring effort
* Enables faster response to violations
***
## Explore Live Demo
See how Snapsec AIM detects violations and sends real-time alerts based on your defined policies.
# APIs
Source: https://docs.snapsec.co/products/aim/apis
Discover, analyze, and investigate APIs with deep visibility into endpoints, vulnerabilities, authentication posture, and asset relationships.
## Overview
The **APIs** module provides a centralized and enriched inventory of all APIs discovered across your organization.
It combines **endpoint visibility, vulnerability data, authentication insights, and ownership context** into a single interface — enabling teams to identify exposed, risky, or unmanaged APIs quickly.
***
## Dashboard View
The dashboard provides a high-level understanding of API posture before diving into individual services.
### Key Metrics
* **Total APIs** — All discovered APIs
* **No Auth APIs** — APIs without authentication (high risk)
* **Vulnerable APIs** — APIs with security findings
* **Critical APIs** — High severity APIs
### Visual Insights
* **Vulnerability Distribution** — Severity breakdown
* **Environment Distribution** — Production vs others
* **Internal vs External APIs** — Exposure scope
* **HTTP Method Distribution** — GET, POST, PATCH, DELETE, etc.
* **Auth Distribution** — Authenticated vs unauthenticated
* **Workspace Distribution** — API ownership across teams
***
## Inventory View
The inventory is the **operational layer** for API discovery and triage.
### Key Columns
| Column | Description |
| ------------------- | --------------------------------- |
| **API Name** | Service or API identifier |
| **Endpoint Count** | Total endpoints mapped to the API |
| **Vulnerabilities** | Number of findings |
| **Owner** | Responsible user |
| **Detected On** | First & last detection timestamps |
### Filters
* **Is Vulnerable**
* **Workspace**
* **Search by API Name**
***
## API Asset View
Clicking an API opens a **deep inspection view**.
### General Information
* **Asset ID**
* **Type (API)**
* **API Name**
* **Environment**
* **Internal Asset (Yes/No)**
* **Is New**
* **Associated Assets**
* **First / Last Detected**
### Ownership Context
* **User**
* **Team**
* **Department**
This ensures **clear accountability for every API**.
***
## Security Overview
### Security Data
* **Total Vulnerabilities**
* **Severity Breakdown** (Critical, High, Medium, Low, Info)
* **Open vs Closed Vulnerabilities**
* **Aggregate CVSS Score**
* **Remediation Progress**
* **Test Status**
* **Last Scan Date**
***
## Endpoint Visibility
Each API is mapped to its underlying endpoints, providing **true operational visibility**.
### Endpoint Data Includes
* **HTTP Method** (GET, POST, PATCH, DELETE)
* **Endpoint Path**
* **Associated API**
* **Endpoint Type**
### Example Endpoints
| Method | Endpoint |
| ------ | ------------------------ |
| GET | /util/v1/engine/rules |
| POST | /util/v1/engine/rules |
| PATCH | /util/v1/engine/rule/:id |
| DELETE | /util/v1/engine/rule/:id |
This allows teams to:
* Understand **attack surface at endpoint level**
* Identify **sensitive or critical operations**
* Detect **overexposed APIs**
***
## Asset Relationships
APIs are not isolated — they are connected to other assets.
### Relationships Include
* **Endpoints**
* **Applications**
* **Services**
* **Other infrastructure assets**
This enables:
* **Dependency mapping**
* **Blast radius analysis**
* **Impact assessment during incidents**
***
## Data Sources (Adapters)
API data is enriched through integrations:
* **Postman** — Fetch API endpoints from collections
* **Vulnerability Management** — Attach security findings
These integrations ensure APIs are not just discovered, but **contextually enriched**.
***
## Why This Matters
The APIs module transforms API discovery into **actionable security intelligence**:
* Identify **unauthenticated APIs instantly**
* Detect **shadow or unmanaged APIs**
* Analyze **endpoint-level exposure**
* Track **vulnerabilities with real context**
* Enforce **ownership and accountability**
* Understand **API dependencies and impact**
***
## Explore Live Demo
Instantly explore how Snapsec AIM discovers, enriches, and analyzes APIs in real time — all without creating an account.
# Applications
Source: https://docs.snapsec.co/products/aim/apps
Discover, monitor, and manage applications across your organization with visibility into ownership, exposure, and relationships.
## Overview
The **Applications** module provides a centralized inventory of all applications discovered across your environment — including internal services and externally exposed platforms.
It enables teams to track ownership, understand deployment types, and monitor application lifecycle and security posture.
***
## Dashboard View
The dashboard gives a high-level overview of your application landscape.
### Key Metrics
* **Total Applications** — All discovered applications
* **Live Applications** — Currently active applications
* **Vulnerable Applications** — Applications with detected issues
* **Critical Applications** — Applications with critical findings
### Visual Insights
* **Application Type Distribution** — OnPrem vs SaaS
* **Application Source Distribution** — Discovery source (e.g., Cloudflare)
* **Status Distribution** — Lifecycle state of applications
***
## Application Inventory
The inventory view lists all applications with operational and ownership details.
### Table Columns
| Column | Description |
| ------------------------ | -------------------------------- |
| **Asset Value** | Application name and domain |
| **Hosting** | Deployment type (OnPrem / SaaS) |
| **HTTP Response Status** | Response status (if available) |
| **Reachability** | External/Internal visibility |
| **Vuln Count** | Number of linked vulnerabilities |
| **Owner** | Assigned owner |
| **Associations** | Linked assets |
| **Detected On** | Discovery timeline |
### Filters & Search
* **Is Vulnerable**
* **Application Sources**
* **Hosting Type**
* **Search by application name**
***
## Application Asset View
Selecting an application opens a detailed view with complete context.
***
## General Information
Each application includes:
* **Asset ID**
* **Type (Application)**
* **Value (Domain / Identifier)**
* **Environment**
* **Internal Asset (Yes / No)**
* **Associated Assets**
* **First Detected / Last Detected**
***
## Lifecycle Status
Applications support lifecycle tracking directly from the asset view.
Available states:
* **Active** — Currently in use
* **Pending** — Newly discovered and under review
* **Staged** — Pre-production or testing phase
* **Decommissioned** — No longer in use
***
## Application Information
Includes:
* **Application Name**
* **App ID**
* **Domain**
* **Application Type (OnPrem / SaaS)**
* **Status**
* **Source (e.g., Cloudflare)**
* **Allowed IPs**
* **Policies**
* **Identity Providers**
***
## Security Overview
Displays:
* Total vulnerabilities
* Severity breakdown (Critical, High, Medium, Low, Info)
* Open vs closed vulnerabilities
* Aggregate CVSS score
* Remediation progress
***
## Asset Relationships
Applications are connected to other assets within your environment.
This helps teams:
* Understand how applications are linked to subdomains and other assets
* Identify dependencies across the environment
* Analyze impact before making changes
***
## Data Sources (Adapters)
Applications are discovered through integrated data sources.
* Example: **Cloudflare**
* Shows which integrations are contributing asset discovery
***
## Why This Matters
The Applications module helps teams:
* Maintain a complete application inventory
* Track ownership and accountability
* Understand deployment environments (OnPrem vs SaaS)
* Monitor lifecycle states of applications
* Identify security issues across applications
* Gain visibility into asset relationships
***
## Explore Live Demo
Instantly explore how Snapsec AIM discovers, enriches, and tracks applications across your organization — all without creating an account.
# Business Units
Source: https://docs.snapsec.co/products/aim/business-units
Organize and manage assets by business context to gain clear visibility into ownership, risk exposure, and operational impact.
## Overview
**Business Units** provide a logical grouping of assets based on organizational structure, product lines, or operational domains.\
This allows security and engineering teams to understand **who owns what**, **where risk exists**, and **how vulnerabilities impact the business**.
Each business unit aggregates assets, vulnerabilities, and risk signals into a single, actionable view.
***
## 1. Access Business Units
The Business Units page provides a centralized list of all units with key insights:
* **Owner** responsible for the unit
* **Total assets** mapped to the unit
* **Risk classification** (Critical, High, Medium)
* **Open vulnerabilities summary**
* **Last updated timestamp**
This helps quickly identify high-risk areas across the organization.
***
## 2. Create a Business Unit
Click **Create Business Unit** to define a new logical grouping for assets.
This is typically used to represent:
* Products (e.g., Payments, Analytics)
* Teams (e.g., Backend, DevOps)
* Business functions (e.g., Customer Systems, Internal Tools)
***
## 3. Enter Business Unit Details
Provide the following details:
* **Name** – Unique identifier for the unit
* **Description** – Context about its purpose or scope
* **Owner** – Responsible individual or team
* **Logo URL** – Optional visual identifier
This ensures clear accountability and traceability.
***
## 4. Business Unit Overview
The overview dashboard provides:
* **Total associated assets**
* **Open critical vulnerabilities**
* **Total open vulnerabilities**
* **Associated vulnerabilities count**
This acts as a quick snapshot of the unit’s security posture.
***
## 5. Asset & Vulnerability Insights
Visual insights include:
* **Asset trend over time** to track growth or changes
* **Vulnerability distribution** to understand severity spread
* **Asset type distribution** (IPs, repositories, subdomains, etc.)
This helps identify patterns and potential risk concentration.
***
## 6. Risk Assessment
Each business unit is assigned a **risk score** based on multiple factors.
The system categorizes risk into:
* Low
* Medium
* High
* Critical
This enables prioritization across business units.
***
## 7. Configure Risk Parameters
Risk scoring can be influenced using configurable parameters such as:
* **Application exposure** (e.g., internet-facing)
* **Financial impact**
* **User/customer scale**
* **Data sensitivity (confidentiality)**
* **Integrity and availability requirements**
* **Transactional importance**
* **Compliance requirements (e.g., PCI)**
Adjusting these ensures risk reflects real business impact.
***
## 8. Associated Assets
This section lists all mapped assets along with:
* Asset type (IP, repository, subdomain, etc.)
* Owner
* Active vulnerabilities
This provides a direct link between assets and business context.
***
## 9. Add / Manage Assets
Click **Add Assets** to associate new assets with the business unit.
This ensures all relevant resources are included in risk evaluation.
***
## 10. Asset Selection
You can:
* Search assets across inventory
* Select multiple assets
* Add or remove associations dynamically
This keeps business units up to date as infrastructure evolves.
***
## 11. Vulnerabilities View
Displays all vulnerabilities associated with the unit.
If no vulnerabilities are present, the system clearly indicates a **clean security state**, helping teams quickly validate risk posture.
***
## Value
Business Units bridge the gap between **technical assets and business impact** by:
* Establishing clear ownership
* Enabling risk-based prioritization
* Providing contextual visibility into vulnerabilities
* Supporting compliance and reporting needs
***
## Next Steps
* Map all critical assets to appropriate business units
* Configure risk parameters based on your organization
* Regularly review high-risk units and take action
***
## Why This Matters
* Connect asset-level risk to business impact
* Eliminate blind spots across organizational boundaries
* Enable risk-based prioritization per business unit
* Strengthen accountability across teams
***
## Explore Live Demo
Experience how Snapsec AIM groups assets into business units, enabling contextual risk analysis and faster decision-making.
# Certificates
Source: https://docs.snapsec.co/products/aim/certs
Monitor SSL/TLS certificates, track expiry risks, and manage certificate lifecycle across your asset inventory.
## Overview
The **Certificates** section provides complete visibility into all SSL/TLS certificates discovered across your environment.\
It helps teams monitor certificate health, prevent expirations, and understand how certificates are connected to assets like subdomains and services.
***
## Dashboard View
The dashboard provides a high-level overview of certificate posture and expiry risks.
### Key Metrics
* **Total Certificates** — All discovered certificates
* **Expired Certificates** — Certificates no longer valid
* **Expiring Soon** — Certificates nearing expiration
* **Valid Certificates** — Currently active and trusted certificates
***
## Key Insights
### Valid vs Expired
Quickly identify:
* Active certificates
* Expired certificates
Helps prevent downtime caused by missed renewals.
***
### Certificate Authority Distribution
Shows which providers are issuing certificates:
* Let’s Encrypt
* Google Trust Services
* GlobalSign
* Others
Useful for trust analysis and compliance tracking.
***
### Issuer Country
Breakdown of certificate issuers by country:
* Helps detect unusual or unexpected issuance sources
***
### Expiration Timeline
Visualizes when certificates will expire:
* Immediate (\< 1 month)
* Short-term (1–3 months)
* Mid-term (3–6 months)
* Long-term (> 6 months)
Critical for proactive renewal planning.
***
## Inventory Table
The certificates table is the primary view for managing certificate assets.
### Key Columns
| Column | Description |
| --------------- | ----------------------------------------- |
| **Asset Value** | Domain or hostname using the certificate |
| **Status** | Certificate status (Valid, Expired, etc.) |
| **Issued By** | Certificate authority |
| **Valid From** | Certificate start date |
| **Valid Till** | Expiration date |
| **Owner** | Assigned owner |
| **Detected On** | First and last detection timestamps |
***
## Certificate Detail View
Selecting a certificate opens a detailed asset view with full context.
***
## General Information
This section includes:
* **Asset ID**
* **Type (Certificate)**
* **Certificate Value (Fingerprint / Hash)**
* **Issuer Details** (CN, Organization, Country)
* **Last Checked Timestamp**
* **Certificate Status (Valid/Invalid)**
* **Associated Assets**
* **First Detected / Last Detected**
***
## Lifecycle Management
Each certificate can be assigned a lifecycle state:
* **Active** — Currently in use
* **Pending** — Newly discovered or under review
* **Staged** — Prepared but not fully active
* **Decommissioned** — No longer in use
This helps teams track operational status beyond technical validity.
***
## Ownership & Accountability
Certificates can be mapped to:
* **User**
* **Team**
* **Department**
Ensuring clear accountability for renewal and management.
***
## Security Insights
The security section provides:
* Total vulnerabilities linked to the certificate
* Severity breakdown (Critical, High, Medium, Low, Info)
* Open vs closed vulnerabilities
* Aggregate CVSS score
* Remediation progress
***
## Asset Relationships
Certificates are linked to other assets such as:
* Subdomains
* Domains
* Applications
This helps understand **impact before rotation or removal**.
***
## Data Sources
Shows which adapter discovered the certificate (e.g., SSL cert scanner), helping validate data origin and reliability.
***
## Why This Matters
The Certificates module helps teams:
* Prevent outages caused by expired certificates
* Identify weak or misconfigured certificates
* Maintain trust and compliance standards
* Track ownership and accountability
* Understand certificate dependencies across assets
***
## Explore Live Demo
Instantly explore how Snapsec AIM discovers, enriches, and tracks certificates and other assets in real time — all without creating an account.
# Classifiers
Source: https://docs.snapsec.co/products/aim/classifiers
Create and manage classification rules to automatically tag and organize assets based on defined conditions.
## Overview
Asset Classifiers allow you to automatically categorize assets based on predefined conditions.
These rules help identify patterns such as shadow IT, sensitive data exposure, or critical infrastructure, enabling better visibility and faster decision-making across your asset inventory.
***
## Classifier List
This view provides a centralized list of all classifiers.
### Key Elements
* **Name & Description** — Defines the purpose of the classifier
* **Enabled Toggle** — Activate or deactivate rules instantly
* **Matched Assets** — Number of assets currently matching the rule
* **Created On** — Timestamp of rule creation
* **Actions Menu** — Manage individual classifiers
***
## Add a Classifier
To create a new classifier:
1. Click **Add Classifier**
2. Open the guided rule editor
3. Define rule logic and actions
***
## Guided Rule Editor
The guided editor allows you to visually define classification logic.
### Rule Configuration
* **Rule Name** — Unique identifier for the classifier
* **Description** — Optional explanation of rule purpose
### Conditions
Define when the rule should trigger:
* Select a field
* Choose an operator (e.g., equals, contains)
* Provide a value
### Set Fields (Actions)
Define what happens when conditions match:
* Assign classification fields
* Tag or modify asset attributes
### YAML Preview
A real-time YAML representation is generated for transparency and advanced control.
***
## Manage Classifiers
Each classifier includes an action menu with the following options:
* **Execute** — Run the classifier immediately on assets
* **Edit** — Modify rule logic or conditions
* **Delete** — Remove the classifier permanently
***
## Execute All Rules
You can execute all classifiers simultaneously using the **Execute All Rules** option from the main screen.
This ensures all rules are applied across the latest asset data.
***
## Why This Matters
* Automates asset categorization at scale
* Reduces manual tagging effort
* Identifies high-risk or non-compliant assets quickly
* Enables policy-driven asset management
***
## Explore Live Demo
See how Snapsec AIM automatically classifies assets using flexible rule logic and real-time execution.
# Dashboard
Source: https://docs.snapsec.co/products/aim/dashboard
Get a real-time overview of your entire asset inventory with unified visibility across asset types, vulnerabilities, and infrastructure distribution.
## Overview
The **AIM Dashboard** provides a high-level, real-time view of all assets across your organization.\
It centralizes visibility into asset types, vulnerability distribution, and infrastructure composition — enabling security teams to quickly understand their external and internal footprint.
***
## Top-Level Asset Summary
At the top of the dashboard, you get an instant snapshot of your total asset inventory:
* **Total Assets** — Complete count of all discovered assets
* **Subdomains** — All discovered domains and subdomains
* **APIs** — Identified API endpoints and services
* **IP Addresses** — Mapped internal and external IPs
* **Repositories** — Connected code repositories
* **Certificates** — SSL/TLS certificates across assets
* **Employees** — Mapped identities (if integrated)
* **Applications** — Detected applications across environments
This summary helps you quickly assess the scale and diversity of your attack surface.
***
## Asset View Selector
The dashboard includes a **dynamic view selector** (top-right), allowing you to filter insights by asset type:
* Default (All assets)
* Subdomains
* IP Addresses
* Certificates
* Applications
* Repositories
* Object Storage
* APIs
* Employees
***
## Focused Asset Dashboards
Each asset type has its **own dedicated dashboard view**, allowing you to drill into specific asset categories with tailored insights.
When a specific asset type is selected:
* Metrics update **contextually for that asset class only**
* Visualizations reflect **type-specific insights**
* Teams can analyze **risk and distribution in isolation**
* Noise is reduced, enabling **faster decision-making**
***
## Key Visual Insights
### Active Vulnerabilities
A severity-based bar chart showing:
* Critical
* High
* Medium
* Low
* Informational
This helps teams instantly prioritize remediation efforts.
***
### Subdomains Distribution
Breakdown across environments:
* Production
* Development
* Staging
***
### IP Address Classification
* External
* Internal
Helps identify exposed infrastructure.
***
### Code Repositories
Displays total repositories and their activity status.\
Useful for understanding code exposure and supply chain risk.
***
### APIs Overview
Shows API exposure and authentication posture:
* Secured (e.g., bearer token)
* Unauthenticated
***
### Applications Overview
Breakdown by deployment type:
* SaaS
* On-Prem
***
### SSL Certificates
Tracks certificate lifecycle:
* Valid
* Expired
* About to expire
***
### Object Storage
Distribution across cloud providers:
* AWS S3
* Azure Blob
* GCP Storage
* OCI
***
### Registry / Asset State
* Active
* Archived
***
## Why This Matters
The AIM Dashboard transforms fragmented asset data into a **single, actionable intelligence layer**:
* Understand your **complete asset inventory instantly**
* Identify **risk concentration areas quickly**
* Detect **public exposure and weak configurations**
* Analyze **specific asset classes in isolation**
* Enable **faster, data-driven security decisions**
***
## Explore Live Demo
Instantly explore how Snapsec AIM discovers, enriches, and tracks every asset in real time — all without creating an account.
# Employees
Source: https://docs.snapsec.co/products/aim/employees
Track employee identities, understand internal vs external exposure, and monitor activity across your organization.
## Overview
The **Employees** section provides visibility into all employee-linked identities discovered across your environment.\
It helps teams track internal and external users, understand workforce exposure, and maintain accountability for asset ownership.
***
## Dashboard View
The dashboard gives a high-level overview of employee distribution and activity.
***
## Key Metrics
* **Total Employees** — Total number of discovered identities
* **External Employees** — Vendor, contractor, or third-party users
* **Active Employees** — Currently active identities
* **Inactive Employees** — Disabled or inactive identities
***
## Key Insights
### Internal vs External Users
* Differentiates employees based on domain or source
* Helps identify third-party exposure and vendor access
***
### Vendor Distribution
* Shows which platforms or domains employees are associated with
* Useful for identifying reliance on external services
***
### Activity Distribution
* Tracks user activity over time
* Helps identify dormant or inactive accounts
***
## Employee Inventory
The inventory view displays employee identities in a card-based format.
### What Each Card Shows
* **User Initial / Avatar**
* **Name**
* **Email Address**
* **Type** (Internal / External)
***
## Filters & Search
Users can refine employee data using:
* **Is Vulnerable** (if applicable)
* **Active Status**
* **Employee Type** (Internal / External)
* **Search by Name or Email**
***
## Why This Matters
The Employees module helps teams:
* Identify external and third-party access
* Detect inactive or unused accounts
* Maintain visibility into identity exposure
* Strengthen ownership and accountability
* Support IAM and security audits
***
## Explore Live Demo
Instantly explore how Snapsec AIM discovers, enriches, and tracks employee identities across your organization — all without creating an account.
# Integrations
Source: https://docs.snapsec.co/products/aim/integrations
Connect external data sources and tools to continuously enrich your asset inventory.
## Overview
Integrations (Adapters) allow you to connect external platforms and data sources to automatically discover, enrich, and update your asset inventory.
These integrations bring in data from cloud providers, APIs, repositories, DNS tools, and security platforms — enabling continuous visibility across your environment.
***
## Integrations Library
This screen displays all available integrations.
### Key Elements
* **Integration Cards** — Each represents a data source or tool
* **Category Tags** — API Discovery, Cloud, Network, etc.
* **Install Button** — Add integration instantly
* **Active Connections** — Shows configured instances
***
## Filter by Category
Use the category filter to quickly find relevant integrations.
### Available Categories
* API Discovery
* Cloud Infrastructure
* Network Intelligence
* Code Repository
* DNS & Network
* Certificate Transparency
* Data Import
* Communication
***
## Active Integrations
The Active Integrations tab shows all configured adapters.
### Available Actions
* **Delete** — Remove integration
* **Refresh** — Sync data immediately
* **Status Indicator** — Shows active/installed state
***
## Refresh Logs
Logs provide visibility into integration activity.
### Log Details
* **Adapter Name** — Source of the data
* **Event** — Action performed (e.g., refresh)
* **Status** — Success or failure
* **Log Message** — Execution details
* **Records Synced** — Number of assets pulled
* **Date & Time** — When the action occurred
***
## Supported Integrations
Snapsec AIM supports a wide range of integrations, including:
* Cloud providers (AWS, Oracle Cloud, etc.)
* API platforms (Postman, Swagger)
* Recon tools (Censys, HackerTarget)
* Code repositories (GitHub)
* DNS & certificate tools (CRT, DNS Resolver)
* Internal Snapsec modules
***
## Why This Matters
* Enables continuous asset discovery
* Eliminates manual data collection
* Centralizes visibility across tools
* Improves accuracy of asset inventory
* Powers automation across policies and scans
***
## Explore Live Demo
See how Snapsec AIM connects with external platforms to continuously enrich and update your asset inventory.
# IP Addresses
Source: https://docs.snapsec.co/products/aim/ips
Track and analyze IPs with visibility into exposure, relationships, and security posture.
## Overview
The **IP Addresses** module provides a structured view of your network — from **high-level exposure** to **deep asset intelligence**.
***
## 1. Dashboard
Shows:
* Total IPs
* External vs internal exposure
* Vulnerable IPs
* Location and ASN distribution
***
## 2. Inventory
Allows you to:
* Search and filter IPs
* Identify vulnerable assets
* View ownership and linked assets
***
## 3. IP Details
### 3.1 General Information
Includes:
* IP classification
* Environment
* Ownership
* Detection timeline
***
### 3.2 Location & Security
Includes:
* Location and ISP
* ASN details
* Vulnerability summary
***
### 3.3 Relationships & DNS
Shows:
* DNS mappings
* Linked subdomains
* Connected assets
***
## Why This Matters
* Quickly identify exposed infrastructure
* Understand where assets are hosted
* Trace relationships across your attack surface
* Prioritize risks based on real context
***
## Explore Live Demo
Instantly explore how Snapsec AIM maps your attack surface in real time.
# Lifecycle
Source: https://docs.snapsec.co/products/aim/lifecycle
Manage asset states across staging, active usage, and decommissioning with full visibility, restoration capabilities, and deep asset context.
## Overview
The **Lifecycle Management** module allows teams to control how assets transition across different operational states — from staging to decommissioning — while maintaining full visibility and context.
It ensures assets are never lost, supports recovery when needed, and preserves security and ownership data across the entire lifecycle.
***
## Staged Assets
The **Staged** section acts as a holding layer for assets that are identified but not yet active.
### Key Behavior
* Assets can be reviewed before activation
* Prevents unverified assets from entering active inventory
* Displays an empty state when no assets are staged
***
## Decommissioned Inventory
The **Decommissioned** section stores assets that are no longer active but are retained for visibility and audit purposes.
### What You Can See
* Asset name and type
* Active vulnerabilities at time of decommission
* Owner and ownership details
* Who decommissioned the asset
* Decommission date
***
## Restoring Assets
Assets in the decommissioned state can be restored at any time.
### How It Works
1. Click the **three-dot menu (⋯)**
2. Select **Restore**
3. Asset returns to active inventory
This ensures no asset is permanently lost and historical context remains intact.
***
## Lifecycle State Control
Each asset is assigned a lifecycle state that defines its operational status.
### Available States
* **Active** — Fully operational and monitored
* **Pending** — Newly discovered and under review
* **Staged** — Prepared but not yet active
* **Decommissioned** — Retired but retained for visibility
***
## General Asset Information
Provides core metadata required to understand the asset.
### Includes
* Asset ID and type
* Asset value (domain/IP)
* Environment classification
* Internal vs external designation
* Associated assets
* First and last detection timestamps
***
## Subdomain & Exposure Details
Gives visibility into how the asset behaves externally.
### Key Insights
* HTTP status code
* External reachability
* WAF presence and provider
* Network scope
***
## Ownership & Accountability
Every asset is mapped to an owner to ensure accountability.
### Includes
* Assigned user
* Team
* Department
* Custom assignment status
***
## Location & Infrastructure Data
Provides infrastructure-level intelligence about the asset.
### Data Points
* City, region, country
* Latitude and longitude
* ISP and ASN
* Organization and timezone
* IP version and exposure
***
## Security Overview
Summarizes the security posture of the asset.
### Includes
* Total vulnerabilities
* Severity breakdown (Critical, High, Medium, Low, Info)
* Open vs closed vulnerabilities
* Aggregate CVSS score
* Remediation progress
***
## Open Ports
Displays exposed services and potential entry points into the asset.
***
## DNS Records
Shows how the asset resolves across infrastructure.
***
## SSL Certificates
Tracks certificate validity and encryption posture of the asset.
***
## Asset Relationships
Helps understand how the asset connects with other components.
***
## Data Sources
Displays integrations responsible for discovering and enriching asset data.
***
## Why This Matters
* Prevents orphaned and unmanaged assets
* Enables safe decommissioning without losing context
* Allows quick restoration of critical assets
* Maintains full lifecycle visibility across infrastructure
* Preserves security, ownership, and operational history
***
## Explore Live Demo
Experience how Snapsec AIM helps you manage asset states, restore assets instantly, and maintain complete lifecycle visibility across your infrastructure.
# Object Storage
Source: https://docs.snapsec.co/products/aim/objects
Discover, track, and manage cloud object storage buckets across multiple providers.
## Overview
The **Object Storage** module provides a centralized inventory of all cloud storage buckets discovered across your environment.
It enables teams to track storage locations, monitor vulnerabilities, and maintain visibility across multiple cloud providers.
***
## Dashboard View
The dashboard provides a high-level summary of object storage assets.
### Key Metrics
* **Total Buckets** — All discovered storage buckets
* **Live Buckets** — Active buckets currently tracked
* **Vulnerable Buckets** — Buckets with detected vulnerabilities
* **Critical Buckets** — Buckets with critical issues
### Visual Insights
* **Provider Distribution** — AWS S3, Azure Blob, GCP Cloud Storage, OCI Object Storage
* **Region Distribution** — Bucket distribution across regions
* **Vulnerability Distribution** — Displays severity breakdown when data is available
***
## Object Storage Inventory
The inventory view lists all buckets with key metadata.
### Table Columns
| Column | Description |
| -------------------- | ------------------------------------- |
| **Asset** | Bucket name |
| **Compartment Name** | Logical grouping (if available) |
| **Provider** | Cloud provider (AWS, Azure, GCP, OCI) |
| **Region** | Bucket region |
| **Owner** | Assigned owner |
| **Associations** | Linked assets |
| **Detected On** | Discovery timestamps |
### Filters & Search
* **Is Vulnerable**
* **Provider**
* **Region**
* **Search by bucket name**
***
## Object Storage Asset View
Selecting a bucket opens its detailed asset view.
***
## General Information
Each bucket includes:
* **Asset ID**
* **Type (Object Storage)**
* **Bucket Name**
* **Environment**
* **Internal Asset (Yes / No)**
* **Is New**
* **Associated Assets**
* **First Detected / Last Detected**
***
## Security Overview
Each bucket includes a built-in security summary:
* **Total Vulnerabilities**
* **Severity Breakdown** (Critical, High, Medium, Low, Info)
* **Open vs Closed Vulnerabilities**
* **Aggregate CVSS**
* **Remediation Progress**
* **Tested Status**
* **Last Scan Date**
***
## Data Sources (Adapters)
AIM integrates with external providers to discover object storage assets.
* Example: **GitLab Integration**
* Used to enrich and map storage-related assets and repositories
***
## Why This Matters
The Object Storage module helps teams:
* Maintain visibility across all cloud storage buckets
* Track vulnerabilities associated with storage assets
* Understand bucket distribution across providers and regions
* Identify ownership gaps
* Monitor storage assets within a centralized inventory
***
## Explore Live Demo
Instantly explore how Snapsec AIM discovers and tracks object storage assets across your environment — all without creating an account.
# Registries
Source: https://docs.snapsec.co/products/aim/registries
Discover, monitor, and manage container registries with visibility into vulnerabilities, ownership, and linked assets.
## Overview
The **Registries** module provides a centralized inventory of all container registries discovered across your environment.
It enables teams to track registry sources, monitor vulnerabilities, and maintain ownership visibility for container-based assets.
***
## Dashboard View
The dashboard gives a high-level summary of registry posture.
### Key Metrics
* **Total Registries** — All discovered registries
* **Vulnerable Registries** — Registries with detected vulnerabilities
* **Critical Registries** — Registries with critical issues
* **Archived Registries** — Registries marked as archived
### Visual Insights
* **Vulnerability Severity Distribution** — High, Medium, Low breakdown
* **Active vs Archive Distribution** — Lifecycle status of registries
***
## Registry Inventory
The inventory view lists all registries with key metadata.
### Table Columns
| Column | Description |
| ------------------- | ------------------------------ |
| **Asset** | Registry name |
| **Registry Status** | Active or archived |
| **Registry Source** | Source provider (e.g., GitLab) |
| **Vuln Count** | Number of vulnerabilities |
| **Owner** | Assigned user |
| **Associations** | Linked assets |
| **Detected On** | Discovery timeline |
### Filters & Search
* **Is Vulnerable**
* **Registry Status**
* **Registry Source**
* **Search by registry name**
***
## Registry Asset View
Clicking a registry opens a detailed asset view.
***
## General Information
Each registry asset includes:
* **Asset ID**
* **Type (Registry)**
* **Registry Value (URL / Path)**
* **Environment**
* **Internal Asset (Yes / No)**
* **Is New**
* **Associated Assets**
* **First Detected / Last Detected**
***
## Ownership
Each registry is mapped to an owner for accountability:
* **User**
* **Team**
* **Department**
* **Custom Assignment**
***
## Security Overview
Registries include a built-in security summary:
* **Total Vulnerabilities**
* **Severity Breakdown** (Critical, High, Medium, Low, Info)
* **Open vs Closed Vulnerabilities**
* **Aggregate CVSS**
* **Remediation Progress**
* **Last Scan Date**
* **Tested Status**
***
## Asset Relationships
Registries can be linked to other assets within AIM:
* Applications
* Repositories (e.g., GitLab repos)
* Related infrastructure assets
This helps teams understand how container registries connect to the broader environment.
***
## Data Sources (Adapters)
AIM integrates with external providers to discover registry data.
* Example: **GitLab Integration**
* Automatically fetches registry and repository information
***
## Why This Matters
The Registries module helps teams:
* Maintain visibility over all container registries
* Identify vulnerable container sources
* Track ownership and accountability
* Understand relationships between registries and applications
* Monitor registry activity and lifecycle status
***
## Explore Live Demo
Instantly explore how Snapsec AIM discovers and tracks registries across your environment — all without creating an account.
# Repositories
Source: https://docs.snapsec.co/products/aim/repo
Track and manage code repositories with visibility into exposure, activity, vulnerabilities, and ownership.
## Overview
The **Repositories** section in AIM provides a complete inventory of all code repositories discovered across your organization.\
It enables teams to monitor **repository exposure, activity, vulnerabilities, and ownership** in a single unified view.
***
## Dashboard View
Each repository dataset is supported by a **dashboard view** that highlights overall posture, activity, and distribution trends.
The dashboard provides:
* **Total Repositories** — All discovered repositories
* **Active Repositories** — Currently active codebases
* **Vulnerable Repositories** — Repositories with detected issues
* **Archived Repositories** — Repositories no longer in active use
***
## Key Insights
### Vulnerable vs Safe
Shows how many repositories:
* Have vulnerabilities
* Are currently safe
Helps quickly identify risky codebases.
***
### Visibility Distribution
Breakdown of:
* Private repositories
* Public repositories
Public repositories require extra attention due to exposure risk.
***
### Repository Creation Trends
Tracks repository creation over time:
* Helps identify spikes in development activity
* Useful for governance and growth tracking
***
### Repository Activity Overview
Shows activity levels across time:
* Last week
* Last month
* Last 3 months
* Last year
Helps identify inactive or stale repositories.
***
### Active vs Archived
Displays:
* Active repositories
* Archived repositories
Useful for cleanup and lifecycle management.
***
### Language Distribution
Breakdown of programming languages used across repositories:
* Helps understand technology stack
* Useful for standardization and risk analysis
***
## Inventory Table
The repository table is the **primary working view** for managing code assets.
### Key Columns
| Column | Description |
| ------------------- | ------------------------------------------------- |
| **Repository** | Repository name and source (GitHub, GitLab, etc.) |
| **Visibility** | Public or Private |
| **Language** | Primary programming language |
| **Status** | Active or Archived |
| **Vulnerabilities** | Number of associated issues |
| **Owner** | Assigned owner |
| **Last Push** | Last activity timestamp |
| **Detected On** | First and last detection |
***
## Search and Filters
Quickly refine repository data using:
* **Is Vulnerable** — Show repositories with vulnerabilities
* **Archive Status** — Active vs archived
* **Visibility** — Public or private
* **Language** — Filter by tech stack
* **Search** — Find specific repositories
These filters help prioritize security and cleanup efforts.
***
## Why This Matters
The Repositories module gives visibility into your **code attack surface**:
* Identify **publicly exposed repositories**
* Detect **inactive or abandoned codebases**
* Track **vulnerabilities tied to code assets**
* Understand **technology usage across repos**
* Enforce **ownership and accountability**
***
## Explore Live Demo
Instantly explore how Snapsec AIM discovers, enriches, and tracks every asset in real time — all without creating an account.
# Reports
Source: https://docs.snapsec.co/products/aim/reports
Export asset inventory data in multiple formats for reporting, analysis, and integrations.
## Overview
Exports allow you to extract asset inventory data for reporting, compliance, or external analysis.
You can generate full inventory exports or filter exports based on specific asset types, and download them in multiple formats such as CSV, XLSX, or JSON.
***
## Export Options
The exports screen provides two primary options:
### Full Asset Inventory Export
* Exports all assets in your inventory
* Ideal for complete reporting and backups
### Asset Specific Export
* Export assets based on selected type
* Useful for targeted analysis
***
## Generate Full Inventory Export
To export the complete inventory:
1. Click **Generate Export** under Full Asset Inventory
2. Select your preferred format:
* CSV
* XLSX
* JSON
3. Confirm to generate the export
***
## Generate Asset-Specific Export
To export specific assets:
1. Click **Generate Export** under Asset Specific Export
2. Select the asset type
3. Choose the export format
4. Click **Generate**
***
## Supported Formats
Exports are available in multiple formats to support different use cases:
* **CSV** — Lightweight and widely compatible
* **XLSX** — Structured and ideal for spreadsheets
* **JSON** — Best for integrations and automation
***
## Why This Matters
* Enables easy reporting and compliance tracking
* Supports external analysis and integrations
* Provides flexible data extraction
* Simplifies audit and documentation workflows
***
## Explore Live Demo
See how Snapsec AIM allows you to export asset data in multiple formats for reporting and analysis.
# Settings
Source: https://docs.snapsec.co/products/aim/settings
Configure global synchronization, public access, and default ownership for your asset inventory.
## Overview
Settings allow you to control how your asset inventory behaves across synchronization, public access, and ownership mapping.
These configurations help standardize data management, automate workflows, and ensure proper asset accountability across teams.
***
## Adapter Settings
Adapter Settings define how integrations sync data into your platform.
### Key Controls
* **Enable Auto Sync** — Automatically sync all adapters on a schedule
* **Sync Schedule** — Choose frequency (e.g., daily)
* **Time चयन** — Define exact execution time
* **Save Configuration** — Apply settings globally
This ensures your asset inventory remains continuously updated without manual intervention.
***
## Global Settings
Global Settings allow controlled public access to asset data.
### Public Asset Search
* Share a **read-only public link**
* Enables visibility into assets, vulnerabilities, and reports
* Ideal for quick external access
### Edit Asset Access
* Share a **public edit link**
* Allows updating asset name and exposure
* Should be shared cautiously
These links enable controlled collaboration without requiring platform access.
***
## Default Ownership
Default Ownership ensures every asset is automatically assigned to the correct stakeholders.
### Mapping Configuration
* **Asset Type** — Subdomains, APIs, IPs, etc.
* **Owner** — Assigned user or email
* **Team** — Responsible group
* **Department** — Organizational unit
### Benefits
* Eliminates unassigned assets
* Improves accountability
* Streamlines incident response
* Ensures consistent ownership across inventory
***
## Why This Matters
* Automates data synchronization across integrations
* Enables controlled external access to asset data
* Ensures every asset has clear ownership
* Reduces manual configuration overhead
* Strengthens governance and accountability
***
## Explore Live Demo
See how Snapsec AIM centralizes configuration for sync, access, and ownership across your entire asset inventory.
# Subdomains
Source: https://docs.snapsec.co/products/aim/subdomains
Discover, analyze, and investigate subdomains with deep visibility into DNS, SSL, ports, vulnerabilities, and asset relationships.
## Overview
The **Subdomains** module provides a complete, enriched inventory of all discovered subdomains across your organization.
It goes beyond simple discovery by combining **reachability, vulnerabilities, DNS intelligence, SSL data, open ports, and asset relationships** into a single investigation workflow.
***
## Dashboard View
The dashboard provides high-level visibility into subdomain posture across the organization.
### Key Metrics
* **Total Subdomains** — All discovered assets
* **Live Subdomains** — Actively reachable endpoints
* **Vulnerable Subdomains** — Subdomains with findings
* **Critical Subdomains** — High severity assets
### Visual Insights
* **Vulnerability Distribution** — Severity-based breakdown
* **Environment Distribution** — Production, Staging, Unknown
* **Network Scope** — External vs internal exposure
* **WAF Distribution** — Protected vs unprotected assets
* **Active vs Inactive** — Live vs dead endpoints
* **Status Code Distribution** — HTTP response patterns
***
## Inventory View
The inventory is the **operational layer** for filtering and triaging subdomains.
### Key Columns
| Column | Description |
| ------------------- | ---------------------- |
| **Asset Value** | Subdomain name + title |
| **Status** | HTTP response code |
| **Vulnerabilities** | Count of findings |
| **Reachability** | External / internal |
| **Environment** | Production / staging |
| **Owner** | Assigned user |
| **Associations** | Linked assets |
| **Detected On** | First & last seen |
### Filters
* **Is Vulnerable**
* **Status Code**
* **WAF Protection**
* **Externally Reachable**
* **Environment**
***
## Subdomain Asset View
Clicking a subdomain opens a **deep inspection view**.
### General Information
* **Asset ID**
* **Type (Subdomain)**
* **Domain Value**
* **Environment**
* **Internal Asset**
* **Is New**
* **Associated Assets**
* **First / Last Detected**
***
## Subdomain Details
This section provides live HTTP and infrastructure insights.
### Includes
* **Status Code** (e.g., 200, 403)
* **Page Title**
* **Live Status**
* **Externally Reachable (Yes/No)**
* **Network Scope**
* **WAF Detection**
* **Server Type (e.g., nginx)**
* **Content Type**
***
## Security Overview
### Security Data
* **Total Vulnerabilities**
* **Severity Breakdown** (Critical, High, Medium, Low, Info)
* **Open vs Closed Vulnerabilities**
* **Aggregate CVSS Score**
* **Remediation Progress**
* **Test Status**
* **Last Scan Date**
***
## Open Ports
### Port Intelligence
* **Port Number** (e.g., 80, 443)
* **Environment**
* **Vulnerability Status**
* **Associated Assets Count**
* **Last Checked Timestamp**
***
## DNS Records & SSL Certificates
### DNS Visibility
* **Record Values (IP / NS / MX / TXT)**
* **Record Type**
* **Resolved From**
* **Third-party indication**
* **Last Checked**
### SSL Certificate Data
* **Common Name**
* **Issuer**
* **Validity Period**
* **Alternative Names**
***
## Asset Relationships
Subdomains are automatically linked to related infrastructure.
### Includes Relationships With:
* **DNS Records**
* **IP Addresses**
* **Repositories**
* **Applications**
* **Other assets in AIM**
This enables teams to **trace dependencies and understand blast radius**.
***
## Data Sources (Adapters)
Subdomain data is enriched through multiple integrations:
* **HackerTarget** — External reconnaissance data
* **CRT (Certificate Transparency)** — Subdomain discovery via cert logs
* **SnapSec ASM** — External attack surface intelligence
* **Vulnerability Management** — Security findings
***
## Why This Matters
The Subdomains module enables teams to:
* Discover **complete external attack surface**
* Identify **publicly exposed assets instantly**
* Correlate **DNS, SSL, and infrastructure signals**
* Detect **open ports and reachable services**
* Track **vulnerabilities with remediation context**
* Understand **asset relationships and dependencies**
This turns subdomain tracking from simple inventory into **full attack surface intelligence**.
***
## Explore Live Demo
Instantly explore how Snapsec AIM discovers, enriches, and analyzes subdomains in real time — all without creating an account.
# Triggers
Source: https://docs.snapsec.co/products/aim/triggers
Automate actions based on asset events to enable continuous security workflows.
## Overview
Triggers allow you to automate actions across your asset inventory based on defined conditions.
They continuously monitor asset changes and automatically execute workflows such as scans or policy enforcement — eliminating manual intervention and improving response time.
***
## Triggers List
This screen provides a centralized view of all trigger rules.
### Key Elements
* **Name & Description** — Defines what the trigger does
* **Enabled Toggle** — Activate or disable triggers instantly
* **Matched Assets** — Assets currently matching the condition
* **Created On** — Rule creation timestamp
* **Actions Menu** — Manage trigger execution
***
## Create a Trigger
To create a new trigger:
1. Click **Create Trigger**
2. Open the guided policy builder
3. Define conditions and trigger actions
***
## Guided Policy Builder
This builder allows you to define when and how automation should occur.
### Rule Configuration
* **Rule Name** — Unique name for the trigger
* **Description** — Optional explanation
### Conditions
Define when the trigger should activate:
* Select a field
* Choose an operator (equals, contains, etc.)
* Provide a value
### Trigger Actions
Define what should happen automatically:
* Run vulnerability scans
* Trigger workflows
* Enforce security policies
***
## Manage Triggers
Each trigger supports:
* **Edit Trigger** — Update logic or actions
* **Execute Now** — Run instantly on current assets
* **Delete Trigger** — Remove permanently
***
## Execute All Rules
Use **Execute All Rules** to run all triggers across your assets and enforce automation immediately.
This ensures your automation rules are applied to the latest asset state.
***
## Real-World Examples
* Run scans when a new IP is discovered
* Trigger actions when a new port opens
* Start checks when a device becomes non-compliant
* Automatically scan newly onboarded assets
***
## Why This Matters
* Converts detection into action
* Eliminates manual workflows
* Reduces response time
* Enables continuous security automation
***
## Explore Live Demo
See how Snapsec AIM automatically executes scans and workflows when trigger conditions are met.
# Workstations
Source: https://docs.snapsec.co/products/aim/workstations
Monitor endpoints, system details, and device-level security posture across your organization.
## Overview
The **Workstations** module provides a centralized inventory of all discovered endpoints including laptops, desktops, and virtual machines.
It enables teams to track device ownership, operating systems, system-level data, and basic security posture across the environment.
***
## Dashboard View
The dashboard provides a high-level summary of all workstations.
### Key Metrics
* **Total Workstations** — All discovered devices
* **Live Workstations** — Currently active endpoints
* **Vulnerable Workstations** — Devices with detected issues
* **Critical Workstations** — Devices with critical findings
### Visual Insights
* **Platform Distribution** — Windows, Linux, Darwin
* **Region Distribution** — Geographic breakdown
* **RAM Distribution** — Memory allocation across devices
* **Architecture Distribution** — Arm64 vs Amd64
* **Status Distribution** — Active, Inactive, Maintenance
***
## Workstation Inventory
The inventory view lists all discovered workstations with key details.
### Table Columns
| Column | Description |
| -------------------- | ----------------------------------- |
| **Asset** | Device name or identifier |
| **Operating System** | OS type and version |
| **Vuln Count** | Number of vulnerabilities |
| **Owner** | Assigned user |
| **Detected On** | First and last detection timestamps |
### Filters & Search
* **Is Vulnerable**
* **OS Platform**
* **Firewall Status**
* **Location**
* **Search by device name**
***
## Workstation Asset View
Selecting a workstation opens a detailed view with complete system context.
***
## General Information
Each workstation includes:
* **Asset ID**
* **Type (Workstation)**
* **Hostname**
* **FQDN**
* **Timezone**
* **Environment**
* **Internal Asset (Yes / No)**
* **Associated Assets**
* **First Detected / Last Detected**
***
## Operating System
Includes:
* **Platform** (e.g., Darwin, Linux, Windows)
* **Distribution**
* **Version**
* **Architecture**
***
## Hardware Details
Displays:
* **CPU Model**
* **Cores & Threads**
* **RAM Total / Used / Available**
* **Disk Capacity**
***
## Processes
Provides visibility into:
* Active processes
* Process IDs (PID / PPID)
* Running user (e.g., root)
* CPU and memory usage
***
## Users & Network Information
Includes:
### System Users
* Username
* UID
* Shell
* Groups
### Network & Location
* Public IP
* City, Region, Country
* ISP and ASN
* Latitude & Longitude
* Timezone
***
## Security Overview
Displays basic security posture of the workstation:
* Total vulnerabilities
* Severity breakdown (if available)
* Open vs closed vulnerabilities
* Aggregate CVSS
* Remediation progress
* Last scan date
***
## Ownership
Each workstation is mapped to an owner for accountability:
* **User**
* **Team**
* **Department**
* **Custom Assignment**
***
## Why This Matters
The Workstations module helps teams:
* Maintain complete visibility of all endpoints
* Track device ownership and accountability
* Monitor system-level configurations
* Understand geographic and network exposure
* Investigate processes and user activity
* Identify vulnerable or unmanaged devices
***
## Explore Live Demo
Instantly explore how Snapsec AIM discovers and tracks workstations across your environment — all without creating an account.
# Asset Catalog
Source: https://docs.snapsec.co/products/asm/asset-catalog
Explore, filter, and manage all discovered external assets with real-time context, signals, and exposure insights.
## Overview
The **Asset Catalog** is your **single source of truth** for everything exposed across your external attack surface.
It provides a **structured, continuously updated inventory** of all discovered assets — enriched with context like **signals, exposure status, technologies, ports, and infrastructure mapping**.
Unlike traditional inventories, this is not just a list — it’s an **interactive system designed for investigation, filtering, and action**.
***
## How It Works
ASM continuously discovers and updates assets using:
* Active scanning (ports, services, web validation)
* Passive intelligence (DNS, CT logs, internet datasets)
* Technology fingerprinting
* Infrastructure mapping
Each asset is:
* **Discovered** → identified from multiple sources
* **Enriched** → tagged with metadata (WAF, ASN, tech stack)
* **Classified** → grouped by type (IP, Subdomain, Port, etc.)
* **Monitored** → updated as changes occur
* **Correlated** → linked to related entities
This creates a **live, queryable map of your attack surface**.
***
## Core Capabilities
### Unified Asset Inventory
All asset types are accessible in one place:
* Subdomains
* Web Servers
* IP Addresses
* DNS Records
* Ports
* Certificates
* Technologies
Each view is optimized for **deep inspection and filtering**, not just visibility.
***
### Filtering & Exploration
Every asset view includes powerful controls:
* Search across assets
* Filters (e.g., **Is New, WAF, Status, Network Scope**)
* Attribute-based filtering (ports, services, DNS class, etc.)
* Reset and quick refinement
This enables teams to:
* Narrow down large datasets instantly
* Investigate specific exposure patterns
* Focus on high-priority segments
***
### Signals Integration
Each asset is mapped with **signals** — indicators of potential risk, anomalies, or findings.
* Signals are visible directly in tables
* Assets with **0 signals are still tracked** (important for baseline visibility)
* Enables quick identification of **active vs clean surface areas**
***
### Export & Reporting
All views support **Export to CSV**, allowing teams to:
* Share data externally
* Perform offline analysis
* Integrate with reporting workflows
***
## Asset Views
Each asset type provides a focused lens into a specific layer of your attack surface.
***
### Subdomains
Subdomains represent your **external entry points**.
**Key Insights:**
* Open ports per subdomain
* IP address mappings
* WAF detection (e.g., Cloudflare)
* External exposure classification
* Signal presence
**Why It Matters:**\
Unmanaged or forgotten subdomains are one of the most common attack vectors.
***
### Web Servers
Focuses on **HTTP/HTTPS services and application exposure**.
**Key Insights:**
* HTTP status codes (200, 403, 418, etc.)
* Detected services (Dozzle, Vercel, etc.)
* Open ports per service
* External exposure visibility
**Why It Matters:**\
This is where attackers interact — APIs, panels, dashboards, and apps.
***
### IP Addresses
Provides a **network-level view** of infrastructure.
**Key Insights:**
* Geolocation and ASN (e.g., AWS, Fastly, Hostinger)
* Open ports per IP
* Network scope (external/internal)
* Infrastructure ownership
**Why It Matters:**\
Helps identify shadow infrastructure and unmanaged cloud assets.
***
### DNS Records
Tracks all DNS-level mappings and configurations.
**Key Insights:**
* Record types (A, CNAME, MX, SOA, etc.)
* Domain ↔ infrastructure relationships
* Detection timestamps
* Signal tracking
**Why It Matters:**\
DNS misconfigurations and dangling records are common exposure points.
***
### Ports
Highlights **network exposure and service-level access**.
**Key Insights:**
* Open ports and services (HTTP, HTTPS, etc.)
* Service versions (if detected)
* External vs internal exposure
* Detection timestamps
**Why It Matters:**\
Unexpected open ports often indicate misconfigurations or attack surface expansion.
***
### Certificates
Tracks SSL/TLS posture across assets.
**Key Insights:**
* Valid, expired, and at-risk certificates
* Expiry timelines
* Domain associations
* Signal indicators
**Why It Matters:**\
Certificate issues can indicate neglected assets or cause service disruptions.
***
### Technologies
Provides a **high-level inventory of detected technologies**.
**Key Insights:**
* Frameworks (React, Next.js)
* Infrastructure (Nginx, Cloudflare, Netlify, Vercel)
* Categories (CDN, Analytics, Security, etc.)
* Asset-level mapping
**Why It Matters:**
* Detect outdated or vulnerable stacks
* Identify unauthorized technologies
* Understand platform usage across teams
***
## Correlation Across Assets
The real power of the catalog lies in **relationships**:
* Subdomain → IP → Ports → Web Server
* DNS → Infrastructure → Exposure
* Technology → Service → Risk signals
This allows teams to:
* Trace issues across layers
* Perform faster root cause analysis
* Understand full exposure context
***
## Continuous Updates
The catalog is **always live**:
* New assets are discovered automatically
* Changes are reflected in near real-time
* Signals update dynamically
This ensures your visibility is always aligned with your **actual attack surface**.
***
## Why This Matters
* **Complete Visibility** — No blind spots across external assets
* **Actionable Context** — Signals + metadata in one place
* **Faster Investigations** — Correlated asset relationships
* **Operational Efficiency** — Filter, export, and act instantly
* **Reduced Risk** — Identify exposure before exploitation
***
## Explore Live Demo
Experience how ASM provides real-time asset discovery, enrichment, and visibility across your entire attack surface.
# Blacklisted Assets
Source: https://docs.snapsec.co/products/asm/blacklisted-assets
Exclude specific assets from monitoring, scanning, and risk evaluation to reduce noise and focus on relevant exposures.
## Overview
The **Blacklisted Assets** section allows you to **exclude specific assets** from monitoring, scans, and risk signal evaluations.
This helps security teams eliminate **false positives**, ignore **non-relevant infrastructure**, and maintain a **clean and actionable attack surface view**.
***
## Why Blacklist Assets?
Not all discovered assets require monitoring.
Blacklisting is useful when:
* 🧪 Assets are used for **testing or staging**
* 🔁 Assets are **owned but intentionally exposed**
* 🚫 Assets are **out of scope** for security monitoring
* ⚠️ Assets generate **repeated false positives**
***
## Blacklisted Assets Table
The table provides a centralized view of all excluded assets.
### Fields Explained
| Field | Description |
| ------------------ | ------------------------------------- |
| **Asset Value** | The IP address or domain/subdomain |
| **Type** | Asset type (IP or Subdomain) |
| **Reason** | Optional explanation for blacklisting |
| **Blacklisted By** | User who performed the action |
| **Blacklisted On** | Date when the asset was excluded |
***
## How Blacklisting Works
Once an asset is blacklisted:
* It is **excluded from scans**
* It does not appear in **Risk Signals**
* It is ignored in **exposure detection**
* It is removed from **security prioritization workflows**
This ensures your team focuses only on **relevant and actionable risks**.
***
## Workflow Example
1. Identify an asset generating noise or not relevant
2. Add it to the **Blacklist**
3. Future scans ignore the asset
4. Risk Signals no longer include it
5. Security team focuses on real threats
***
## Best Practices
* 🎯 Only blacklist assets that are **confirmed non-critical**
* 📝 Always provide a **reason** for traceability
* 🔍 Periodically review blacklisted assets
* 🔁 Re-include assets if their risk profile changes
***
## Value to Security Teams
| Benefit | Description |
| -------------------------- | -------------------------------- |
| **Noise Reduction** | Eliminates irrelevant findings |
| **Improved Focus** | Prioritize real security risks |
| **Cleaner Dashboards** | Accurate exposure visibility |
| **Operational Efficiency** | Reduce unnecessary triage effort |
***
## From Noise to Clarity
**Discover → Filter → Focus → Secure**
Blacklisting ensures your attack surface reflects **what truly matters**.
***
## Explore Live Demo
Instantly explore how Snapsec Attack Surface Management (ASM) detects exposures, filters noise, and enables real-time security decisions — all in one unified platform.
# Dashboard
Source: https://docs.snapsec.co/products/asm/dashboard
Get a real-time overview of your attack surface, risk signals, and asset distribution across your organization.
## Overview
The **ASM Dashboard** provides a real-time view of your organization’s external attack surface — combining **asset discovery, risk signals, and operational insights** into a single interface.
It helps teams quickly answer:
* What assets are exposed?
* Where are risks concentrated?
* Which areas require attention right now?
All data is continuously updated from ASM discovery pipelines, ensuring visibility reflects your **current external footprint**.
***
## Key Metrics
At the top of the dashboard, core metrics provide a quick snapshot of your environment:
| Metric | Description |
| ----------------- | --------------------------------------------------------------- |
| **Total Assets** | Total number of discovered assets across all categories |
| **Risk Signals** | Total number of signals indicating potential risks or anomalies |
| **Total Tickets** | Issues or findings currently tracked for action or validation |
| **Next Scan** | Scheduled time for the next discovery or scan cycle |
These metrics give an immediate understanding of **scale, activity, and operational workload**.
***
## Asset Distribution
The **Asset Distribution** chart shows how your attack surface is spread across different asset types.
### Includes:
* IP Addresses
* Ports
* Subdomains
* Technologies
* Web Servers
* Certificates
* DNS Records
This view helps you:
* Understand which asset types dominate your surface
* Identify areas with higher exposure potential
* Track growth across different infrastructure layers
***
## Signal Distribution
The **Signal Distribution** chart breaks down where risk signals are originating from.
Signals are categorized by asset type, such as:
* DNS Records
* IP Addresses
* Ports
* Web Servers
This enables teams to:
* Identify **which layers are generating the most alerts**
* Detect patterns in misconfigurations or anomalies
* Focus investigations on the most active risk sources
***
## Risk Distribution
The **Risk Distribution** chart provides a high-level view of how risks are spread across asset categories.
It helps answer:
* Which asset types contribute most to overall risk?
* Is risk concentrated or distributed across the environment?
This allows for **better prioritization and resource allocation**.
***
## Attack Surface Posture
The **Current Attack Surface Posture** table provides a structured breakdown of your environment.
| Field | Description |
| ----------------------- | ------------------------------------------------- |
| **Asset Type** | Category of asset (IP, Ports, Subdomains, etc.) |
| **Current Asset Count** | Total assets in that category |
| **Total Signals** | Number of signals associated with that asset type |
| **Total Risks** | Number of confirmed or mapped risks |
This table enables:
* Side-by-side comparison of asset categories
* Identification of **high-signal / high-risk areas**
* Faster prioritization of remediation efforts
***
## Why This Dashboard Matters
* **Unified Visibility** — Assets, signals, and risks in one place
* **Actionable Insights** — Quickly identify where attention is needed
* **Operational Awareness** — Track tickets and ongoing activity
* **Data-Driven Decisions** — Prioritize based on real exposure and signals
***
## Explore Live Demo
See how ASM provides real-time visibility into your attack surface, correlates signals, and helps prioritize risks across your environment.
# Reports
Source: https://docs.snapsec.co/products/asm/reports
Generate, download, and manage reports for your attack surface, exposures, and security posture.
## Overview
The **Reports** section allows security teams to **generate, manage, and export structured reports** of their external attack surface.
Reports consolidate data from scans, assets, and risk signals into **executive-ready and audit-friendly documents**, enabling better visibility, decision-making, and compliance tracking.
***
## Report Types
The platform supports multiple report formats tailored for different use cases:
High-level PDF report summarizing assets, exposures, and risk posture for leadership and stakeholders.
Detailed breakdown of all detected exposures and vulnerabilities in structured format.
Complete inventory of all discovered external assets across your organization.
***
## Generating Reports
To generate a report:
1. Select the desired report type
2. Click **Generate**
3. The system compiles data from scans and exposures
4. Report appears in **Report History**
Reports are generated asynchronously and updated with a **status indicator**.
***
## Report History
The **Report History** section provides a complete log of all generated reports.
### Fields Explained
| Field | Description |
| --------------------------- | ---------------------------------- |
| **Name** | Report title with timestamp |
| **Created At** | When the report was generated |
| **Generation Initiated By** | User who triggered the report |
| **Status** | Current state (Completed / Failed) |
***
## Report Status
* 🟢 **Completed** — Report is ready for download
* 🔴 **Failed** — Report generation failed
* 🟡 *(Processing)* — Report is being generated (if applicable)
***
## Report Actions
Each report provides quick actions via the menu:
* ⬇️ **Download Report** — Export the report file
* 🗑️ **Delete Report** — Remove unnecessary reports
These actions allow teams to maintain a clean and usable report repository.
***
## How Reports Are Built
Reports aggregate data from multiple ASM components:
1. **Scans** — Asset discovery results
2. **Assets** — Subdomains, IPs, services
3. **Exposures** — Detected risks and misconfigurations
4. **Risk Signals** — Correlated findings and severity
This ensures every report reflects the **latest security posture**.
***
## Workflow Example
1. Run or complete a scan
2. Navigate to **Reports**
3. Generate an Executive or Exposure report
4. Wait for processing to complete
5. Download and share with stakeholders
***
## Benefits
* ✅ Centralized reporting for all ASM data
* ✅ Executive-ready summaries
* ✅ Easy export for compliance and audits
* ✅ Full audit trail of generated reports
* ✅ Quick access to historical reports
***
## Best Practices
* 📅 Generate reports after each major scan
* 📊 Use Executive Reports for leadership
* 🔍 Use Exposure Reports for technical teams
* 🧹 Clean up failed or duplicate reports regularly
***
## From Data to Decisions
**Scan → Detect → Analyze → Report → Act**
Reports transform raw attack surface data into **actionable insights** for both technical and non-technical stakeholders.
***
## Explore Live Demo
Instantly explore how Snapsec Attack Surface Management (ASM) detects exposures, correlates signals, and enables real-time security decisions — all in one unified platform.
# Risk Signals
Source: https://docs.snapsec.co/products/asm/risk-signals
Continuously detect, analyze, and act on security exposures across your attack surface using real-time signals and rule-based intelligence.
## Overview
**Risk Signals** transform your attack surface into **real-time, actionable security intelligence**.
***
## Signal Deep Dive
### Impacted Assets
* Asset (IP / domain)
* Host mapping
* External exposure status
* Detection timestamp
* VM ticket actions (View / Create Ticket)
***
## Export & Action
* Export impacted assets
* Take action via ticketing
* Track remediation progress
***
## Creating Rules
***
## Guided Rule Editor
### Configuration Includes
* Rule name and description
* Condition builder (field, operator, value)
* Multiple condition support
* Live YAML preview
***
## Workflow Example
1. Signals automatically evaluate assets after discovery and scanning
2. Detected exposures appear as violations with severity and trends
3. Security teams review impacted assets
4. Remediation or ticketing actions are performed
5. Signals are re-synced to validate fixes
***
## Reporting Workflow
1. Generate a report after signal evaluation
2. The platform compiles assets, exposures, and analytics
3. Export findings for internal or compliance use
4. Share with stakeholders or leadership
***
## From Detection to Action
**Assets → Detection → Context → Action → Validation**
Risk Signals ensure your team is actively reducing risk — not just observing it.
***
## Explore Live Demo
Instantly explore how Snapsec Attack Surface Management (ASM) detects exposures, correlates signals, and enables real-time security decisions — all in one unified platform.
# Scans
Source: https://docs.snapsec.co/products/asm/scans
Execute and monitor domain scans to continuously discover, track, and manage your external attack surface.
## Overview
The **Scans** page enables security teams to **initiate, monitor, and manage discovery scans** across their external attack surface.
Each scan identifies assets such as subdomains, IPs, services, and exposures — providing a continuously updated view of your organization's internet-facing footprint.
***
## Scan List
The scan list provides a **historical and real-time view** of all executed and scheduled scans.
### Key Capabilities
* View **scan status** (Upcoming, Completed, etc.)
* Track **execution time and duration**
* Monitor **scan frequency (weekly / one-time)**
* Identify **recent scan activity**
### Fields Explained
| Field | Description |
| ------------- | ----------------------------------- |
| **Domain** | Target domain scanned |
| **Status** | Current state of the scan |
| **Started** | When the scan started or will start |
| **Duration** | Total scan execution time |
| **Frequency** | Recurrence (Weekly / Once) |
***
## Scan Status & Filtering
You can filter scans based on their execution state:
* **Pending** — Scheduled but not started
* **Running** — Currently in progress
* **Completed** — Successfully finished
* **Failed** — Encountered an issue
* **Cancelled** — Manually stopped
This helps teams quickly focus on **active or problematic scans**.
***
## Launching a Scan
To start a new scan:
1. Click **“Launch Scan Now”**
2. Confirm the action in the prompt
3. The scan is scheduled and begins execution
***
## Confirmation Flow
Before execution, a confirmation modal ensures intentional action:
* Prevents accidental scan triggers
* Adds operational control
* Confirms scan initiation
***
## How Scans Work
Each scan performs a **multi-layered discovery process**:
1. **Asset Enumeration**
* Subdomains
* IP addresses
* DNS records
2. **Service Detection**
* Open ports
* Running services
* Web servers
3. **Data Correlation**
* Mapping assets to hosts
* Identifying relationships
4. **Exposure Identification**
* Publicly accessible services
* Misconfigurations
* Security risks
***
## Continuous Monitoring
Scans can be scheduled (e.g., weekly) to ensure **continuous visibility**.
This enables:
* Detection of **newly introduced assets**
* Monitoring of **infrastructure changes**
* Early identification of **security risks**
* Tracking of **attack surface growth over time**
***
## Workflow Example
1. Launch a scan manually or via schedule
2. Scan begins asset discovery and enumeration
3. Assets and exposures are identified
4. Results are added to the platform
5. Risk Signals and Tickets are generated
***
## Best Practices
* 🕒 Run scans **regularly (weekly recommended)**
* 🎯 Ensure **complete domain coverage**
* 🔁 Review results after each scan
* 📊 Track trends to measure security improvements
***
## Value to Security Teams
| Benefit | Description |
| -------------------------- | ------------------------------------------- |
| **Automated Discovery** | Continuously identifies all external assets |
| **Real-Time Visibility** | Always know what is exposed |
| **Risk Reduction** | Detect exposures early |
| **Operational Efficiency** | Eliminate manual asset tracking |
***
## From Discovery to Security
**Scan → Discover → Analyze → Detect → Act**
Scans form the **foundation of Attack Surface Management**, enabling all downstream security workflows.
***
## Explore Live Demo
Instantly explore how Snapsec Attack Surface Management (ASM) discovers assets, detects exposures, and enables real-time security decisions — all in one unified platform.
# Settings
Source: https://docs.snapsec.co/products/asm/settings
Configure scan schedules, target domains, and vulnerability synchronization for your attack surface monitoring.
## Overview
The **Settings** section allows you to configure how your **Attack Surface Management (ASM)** system operates.
From defining target domains to scheduling scans and enabling integrations, this section controls how assets are discovered, monitored, and synchronized across your security workflows.
***
## Target Domains
Define the domains that ASM should monitor and scan.
* Add root domains (e.g., `example.com`)
* ASM automatically discovers related subdomains and assets
* Multiple domains can be configured
### Why it matters
* Establishes your **attack surface scope**
* Ensures all relevant assets are included in discovery
* Prevents missing shadow or unknown infrastructure
***
## Scan Scheduling
Control how often scans are executed.
### Configuration Options
* **Frequency**
* Once
* Daily
* Weekly
* **Weekday Selection**
* Choose execution day (for weekly scans)
* **Time**
* Define scan start time
* **Manual Trigger**
* Use **Launch Scan Now** to run scans instantly
***
## Launching a Scan
The **Launch Scan Now** button allows immediate execution outside the schedule.
* Useful for **on-demand validation**
* Helps verify fixes after remediation
* Enables quick reassessment of new assets
***
## Vulnerability Synchronization
Configure how detected exposures are synchronized with external systems or internal assessments.
### Key Features
* **Assessment Mapping**
* Link ASM findings to a selected assessment group
* **Search & Select**
* Easily find and assign the correct assessment
* **Automated Sync (Optional)**
* Push findings automatically in real time
***
## Automatic Synchronization
Enable automatic syncing to streamline workflows:
* New exposures are **automatically pushed**
* Reduces manual effort
* Ensures real-time visibility across systems
***
## Workflow Example
1. Add your target domains
2. Configure scan frequency and timing
3. Link an assessment group
4. Enable automatic synchronization (optional)
5. Run scans manually or on schedule
6. Findings flow into Risk Signals and Tickets
***
## Best Practices
* 🌐 Always include **all root domains**
* 🕒 Use **weekly scans** as a baseline
* ⚡ Run manual scans after major changes
* 🔗 Keep assessment mapping updated
* 🔄 Enable auto-sync for real-time workflows
***
## Value to Security Teams
| Benefit | Description |
| --------------------- | ----------------------------------------------------- |
| **Full Control** | Configure how ASM operates |
| **Automation** | Reduce manual intervention |
| **Consistency** | Standardized scanning workflows |
| **Integration Ready** | Seamless connection with ticketing/assessment systems |
***
## From Configuration to Coverage
**Configure → Scan → Detect → Sync → Act**
Settings ensure your ASM platform runs **efficiently, consistently, and intelligently**.
***
## Explore Live Demo
Instantly explore how Snapsec Attack Surface Management (ASM) discovers assets, detects exposures, and enables real-time security decisions — all in one unified platform.
# Tickets
Source: https://docs.snapsec.co/products/asm/tickets
Track, manage, and remediate security exposures through a centralized ticketing workflow integrated with attack surface intelligence.
## Overview
**Tickets** provide a centralized workflow to **track, assign, and remediate security exposures** identified by Risk Signals.
Each exposure can be converted into an actionable ticket, enabling teams to move from detection to resolution efficiently.
***
## Ticket Details
Each ticket provides deep context required for investigation and remediation.
### Includes
* Summary of the issue
* Impact description
* Asset details (IP, domain, subdomain)
* Port, service, and protocol information
* Discovery metadata
***
## Report Panel & Actions
The right-side panel provides quick insights and actions.
### Capabilities
* View CVSS score and vector
* Assign ownership
* Update ticket state
* Download report
* Copy or share findings
***
## Comments & Collaboration
Teams can collaborate directly within tickets.
* Add comments and mentions
* Create blockers
* Track discussion history
***
## Attachments
Add supporting evidence or documentation directly to tickets.
* Drag & drop files
* Upload screenshots or logs
* Maintain investigation artifacts
***
## Actions & Integrations
Tickets integrate directly with remediation workflows.
* Send to VM (Vulnerability Management tools)
* Create or link external tickets
* Sync remediation status
***
## Export & Sync
Manage exposure data at scale.
* Export exposure data
* Sync to VM systems
* Maintain reporting consistency
***
## Exposure Timeline
Track how exposures evolve over time.
* View historical changes
* Track remediation progress
* Identify recurring issues
***
## Workflow Example
1. Exposure is detected via Risk Signals
2. A ticket is created automatically or manually
3. Security team reviews details and assigns ownership
4. Actions are taken (fix, mitigate, or escalate)
5. Ticket is synced with VM or external systems
6. Status is updated and validated
***
## Benefits
✅ Centralized remediation workflow\
✅ Seamless collaboration across teams\
✅ Integrated VM and ticketing actions\
✅ Full visibility into exposure lifecycle\
✅ Audit-ready tracking and documentation
***
## From Detection to Resolution
**Detection → Ticketing → Assignment → Action → Validation**
Tickets ensure every identified risk is **tracked, owned, and resolved**.
***
## Explore Live Demo
Instantly explore how Snapsec Attack Surface Management (ASM) detects exposures, correlates signals, and enables real-time security decisions — all in one unified platform.
# Active Vulnerabilities
Source: https://docs.snapsec.co/products/vm/active-vulnerabilites
Track, triage, and manage all active security findings in one centralized view.
## Overview
The Active Vulnerabilities section provides a **real-time view of all open security findings** across your organization.
It is the primary workspace for:
* Triage and prioritization
* Assignment and ownership
* Tracking remediation progress
* Managing vulnerability lifecycle
***
## Vulnerability Dashboard
### Key Metrics
* **In Review** → Newly identified findings awaiting triage
* **Triaged** → Reviewed and categorized
* **Duplicate** → Repeated findings grouped
* **Retest** → Awaiting verification after fix
* **Fixed in Staging** → Patched but not yet verified
* **Resolved** → Successfully remediated
* **Risk Accepted** → Accepted by business
* **Unresolved** → Still open
* **False Positive** → Invalid findings
* **Not Applicable** → Out of scope
***
## Filtering & Search
### Available Filters
* State
* Severity
* Assessment
* Assignee
* Category
* CWE
* Team
This enables teams to quickly:
* Focus on critical issues
* View team-specific vulnerabilities
* Filter by compliance or category
***
## Create Vulnerability
Use this when adding findings from:
* Manual testing
* External reports
* Bug bounty submissions
### Required Fields
* **Vulnerability Title**
* **Assessment Selection**
***
## Vulnerability Details View
### Report Includes
* CWE mapping
* Category classification
* Detailed description
* Steps to reproduce
* Impact analysis
* References (OWASP, CWE, etc.)
***
## Metadata & Ownership
### Fields Available
* **Owner** → Assigned individual
* **State** → Current lifecycle stage
* **Assessment** → Linked assessment
* **Collaborators** → Supporting users
* **Affected Asset** → Impacted system
* **CWE Mapping** → Standard classification
* **Reported Date**
* **Business Unit**
* **SLA Status**
***
## Collaboration & Activity
Each vulnerability includes:
* **Comments panel** → Team discussion
* **Blockers** → Identify dependencies
* **Activity timeline** → Full audit trail
This ensures complete visibility into:
* Who changed what
* When actions were taken
* Progress toward remediation
***
## Attachments
Upload supporting evidence:
* Screenshots
* Request/response logs
* Exploit proof
***
## Why This Matters
This is where vulnerability management becomes operational.
### Key Benefits
* Centralized vulnerability lifecycle management
* Faster triage and prioritization
* Clear ownership and accountability
* Full audit trail for compliance
* Improved remediation tracking
***
## Where It Fits
Active Vulnerabilities connects with:
* **Assessments** → Source of findings
* **Detection Rules** → How issues are identified
* **Vulnerability Sources** → Confidence & accuracy
* **SLA Module** → Remediation timelines
* **Reports** → Executive visibility
***
## Explore Live Demo
Track, triage, and resolve vulnerabilities efficiently across your organization.
# Archived Vulnerabilities
Source: https://docs.snapsec.co/products/vm/archived-vulnerabilities
Store and manage vulnerabilities that are no longer active but retained for historical and audit purposes.
## Overview
The Archived Vulnerabilities section is used to store vulnerabilities that are **no longer actively tracked** but are preserved for:
* Historical reference
* Audit and compliance
* Long-term record keeping
These vulnerabilities are **removed from active workflows** but remain accessible when needed.
***
## Archived Vulnerabilities List
### What You See
* Vulnerability title
* Archived by (user/system)
* Owner
* Assessment
* Current state
* Severity
***
## Filters & Controls
### Available Filters
* Severity
* State
This helps in:
* Reviewing past issues
* Auditing archived findings
* Searching historical vulnerabilities
***
## Unarchive Vulnerability
You can restore an archived vulnerability back into the workflow.
### How It Works
* Click the **three-dot menu (⋯)**
* Select **Unarchive**
This moves the vulnerability back to:
➡️ Active or Closed state (based on last status)
***
## Archived Vulnerability Details
### Includes
* Full vulnerability report
* Severity and CWE mapping
* Category classification
* Steps to reproduce
* Impact analysis
***
## Metadata & Context
### Available Fields
* Owner
* State
* Assessment
* Affected asset
* CWE
* Reported date
* Business unit
* SLA status
***
## Activity Timeline
Archived vulnerabilities retain full history:
* Comments and discussions
* Status transitions
* Ownership updates
This ensures:
* Complete traceability
* Audit readiness
* Historical accountability
***
## Attachments
All supporting files remain accessible:
* Screenshots
* Logs
* Evidence files
***
## When to Archive
Archive vulnerabilities when:
* They are no longer relevant
* They are superseded by newer findings
* They are retained only for compliance
* They clutter active workflows
***
## Why It Matters
Archiving helps:
* Reduce noise in active dashboards
* Keep workflows focused
* Maintain clean vulnerability pipelines
* Preserve long-term security history
***
## Key Benefits
* Clean and organized vulnerability management
* Full audit trail retention
* Easy restoration when needed
* Improved operational clarity
***
## Where It Fits
Archived Vulnerabilities completes the lifecycle:
* **Active → Closed → Archived**
And integrates with:
* **Reports & Compliance**
* **SLA Tracking**
* **Risk Acceptance**
* **Audit Logs**
***
## Explore Live Demo
Keep your vulnerability lifecycle clean while preserving full historical context.
# Assessment Groups
Source: https://docs.snapsec.co/products/vm/assessment-groups
Organize and manage assessments using folders for better structure, tracking, and navigation.
## Overview
**Assessment Groups** help you organize multiple assessments into structured folders.\
This makes it easier to manage large volumes of security testing across different projects, teams, or environments.
Instead of handling assessments individually, you can group them logically — improving visibility, navigation, and reporting.
***
## What You Can Do
* **Organize Assessments**
* Group related assessments by project, business unit, or testing type
* **Simplify Navigation**
* Quickly access relevant assessments without scrolling through long lists
* **Improve Tracking**
* Monitor multiple assessments within a single context
***
## Creating a Folder
Select **Create Folder** from the Assessment Groups page.
Provide a meaningful name (e.g., *Q1 2026 Assessments*, *Critical Assets*).
Click **Create Folder** to add it to your workspace.
***
## Managing Folders
* **Rename Folder**
* Update folder names as projects evolve
* **Delete Folder**
* Remove folders that are no longer needed
Deleting a folder does not remove the assessments inside it — they remain available in the main assessment list.
***
## Adding Assessments to a Folder
Click on the folder where you want to add assessments.
Use the **Add Assessments** option inside the folder.
Choose one or more assessments from the dropdown list.
Click **Add Assessments** to link them to the folder.
***
## Inside a Folder
Inside a folder, you can:
* View all grouped assessments in one place
* Track their status and progress
* Add more assessments anytime
* Organize further using sub-folders (if applicable)
***
## Why It Matters
Assessment Groups bring structure to your vulnerability management process.
They help you:
* Manage multiple assessments efficiently
* Maintain clarity across teams and projects
* Improve reporting and organization at scale
***
## Explore Live Demo
Experience how Snapsec organizes and manages assessments at scale using structured grouping.
# Assessment Details
Source: https://docs.snapsec.co/products/vm/assessments
Understand, manage, and track a single assessment — from vulnerabilities to reporting.
## Overview
An **Assessment** represents a complete security engagement — combining vulnerabilities, remediation progress, team collaboration, and reporting in one place.
It allows teams to track findings from discovery to resolution while maintaining full visibility and accountability.
***
## What You Can See
* **Assessment Status**
* Track stages like *New, Testing Ongoing, and Remediation*
* **Progress Tracking**
* Monitor resolved vs total vulnerabilities
* **Vulnerability Summary**
* View counts across different states like Open, Resolved, and Retest
* **Team Members**
* Identify contributors working on the assessment
***
## Metrics & Insights
* **Vulnerability Trends**
* Track how issues evolve over time
* **Open vs Closed by Severity**
* Identify bottlenecks in remediation
* **Severity Distribution**
* Understand overall risk exposure
***
## Working with an Assessment
Each assessment is structured into tabs to support different workflows.
***
### Dashboard
* High-level overview of progress and metrics
* Quick visibility into current assessment status
***
### Vulnerabilities
* View and manage all identified vulnerabilities
* Filter by severity, owner, state, or business unit
* Track statuses like *Not Applicable, Open, or Resolved*
***
### Docs & Evidences
* Upload screenshots, logs, and PoCs
* Maintain audit-ready documentation
* Link evidence to vulnerabilities
***
### Activity
* View a complete timeline of actions
* Track updates like scope changes, edits, and status updates
* Maintain full audit trace
***
## Reports
The **Reports** tab allows you to generate multiple types of reports for different stakeholders.
### Available Reports
* **Vulnerability Report**
* Detailed list of all findings with severity and impact
* **Executive Report**
* High-level summary for leadership and decision-makers
* **SLA Report**
* Tracks SLA compliance and violations
* **CSV Export**
* Raw data export for offline analysis
* **Revalidation Report**
* Confirms which vulnerabilities have been fixed
* **Certificate of Completion**
* Proof of assessment completion
***
## Customizing Reports
Before generating reports, you can fully customize their content to match your organization’s standards and reporting needs.
### What You Can Customize
* **Report Title**
* Define how the report will be labeled
* **Author & Reviewer**
* Add ownership and review attribution for audit purposes
* **Executive Summary**
* Provide a high-level overview of findings and risk posture
* **Custom Scope**
* Specify included assets, targets, or exclusions
* **Methodology**
* Describe testing approach, tools, and techniques used
* **Conclusion**
* Summarize overall risk and key takeaways
* **Action Plan**
* Add recommended next steps and remediation strategy
***
## Scope
* Define assets included in testing
* Add domains and IP ranges
* Specify out-of-scope items
***
## Settings
* Update assessment details:
* Name, category, and date
* Business unit and departments
* Manage collaborators
* Control lifecycle:
* Start
* Pause
* Complete
***
## Why It Matters
The Assessment view centralizes everything required to run a security engagement.
It enables:
* Complete visibility across vulnerabilities and progress
* Seamless collaboration between teams
* Structured, customizable reporting for stakeholders and compliance
***
## Explore Live Demo
Experience how Snapsec manages assessments end-to-end — from detection to reporting.
# Asset Catalog
Source: https://docs.snapsec.co/products/vm/assets
Gain complete visibility into your attack surface with real-time asset intelligence and vulnerability correlation.
## Overview
The **Asset Catalog** provides a centralized, real-time view of all assets discovered across your environment — including subdomains, applications, IPs, and infrastructure components.
It combines **asset intelligence + vulnerability context** into a single interface, allowing teams to quickly understand:
* What assets exist
* Which assets are vulnerable
* How risk is distributed
* What needs immediate attention
Each asset is enriched with ownership, vulnerability counts, and remediation progress — enabling faster prioritization and accountability.
Every asset is continuously mapped to vulnerabilities — giving you a live view of your attack surface risk.
***
## Asset Intelligence Dashboard
The top section provides a **quick snapshot of your entire asset landscape**.
### Key Insights
* **Total Assets**
* Total number of discovered assets across all sources
* **Vulnerable Assets**
* Assets currently affected by one or more vulnerabilities
* **Safe Assets**
* Assets with no active vulnerabilities
***
### Visual Breakdowns
* **Asset Type Distribution**
* Understand the composition of your environment (subdomains, IPs, apps, storage, etc.)
* **Vulnerable vs Safe Assets**
* Instantly assess overall exposure
* **Severity Distribution**
* Identify where critical, high, and low-risk assets exist
These visual insights help security teams prioritize high-risk asset categories first.
***
## Filters
Use filters at the top of the table to refine your asset view quickly.\
You can filter assets by:
* **Asset Type**
* **Is Vulnerable**
* **Adapter (source integration)**
* **State**
***
## Asset Inventory Table
The asset table provides a **detailed, actionable view** of every asset.
### Key Columns
* **Asset Name**
* Domain, subdomain, or resource identifier
* **Owner**
* Assigned team or user responsible for the asset
* **Total Vulnerabilities**
* Total number of findings linked to the asset
* **Open Vulnerabilities**
* Breakdown by severity (e.g., High, Low, Info)
* **Remediation Progress**
* Percentage of resolved vulnerabilities
Click any asset to drill down into its full vulnerability list and detailed findings.
***
## Vulnerability Correlation
Each asset is automatically linked to vulnerabilities identified across:
* Assessments
* Scanners and integrations
* Manual testing
This ensures that every finding is tied to its originating asset, giving complete traceability and context.
Assets and vulnerabilities stay continuously synchronized — no manual linking required.
***
## Remediation Progress
Each asset includes a **Remediation Progress Bar** showing the percentage of resolved vs. open vulnerabilities.\
This metric allows teams to track closure rates and measure the impact of their ongoing fixes.
You can also perform quick actions on any asset:
Highlight critical assets that require continuous monitoring.
Ensure accountability by assigning assets to teams or individuals.
Perform actions like updating metadata or removing outdated entries.
***
## Explore Live Demo
Experience how Snapsec delivers real-time asset visibility with vulnerability-driven prioritization.
# Workflow Automation
Source: https://docs.snapsec.co/products/vm/automation-engine
Automate vulnerability management processes using rule-based workflows that execute actions based on configurable conditions.
# Workflow Automation
Workflow Automation enables organizations to automate repetitive vulnerability management tasks by creating rules that evaluate vulnerability attributes and execute predefined actions. This reduces manual effort, standardizes operational processes, and accelerates remediation workflows.
***
## Automation Rules
The **Automation Rules** dashboard provides a centralized view of all configured automation workflows. Each rule displays its execution type, status, and purpose, allowing administrators to quickly review and manage automated processes.
To create a new automation rule:
1. Navigate to **Workflow Automation**
2. Click the **+** button.
3. Provide the rule name and description.
4. Configure rule conditions.
5. Define the automation action.
6. Configure the execution policy.
7. Save the rule.
### Rule Components
| Component | Description |
| ---------------- | -------------------------------------------------- |
| Rule Name | Unique identifier for the automation rule. |
| Description | Brief explanation of the rule's purpose. |
| Conditions | Criteria that determine when the rule executes. |
| Action | Operation performed when conditions are satisfied. |
| Execution Policy | Defines when and how the rule is triggered. |
***
## Configure an Automation Rule
Automation rules are created using three configuration stages:
### Conditions
Specify the vulnerability attributes that must match before the automation executes.
Common condition fields include:
* Severity
* State
* Source
* Category
* Owner
* Business Unit
* Asset Type
### Actions
Define the operation performed after all configured conditions are satisfied.
Examples include:
* Assign vulnerability owner
* Update vulnerability state
* Execute False Positive Analysis
* Modify vulnerability attributes
### Execution Policy
Configure how the rule is triggered.
| Policy | Description |
| ----------- | ------------------------------------------------------------------ |
| Event Based | Executes automatically when configured vulnerability events occur. |
| Manual | Executes only when manually initiated by an administrator. |
Automation rules execute only when all configured conditions evaluate successfully.
***
## Rule Details & Execution History
Selecting a rule displays its complete configuration and execution history.
The **Details** tab provides:
* Rule description
* Execution policy
* Trigger events
* Configured conditions
* Configured actions
* Matching vulnerabilities
The **Jobs** tab records every execution of the automation rule, including:
* Job ID
* Execution status
* Trigger type
* Creation time
* Last updated timestamp
This history helps administrators verify successful executions and troubleshoot workflow behavior when necessary.
***
## Execute Automation Rules
Automation rules configured for manual execution can be started directly from the rule details page using the **Execute Now** option.
Before execution, the platform requests confirmation to prevent accidental workflow execution.
After confirmation, Snapsec:
1. Evaluates the configured rule conditions.
2. Identifies matching vulnerabilities.
3. Executes the configured actions.
4. Records the execution as a job for auditing and tracking.
***
## Why Workflow Automation Matters
Workflow Automation helps organizations standardize vulnerability management by reducing repetitive manual tasks and ensuring security processes are executed consistently.
### Benefits
* Faster vulnerability remediation
* Reduced operational overhead
* Consistent security workflows
* Automated policy enforcement
* Complete execution history and auditability
***
## Explore Live Demo
Discover how Snapsec automates vulnerability management through configurable rules, intelligent execution policies, and workflow-driven actions that reduce manual effort and improve operational efficiency.
# Blockers
Source: https://docs.snapsec.co/products/vm/blockers
Track and manage issues that prevent vulnerability remediation or progress.
## Overview
**Blockers** help teams track issues that delay or prevent vulnerability remediation.
Whenever progress is blocked — due to dependencies, missing access, or validation delays — a blocker ensures the issue is visible, assigned, and tracked until resolution.
Each blocker is linked to a vulnerability and includes ownership, status, and activity history.
Blockers ensure that no remediation delay goes unnoticed — every dependency or issue is tracked with clear ownership.
***
## What You Can Do
* **Track All Blockers**
* View all blockers across vulnerabilities
* **Filter and Search**
* Quickly find blockers using status, priority, or assignee
* **Manage Ownership**
* Assign blockers to responsible team members
* **Monitor Status**
* Track blockers as *Pending* or *Resolved*
***
## Blocker Views
The Blockers section provides two key views:
* **My Blockers**
* Displays blockers assigned to you
* **All Blockers**
* Displays all blockers across the organization
Use *My Blockers* to focus on your tasks and *All Blockers* for complete visibility across teams.
***
## Filtering and Search
You can refine blockers using:
* **Search**
* **Status**
* **Priority**
* **Assignee**
Filtering helps quickly identify unresolved blockers or high-priority delays.
***
## Creating a Blocker
Blockers are created directly from within a vulnerability when progress is blocked.
Navigate to a vulnerability where progress is stalled.
In the **Comment & Blocker Panel**, enter details and enable **Create a Blocker**.
Add description and assign a user, then submit the blocker.
***
## Managing Blockers
Once created, blockers can be updated and resolved directly.
* **Mark as Resolved**
* Close the blocker once the issue is fixed
* **Reopen Blocker**
* Reopen if the issue persists
* **Track Ownership**
* View assigned user and creator
***
## Activity Timeline
All blocker actions are recorded in the **Recent Activity** section:
* Creation
* Status updates
* Resolution
* Reopening
All blocker actions are automatically logged, ensuring full audit visibility.
***
## Why It Matters
Blockers ensure that remediation workflows remain transparent and accountable.
They help teams:
* Identify delays early
* Assign responsibility clearly
* Maintain visibility across teams
* Keep remediation workflows moving efficiently
***
## Explore Live Demo
Experience how Snapsec helps teams track and resolve blockers in real time.
# Business Units
Source: https://docs.snapsec.co/products/vm/business-units
Organize vulnerabilities, assessments, and remediation ownership by business function or team.
## Business Units Overview
The **Business Units** dashboard provides a high-level view of how vulnerabilities and assessments are distributed across organizational teams.
Each card represents a business function or team, enabling clear ownership, accountability, and risk visibility.
### What You Can See
* Business unit name and description
* Assigned owner or responsible lead
* Vulnerability counts by severity (Critical → Info)
* Quick access to detailed unit-level security metrics
This view helps security leaders quickly understand **where risk lives inside the organization**.
***
## Create a Business Unit
Business units can be created to align vulnerability ownership with real-world organizational structure.
### Fields Required
* **Name** — Business unit identifier (e.g., Security Operations, DevOps, Product Engineering)
* **Description** — Scope and responsibility of the unit
* **Owner** — Accountable individual or team
* **Logo URL** *(optional)* — Visual identifier
Once created, business units can be assigned to:
* Vulnerabilities
* Assessments
* Assets involved in remediation workflows
***
## Business Unit Details (Inside a Business Unit)
Selecting **View Details** opens the dedicated business unit page with consolidated vulnerability metrics.
### Summary Metrics Include
* **Total Vulnerabilities**
* **Total Assessments**
* **Open Vulnerabilities**
* **Closed Vulnerabilities**
* **Average CVSS Score**
Ownership information is prominently displayed to reinforce accountability and speed up remediation coordination.
***
## Security Analytics & Associated Assessments
Scrolling further reveals deeper vulnerability analytics and assessment relationships for the selected business unit.
### Available Insights
* **Vulnerability Timeline** — Track detections over time
* **Severity Distribution** — Critical, High, Medium, Low breakdown
* **Detections vs Resolutions** — Measure remediation effectiveness
* **Vulnerabilities by Status** — In Progress, Fixed, Resolved, etc.
* **Associated Assessments** — Security assessments linked to the unit
This view enables teams to assess **both exposure and remediation performance** at a business-unit level.
***
## Example Use Cases
* **Security Operations:** Track remediation progress by team ownership
* **Engineering Managers:** Understand vulnerability impact on their teams
* **Compliance Teams:** Ensure every assessment and finding has a clear owner
* **Leadership:** Gain visibility into organizational security maturity
***
## Explore Live Demo
Explore how Snapsec VM organizes vulnerabilities and assessments by business unit ownership — all without creating an account.
# Change Management
Source: https://docs.snapsec.co/products/vm/change-management
Create, track, and validate change requests through a structured security review workflow.
## Overview
The **Change Management** module helps teams track and validate application or infrastructure changes before deployment.
It ensures that every release, feature update, or configuration change goes through a structured security review process.
Every change request acts as a security checkpoint before deployment — ensuring controlled and auditable releases.
***
## What You Can Do
* **Create Change Requests**
* Submit new requests for security validation
* **Track Status**
* Monitor requests as *Pending* or *Completed*
* **Prioritize Work**
* Assign priority levels like *Low* or *Medium*
* **View Risk Impact**
* Track vulnerabilities linked to each request
Use priorities to align security testing with release urgency — critical fixes can be validated faster without delaying deployments.
***
## Change Requests List
The **Change Requests** page provides a centralized view of all submitted requests.
### Key Details
* **Change Title**
* Name of the request or release
* **Vulnerabilities**
* Linked findings (if any)
* **Dates**
* Request date and report deadline
* **Priority**
* Indicates urgency
* **Assessment State**
* Tracks progress (*Pending / Completed*)
This view is ideal for quickly identifying pending validations and high-priority requests across teams.
***
## Creating a Change Request
Creating a request involves filling structured sections that capture all necessary context.
Providing complete and accurate details ensures faster validation and reduces back-and-forth during testing.
***
### 1. Request Summary
* **Priority Level**
* **Request Title**
* **Requester Name / Team**
* **Contact Information**
* **Jira Ticket ID**
* **Change Summary**
***
### 2. Timeline
* **Date of Request**
* **Planned Go-Live Date**
* **Deadline for Report**
Accurate timelines help align security testing with release schedules and prevent last-minute delays.
***
### 3. Application Info
* **Application Service Name**
* **Tech Stack & Frameworks**
* **Third-Party Integrations**
***
### 4. Testing Environment
* **Environment Type** (e.g., Development, Staging)
* **Test URL or IP**
***
### 5. Authentication & Access
* **Authentication Type**
* **Test Credentials**
Always provide valid test credentials to ensure complete coverage during security testing.
***
### 6. API Documentation
* **Swagger / API URL**
* **Upload supporting files**
Providing API documentation improves testing accuracy and helps identify deeper vulnerabilities faster.
***
## Final Step
* Click **Create Request** to submit
* The request appears in the Change Requests list
* Status is automatically tracked
Once submitted, the request becomes part of your security workflow and can be tracked until completion.
***
## Why It Matters
Change Management ensures that every release is validated before going live.
It helps teams:
* Maintain visibility over all changes
* Reduce risk from untested updates
* Align development with structured security validation
***
## Explore Live Demo
Experience how Snapsec validates and tracks change requests in a structured workflow.
# Closed Vulnerabilities
Source: https://docs.snapsec.co/products/vm/closed-vulnerabilities
Track resolved, accepted, and finalized vulnerabilities across your organization.
## Overview
The Closed Vulnerabilities section provides visibility into **completed vulnerability lifecycle states**.
This includes:
* Successfully resolved issues
* Risk-accepted vulnerabilities
* False positives
* Non-applicable findings
It acts as your **historical record and audit layer**.
***
## Closed Vulnerability Dashboard
### Key Metrics
* **Resolved** → Fully remediated vulnerabilities
* **Risk Accepted** → Accepted by business decision
* **False Positive** → Invalid findings dismissed
* **Not Applicable** → Out-of-scope or irrelevant
* **Retest** → Pending verification
* **Fixed in Staging** → Awaiting confirmation
***
## Filtering & Search
### Filters Available
* State
* Severity
* Assessment
* Assignee
* Category
* CWE
* Team
This allows:
* Reviewing historical fixes
* Validating remediation trends
* Auditing team performance
***
## Create Vulnerability
You can manually add vulnerabilities that are:
* Already resolved externally
* Imported from legacy systems
* Reported post-fix
***
## Closed Vulnerability Details
### Report Includes
* CWE classification
* Category mapping
* Full vulnerability description
* Steps to reproduce
* Impact analysis
* References
***
## Metadata & Status Tracking
### Available Fields
* **Owner**
* **State (Resolved / Retest / Accepted)**
* **Assessment**
* **Affected Asset**
* **CWE Mapping**
* **Reported Date**
* **Business Unit**
* **SLA Status**
***
## Activity Timeline & Audit Trail
Each closed vulnerability maintains a **complete history**:
* State transitions
* Ownership changes
* Comments and discussions
* Validation updates
This ensures:
* Full compliance tracking
* Transparent remediation history
* Easy audit readiness
***
## Attachments
Store proof of remediation:
* Fix validation screenshots
* Logs and evidence
* Security reports
***
## Why This Matters
Closed vulnerabilities are not just “done issues” — they are your:
* **Proof of security maturity**
* **Audit evidence for compliance**
* **Source of remediation insights**
***
## Key Benefits
* Complete historical tracking
* Audit-ready documentation
* Visibility into remediation efficiency
* Reduced duplication of issues
* Stronger compliance posture
***
## Where It Fits
Closed Vulnerabilities connects with:
* **Active Vulnerabilities** → Lifecycle transition
* **Assessments** → Source of findings
* **SLA Module** → Resolution timelines
* **Reports** → Executive summaries
* **Risk Acceptance** → Business decisions
***
## Explore Live Demo
Validate fixes, track history, and maintain compliance across your organization.
# Dashboard
Source: https://docs.snapsec.co/products/vm/dashboard
Monitor your organization's security posture through dedicated analytics dashboards for risk, operations, and vulnerability sources.
# Risk Analytics
## Overview
The **Risk Analytics** dashboard provides an executive-level view of your organization's security posture. It combines vulnerability statistics, organizational risk scoring, SLA compliance, threat exposure, and remediation trends into a single dashboard, enabling security teams and leadership to quickly understand where the greatest risks exist.
Rather than focusing on individual vulnerabilities, Risk Analytics presents a comprehensive view of your security program, helping teams prioritize remediation efforts based on business impact and overall exposure.
Risk Analytics continuously aggregates vulnerability data to provide an always up-to-date view of your organization's overall security posture.
***
## Executive Summary
The summary cards at the top of the dashboard provide an instant snapshot of your current vulnerability landscape.
### Available Metrics
* **Total Open**
* Displays the total number of unresolved vulnerabilities.
* **Critical**
* Number of active Critical severity vulnerabilities.
* **High**
* Number of High severity vulnerabilities.
* **Medium**
* Number of Medium severity vulnerabilities.
* **Unique CVEs**
* Total unique CVEs currently affecting your environment.
* **Unique CWEs**
* Number of unique weakness categories represented across findings.
* **Known Exploited Vulnerabilities (KEV)**
* Vulnerabilities listed in the CISA Known Exploited Vulnerabilities catalog.
* **Average CVSS**
* Average CVSS score across all active findings.
***
## Organization Risk Score
The **Organization Risk Score** provides an overall measurement of your security posture.
The score is dynamically calculated using multiple factors including:
* Vulnerability severity
* True Risk prioritization
* Business impact
* Asset exposure
* Active vulnerabilities
* Organizational risk weighting
As vulnerabilities are discovered or remediated, the score automatically updates to reflect your current risk posture.
***
## SLA Compliance Overview
The SLA Compliance widget tracks remediation performance against defined Service Level Agreements.
It provides visibility into:
* Compliant vulnerabilities
* At Risk vulnerabilities
* Breached vulnerabilities
* Vulnerabilities without assigned SLAs
Additional operational metrics include:
* **MTTR (Mean Time to Resolution)**
* **Remediation Velocity**
These metrics help measure how effectively vulnerabilities are being resolved within expected timelines.
***
## Threat Exposure
The Threat Exposure panel summarizes your organization's exposure based on multiple security indicators.
Key metrics include:
* Overall Exposure Score
* Known Exploited Vulnerabilities (KEV)
* High EPSS vulnerabilities
* High and Critical findings
* Average CVSS
* Unique CVEs
These indicators help identify areas requiring immediate remediation.
***
## Severity Trend
The **Severity Trend** graph visualizes how vulnerability severity changes over time.
This allows teams to monitor:
* New vulnerabilities introduced
* Reduction through remediation
* Overall security posture improvements
* Historical remediation progress
***
## Average Open Age
The **Average Open Age by Severity** visualization shows how long vulnerabilities remain unresolved across each severity level.
This helps identify:
* Aging Critical vulnerabilities
* Long-standing High severity findings
* Medium and Low severity backlog
* Overall remediation efficiency
***
## Executive Insights
The Executive Insights panel automatically highlights the most important remediation opportunities and security observations.
Typical recommendations include:
* Critical vulnerabilities with the highest impact
* High severity findings driving organizational risk
* SLA breaches requiring immediate attention
* Remediation blockers delaying progress
* Accepted risks that should be periodically reviewed
Executive Insights continuously adapt to changes in your vulnerability data, ensuring recommendations remain relevant as your environment evolves.
***
## Why Risk Analytics Matters
Risk Analytics transforms vulnerability data into actionable security intelligence by helping organizations:
* Understand overall organizational risk
* Monitor remediation performance
* Track SLA compliance
* Measure threat exposure
* Prioritize vulnerabilities effectively
* Present executive-ready security metrics
***
# Operational Analytics
## Overview
The **Operational Analytics** dashboard provides a detailed view of your organization's day-to-day vulnerability management activities. It focuses on remediation progress, vulnerability lifecycle tracking, SLA performance, and team productivity to help security teams monitor operational effectiveness.
Unlike Risk Analytics, which focuses on overall organizational risk, Operational Analytics helps security teams understand **how efficiently vulnerabilities are being managed and resolved**.
Operational Analytics provides real-time operational insights, enabling security teams to identify bottlenecks and continuously improve remediation performance.
***
## Operational Summary
The summary section provides an instant overview of vulnerability lifecycle states.
### Available Metrics
* **Total Vulnerabilities**
* Total vulnerabilities currently tracked.
* **In Review**
* Findings awaiting triage.
* **Triaged**
* Vulnerabilities that have been reviewed and categorized.
* **Unresolved**
* Open vulnerabilities still awaiting remediation.
* **Duplicate**
* Duplicate findings linked to existing vulnerabilities.
* **Retest**
* Vulnerabilities awaiting verification after remediation.
* **Fixed in Staging**
* Vulnerabilities resolved in staging environments and awaiting production validation.
* **Resolved**
* Successfully remediated vulnerabilities.
* **Risk Accepted**
* Vulnerabilities accepted by the organization after risk assessment.
* **Rejected**
* Findings determined to be invalid or not applicable.
***
## Vulnerability Discovery Timeline
The timeline visualizes how vulnerabilities are discovered over time, helping teams identify spikes in findings and monitor remediation trends.
This visualization assists with:
* Monitoring assessment activity
* Identifying unusual increases in findings
* Measuring remediation progress
* Understanding long-term security trends
***
## Operational Widgets
The dashboard includes several widgets that provide detailed operational insights.
### Severity Distribution
Displays the distribution of vulnerabilities across:
* Critical
* High
* Medium
* Low
* Informational
This helps teams understand where the majority of security issues exist.
***
### Open vs Closed by Severity
Compares resolved and unresolved vulnerabilities across each severity level.
This enables teams to quickly determine whether high-risk vulnerabilities are being remediated effectively.
***
### SLA Compliance
Measures remediation performance against defined Service Level Agreements.
Displays:
* Within SLA
* At Risk
* Breached
* No SLA Assigned
Helping organizations identify overdue remediation activities.
***
### Top Performing Members
Ranks team members based on remediation activity and vulnerability closures.
This provides visibility into:
* Individual contributions
* Team productivity
* Workload distribution
***
### Vulnerabilities by Business Unit
Displays how vulnerabilities are distributed across different business units.
This helps organizations identify departments requiring additional security attention.
***
### Remediation by Department
Measures remediation performance across organizational departments.
Useful for identifying:
* Teams resolving vulnerabilities quickly
* Departments with growing remediation backlogs
***
## Advanced Operational Metrics
Operational Analytics also includes advanced measurements for tracking remediation efficiency.
### Mean Time to Close (MTTC)
Measures the average time required to resolve vulnerabilities.
This KPI helps evaluate overall remediation effectiveness.
***
### Average Vulnerability Age
Displays the average age of unresolved vulnerabilities grouped by severity.
Older vulnerabilities often indicate remediation bottlenecks or resource constraints.
***
### Vulnerability Source Distribution
Shows where vulnerabilities originate.
Examples include:
* Qualys
* Nuclei
* Trivy
* Manual Assessments
* Other integrated scanners
Understanding source distribution helps evaluate scanner usage and assessment coverage.
***
## Custom Dashboards
Operational Analytics supports creating multiple custom dashboards for different teams, projects, or reporting requirements.
To create a dashboard:
1. Click the **+** button beside the dashboard selector.
2. Enter a dashboard name.
3. Provide an optional description.
4. Select related assessments.
5. Choose dashboard visibility.
6. Save the dashboard.
Custom dashboards allow teams to maintain focused operational views for specific business units or security initiatives.
***
## Dashboard Configuration
Each dashboard can be customized with:
* Dashboard Name
* Description
* Linked Assessments
* Public or Private Visibility
This allows organizations to tailor reporting for different audiences while maintaining centralized vulnerability data.
***
## Why Operational Analytics Matters
Operational Analytics transforms remediation activities into measurable operational metrics.
It enables organizations to:
* Monitor remediation progress
* Track SLA performance
* Measure team productivity
* Identify operational bottlenecks
* Improve remediation efficiency
* Build customized dashboards for different teams
By combining lifecycle tracking with performance metrics, Operational Analytics helps security teams continuously improve their vulnerability management process.
***
# Source Analytics
## Overview
The **Source Analytics** dashboard provides comprehensive insights into the quality, reliability, and effectiveness of every vulnerability source integrated with Snapsec VM.
Rather than simply counting vulnerabilities, Source Analytics helps security teams understand **where findings originate, how accurate those findings are, and which scanners provide the highest confidence results**.
This enables organizations to continuously improve their security tooling while reducing false positives and prioritizing trusted sources.
Source Analytics transforms scanner data into actionable intelligence by measuring accuracy, confidence, and overall signal quality across every integrated source.
***
## Source Overview
The dashboard begins with a high-level summary of all registered vulnerability sources.
### Available Metrics
* **Total Sources**
* Total number of configured vulnerability sources.
* **Active Sources**
* Sources currently contributing findings.
* **Total Findings**
* Combined findings across all configured sources.
* **Accuracy Rate**
* Overall percentage of validated findings.
* **Noisy Sources**
* Sources generating excessive false positives.
* **High Confidence Sources**
* Sources consistently producing reliable findings.
These metrics provide an immediate understanding of the overall quality of your vulnerability ingestion pipeline.
***
## Source Performance
The dashboard includes several visualizations that help evaluate scanner performance.
### Findings by Source
Displays how vulnerabilities are distributed across each integrated scanner or manual source.
This helps identify:
* Primary vulnerability producers
* Scanner utilization
* Assessment coverage
***
### Findings Classification
Breaks down findings into categories such as:
* Valid
* False Positive
* Risk Accepted
Helping teams understand overall signal quality.
***
### Source Activity
Visualizes source activity over time, showing how many findings each source contributes throughout the year.
This enables organizations to monitor scanner usage and identify changes in vulnerability discovery patterns.
***
## Sources Inventory
The Sources Inventory provides a centralized list of every registered vulnerability source.
Each entry includes:
* Source Name
* Source Type
* Linked Projects
* Total Findings
* Valid Findings
* False Positives
* Accuracy Percentage
* Confidence Level
This inventory enables security teams to compare scanners and monitor the quality of imported findings.
***
## Managing Sources
Each source can be searched, filtered, and managed directly from the inventory.
Common management tasks include:
* Viewing source performance
* Comparing scanners
* Tracking confidence levels
* Reviewing historical activity
This makes it easy to identify sources that require tuning or validation.
***
## Registering a Source
New scanners and assessment tools can be added directly from the Source Analytics dashboard.
When registering a source, configure:
* **Source Name**
* **Source Type**
* **Confidence Level**
* **Description**
This allows organizations to onboard commercial scanners, open-source tools, or manual assessment sources into a single reporting framework.
***
## Sources List
The **Sources List** provides a centralized inventory of every vulnerability source configured in Snapsec VM. It allows security teams to monitor source activity, compare performance, and review the quality of findings generated by each scanner or manual source.
Each source includes detailed operational metrics, making it easy to evaluate reliability and identify underperforming integrations.
### Information Available
* **Source Name**
* Name and description of the registered source.
* **Type**
* Indicates whether the source is a scanner, manual source, or another supported type.
* **Projects**
* Number of projects associated with the source.
* **Findings**
* Total vulnerabilities reported by the source.
* **Valid / False Positives**
* Breakdown of validated findings versus false positives.
* **Accuracy**
* Overall accuracy score based on validated findings.
* **Confidence**
* Confidence level assigned to the source.
Use the search bar to quickly locate a source or customize the table using the **Columns** option to display only the information most relevant to your workflow.
***
## Signal Analytics
Signal Analytics evaluates the quality and trustworthiness of vulnerability data collected from every integrated source. Rather than focusing on the number of findings, it measures how reliable each source is by analyzing accuracy and false-positive rates.
This helps organizations identify trusted scanners, reduce noise, and improve overall vulnerability prioritization.
### Noise vs Accuracy Analysis
For every configured source, Snapsec measures:
* **Total Findings**
* **Valid Findings**
* **False Positives**
* **False Positive Rate**
* **Accuracy Percentage**
* **Signal Rating** (High Trust or Noisy)
These metrics make it easy to distinguish high-quality scanners from sources that require tuning or validation.
### Confidence Distribution
The dashboard also provides a confidence breakdown across all registered sources, grouping them into:
* **High Confidence**
* Sources consistently producing reliable, high-quality findings.
* **Medium Confidence**
* Sources with good accuracy that may require occasional validation.
* **Low Confidence**
* Sources generating inconsistent or low-confidence results.
Together, these insights help security teams improve scanner effectiveness, reduce false positives, and build greater confidence in the vulnerability data used for remediation decisions.
## Why Source Analytics Matters
Source Analytics enables organizations to continuously improve the quality of vulnerability data entering Snapsec VM.
It helps teams:
* Measure scanner effectiveness
* Reduce false positives
* Increase confidence in findings
* Optimize security tooling
* Improve vulnerability prioritization
* Build trust in remediation decisions
By combining operational metrics with scanner intelligence, Source Analytics ensures that remediation efforts are based on reliable, high-quality security data.
***
## Explore Live Demo
Experience how Snapsec Risk Analytics provides real-time visibility into organizational risk, threat exposure, and remediation performance through a unified executive dashboard.
# Prioritization
Source: https://docs.snapsec.co/products/vm/normalization-engine
Prioritize vulnerabilities using remediation campaigns, contextual risk analysis, false positive validation, and customizable risk scoring.
## Remediation Campaigns
Remediation Campaigns consolidate related vulnerabilities into actionable remediation efforts, allowing security teams to resolve multiple findings through a single coordinated workflow.
To begin working with a remediation campaign:
1. Navigate to **Prioritization**
2. Open the **Remediation Campaigns** section
3. Select a campaign from the list
4. Review campaign details and affected assets
5. Track remediation progress
6. Resolve vulnerabilities through the campaign workflow
### Campaign Information
| Item | Description |
| --------------- | ------------------------------------------------------------ |
| Campaign Name | Name assigned to the remediation campaign |
| Vulnerabilities | Total vulnerabilities included in the campaign |
| Assets | Number of impacted assets |
| Status | Current remediation status |
| Risk Reduction | Estimated reduction in organizational risk after remediation |
***
## Campaign Dashboard
The dashboard provides a centralized overview of campaign activity, including remediation status, affected assets, ownership, and campaign progress.
### Dashboard Overview
| Section | Description |
| --------------------- | ------------------------------------------------------ |
| Campaign Summary | Displays campaign information and remediation progress |
| Risk Metrics | Shows campaign impact and expected risk reduction |
| Asset Summary | Lists affected assets participating in the campaign |
| Vulnerability Summary | Displays vulnerabilities included in the campaign |
Interactive charts provide visibility into:
* Resolution timeline
* Severity distribution
* Vulnerability state distribution
* Campaign progress
***
## Campaign Assets
The **Assets** tab identifies every asset included in the selected campaign.
Each asset displays:
* Asset name
* Vulnerability count
* Associated component
* Recommended remediation
***
## Campaign Vulnerabilities
The **Vulnerabilities** tab lists every vulnerability associated with the campaign, allowing analysts to review severity, ownership, and remediation status from a single location.
***
## False Positive Analysis
False Positive Analysis helps analysts verify scanner findings before remediation begins.
### Validation Process
1. Open a flagged vulnerability
2. Review AI-assisted analysis
3. Validate the detection
4. Mark as False Positive or Confirmed
5. Save the review
Accurate false positive validation reduces unnecessary remediation effort while improving vulnerability data quality.
***
## Risk Relevance Groups
Risk Relevance Groups automatically classify vulnerabilities that share similar exploitation characteristics, enabling analysts to investigate related findings together.
### Group Overview
| Item | Description |
| --------------- | ------------------------------------------- |
| Risk Group | Logical grouping of related vulnerabilities |
| Vulnerabilities | Findings included in the group |
| Risk Points | Combined contextual risk score |
| Status | Current remediation progress |
***
## Risk Group Dashboard
The dashboard provides visibility into:
* Resolution trends
* Severity distribution
* Vulnerability lifecycle
* Overall remediation progress
***
## Group Vulnerabilities
Each vulnerability includes:
* Severity
* Owner
* Current status
* Risk score
***
## Group Actions
Automation rules can be attached directly to Risk Relevance Groups to streamline operational workflows.
Supported actions include:
* Assign ownership
* Update vulnerability state
* Execute custom workflows
* Trigger automated actions
Each rule includes:
* Trigger conditions
* Execution policy
* Configured actions
* Matching criteria
***
## About Risk Groups
The **About** section explains the group's purpose, associated exploitation characteristics, and recommended remediation approach.
***
## True Risk
True Risk enables organizations to prioritize vulnerabilities using a customizable scoring model that combines technical severity with business context.
***
## Configure Risk Scoring
The scoring framework combines multiple prioritization factors into a single risk score.
### Available Risk Factors
| Factor | Description |
| ------------- | ---------------------------------------- |
| CVSS | Base vulnerability severity |
| Exposure | Internet-facing and internal exposure |
| SLA | SLA compliance and remediation deadlines |
| EPSS | Exploit Prediction Scoring System |
| KEV | Known Exploited Vulnerabilities |
| Asset Type | Criticality based on asset category |
| Business Unit | Organizational business impact |
***
## Configure Individual Risk Categories
Configure weighting for:
* CVSS Severity
* Exposure Prioritization
Configure:
* SLA compliance
* EPSS probability scoring
Additional scoring factors include:
* Known Exploited Vulnerabilities (KEV)
* Asset Type Prioritization
* Business Unit Risk
True Risk allows organizations to build a prioritization model that reflects their own operational, technical, and business requirements instead of relying solely on CVSS scores.
***
## Explore Live Demo
Experience how Snapsec prioritizes vulnerabilities using Remediation Campaigns, False Positive Analysis, Risk Relevance Groups, and True Risk scoring to help security teams focus on the vulnerabilities that matter most.
# Vulnerability Ownership
Source: https://docs.snapsec.co/products/vm/ownership
Assign, manage, and track vulnerability ownership across assessments and teams for better accountability and faster remediation.
## Overview
The **Vulnerability Ownership** feature brings clarity and accountability to your remediation workflow.\
It lets you **assign specific vulnerabilities to owners**, **invite collaborators** to assessments, and **filter findings** by responsible users — ensuring that each issue has a clear point of contact for resolution.
***
## Value
Ensure every vulnerability has a responsible owner for faster and transparent remediation.
Collaborate across security and engineering teams directly within assessments.
Filter, track, and monitor vulnerability ownership across teams and reports.
Ownership details automatically feed into SLA and Change Management metrics.
***
## Inviting or Removing Members from an Assessment
Collaborators can be added or removed from any assessment to manage visibility and responsibilities efficiently.
Navigate to the **Basic Details** tab of an assessment.
Use the **Add New Member** field to invite team members by their email.\
Added members gain access to view and manage vulnerabilities in that assessment.
To revoke access, click on the user’s profile and remove them from the collaborator list.
***
## Assigning a Vulnerability to an Owner
Every vulnerability can be directly assigned to a team member or developer, defining responsibility for its remediation.
Select a vulnerability from the list to view its **Report Details**.
Use the **Owner** dropdown to search and select a user. Once assigned, the user becomes responsible for resolving that issue.
Ownership is reflected in SLA Analytics, Violations, and Change Management dashboards for consistent performance tracking.
***
## Filtering Tickets by Owner
You can easily view and prioritize vulnerabilities based on ownership across assessments.
Go to the **Vulnerabilities** section in the VM module.
Use the **Owner filter** to view vulnerabilities assigned to specific users or teams.
Combine filters such as **Severity**, **State**, and **Assessment** to refine your search further.
***
## Explore Live Demo
Jump straight into the live environment and see how Snapsec unifies asset intelligence, threat detection, and vulnerability tracking — all in one dashboard.
# Reports
Source: https://docs.snapsec.co/products/vm/reports
Search, generate, and manage vulnerability and executive reports with a streamlined, action-first workflow.
## Overview
The **Reports** page provides a centralized and simplified interface to manage all generated reports across your environment.
From vulnerability exports to executive summaries, reports can be quickly generated, searched, and managed — all from a single view.
Each report is linked to its source assessment (if applicable) and includes its current state, allowing teams to track and access reports effortlessly.
Reports are generated on-demand and stored automatically, ensuring instant access and complete traceability.
***
## Search & Discover
The **search bar** enables instant filtering of reports by title.
This allows teams to quickly locate specific reports without navigating through long lists.
### Capabilities
* Search by report name or keyword
* Instant filtering of results
* Efficient navigation across large datasets
***
## Generate Reports
Reports can be generated directly from the Reports page using a simple and guided flow.
Use the **Generate Report** button at the top-right corner.
Choose the required report format:
* Full Re-Validation Report
* Full Executive Report
* All Vulnerabilities
* Assessment Specific
* Change Request
Submit the request — Snapsec automatically compiles the report using the latest available data.
Report generation automatically aggregates vulnerabilities, metadata, and remediation status — eliminating manual effort.
***
## Manage Reports
Each report includes an **actions menu (⋯)** that provides quick access to key operations.
### Available Actions
* **Download**\
Download the generated report instantly for sharing or documentation
* **Delete**\
Remove outdated or unnecessary reports
***
## Report List & Status
The reports table provides a structured view of all generated reports:
* **Report Name** — Title and type of report
* **Assessment Name** — Associated assessment (if available)
* **State** — Current status (e.g., Completed)
* **Actions** — Quick access to report operations
This layout ensures clarity, quick access, and efficient report management.
***
## Why It Matters
The redesigned Reports module enables:
* Faster report generation workflows
* Instant search and retrieval
* Simplified report management via quick actions
* Consistent reporting across technical and executive use cases
Convert vulnerability data into structured, shareable insights in seconds.
***
## Explore Live Demo
Generate, search, and manage reports in a unified vulnerability management platform.
# Risk Acceptance
Source: https://docs.snapsec.co/products/vm/risk-acceptance
Review, approve, or reject risk acceptance requests raised for vulnerabilities.
## Overview
**Risk Acceptance** allows organizations to formally accept certain vulnerabilities when immediate remediation is not feasible.
Instead of leaving vulnerabilities unresolved, teams can raise a **risk acceptance request** with justification, business context, and compensating controls — ensuring every decision is documented, reviewed, and auditable.
Risk Acceptance ensures that accepted risks are **intentional, reviewed, and documented** — not ignored.
***
## What You Can Do
* **Review Requests**
* View all submitted risk acceptance requests
* **Approve or Reject**
* Take action based on risk, justification, and business impact
* **Track Status**
* Monitor requests as *Pending, Approved, or Rejected*
* **Maintain Audit Trail**
* Keep full visibility of decisions and approvers
***
## Escalations List
The **Escalations** page provides a centralized view of all risk acceptance requests.
### Key Details
* **Vulnerability**
* Associated vulnerability for which risk is being accepted
* **Requested By**
* User who raised the request
* **Status**
* *Pending, Approved, Rejected*
* **Reason**
* Summary of why acceptance is requested
* **Approver**
* Assigned reviewer or decision-maker
* **Resolution Date**
* Date of approval or rejection
* **Actions**
* Take action directly from the table
Use filters to quickly identify pending approvals or high-risk requests requiring immediate attention.
***
## Reviewing a Request
Click **Take Action** to open the full request details.
### Included Information
* **Vulnerability Context**
* **Submitted By & Date**
* **Reason for Acceptance**
* **Business Justification**
* **Compensating Controls**
***
## Taking Action
From the request panel, you can:
* **Approve**
* Accept the risk based on justification and controls
* **Reject**
* Require remediation or additional clarification
Approval should be based on risk impact, business necessity, and presence of compensating controls.
***
## Dashboard Insights
The dashboard provides a high-level overview of:
* Total requests
* Pending approvals
* Approved requests
* Rejected requests
It also includes visual breakdowns by:
* **Business Unit**
* **Severity**
* **Department**
***
## Why It Matters
Risk Acceptance brings governance and accountability into vulnerability management.
It ensures:
* No vulnerability is silently ignored
* Business decisions are documented and justified
* Security and business teams stay aligned
* Compliance and audit requirements are met
***
## Explore Live Demo
Experience how Snapsec enables structured risk acceptance and approval workflows.
# Advanced Search
Source: https://docs.snapsec.co/products/vm/search
Search across all vulnerabilities, assets, endpoints, and reports — instantly and intelligently.
## Overview
**Global Search** provides a unified way to search across your entire vulnerability management ecosystem —\
whether vulnerabilities come from **different scanners, assessments, or manual pentests**.
You can instantly locate vulnerabilities, assets, endpoints, CWE identifiers, or even specific text within reports.\
Global Search ensures you never lose visibility of any issue, regardless of its origin or assessment.
***
## Key Capabilities
Find vulnerabilities across all assessments, sources, and integrations in one place.
Search within full vulnerability reports — including summaries, impact, and reproduction steps.
Query assets, endpoints, or hostnames to identify where specific issues exist.
View highlighted matches for your keywords across multiple vulnerabilities.
***
## Using Global Search
Navigate to the **Search** tab under Vulnerability Management.
Type any keyword — such as a vulnerability title (*XSS*), asset name (*app.example.com*),\
endpoint path (*api/v1/user*), or specific CVE/CWE identifier.
Instantly view results grouped by report, assessment, or source.\
Each entry expands to show summaries, steps to reproduce, and report context.
Click a result to open its full vulnerability report in context, enabling deeper investigation or follow-up.
***
## Searchable Data Types
| Type | Example Query | Description |
| ------------------- | -------------------------- | ------------------------------------------------------------ |
| Vulnerability Title | `API with No Versioning` | Finds matching vulnerabilities across all reports. |
| Endpoint | `/api/v1/payment` | Returns vulnerabilities linked to that endpoint. |
| Asset | `staging.example.com` | Shows all findings associated with that asset. |
| Keyword in Report | `JWT`, `encryption` | Searches deep within summaries, impacts, or mitigation text. |
| CWE or CVE ID | `CWE-79`, `CVE-2024-23950` | Locates findings associated with specific identifiers. |
***
## Benefits
* **Faster triage:** Quickly locate and compare similar vulnerabilities across different systems.
* **Cross-source visibility:** Combines results from integrated scanners, assessments, and bug bounty imports.
* **Audit ready:** Retrieve historical findings and related metadata for compliance or reporting.
* **Team-wide clarity:** Ideal for security analysts, developers, and auditors reviewing large data sets.
***
## Explore Live Demo
Jump straight into the live environment and see how Snapsec unifies asset intelligence, threat detection, and vulnerability tracking — all in one dashboard.
# Service Vendors
Source: https://docs.snapsec.co/products/vm/service-vendors
Manage vendor identities and customize branded vulnerability reports.
## Overview
Service Vendors allow you to define **who delivers the security assessment**.
They are used to:
* Brand vulnerability reports
* Manage vendor identities
* Associate assessments with specific teams or partners
***
## Vendor Management
The Service Vendors table provides:
* Vendor name and identity
* Contact details
* Address information
* Number of linked assessments
* Creation date
### Key Actions
* Add new vendor
* Search and filter vendors
* Manage vendor records
***
## Adding a Service Vendor
Use **Add Service Vendor** to register a new vendor identity.
### Required Fields
* **Service Vendor Name**
* **Email**
### Optional Fields
* Phone number
* Address
* Logo URL
* Description / Notes
***
## Vendor Details
Each vendor profile includes:
* **Logo**
Used for report branding
* **Contact Information**
For communication and ownership
* **Description**
Context about vendor services or scope
***
## How It’s Used
Service Vendors integrate directly into the Vulnerability Management workflow.
### Key Use Cases
* Assign vendors to assessments
* Generate **branded vulnerability reports**
* Separate internal vs external security teams
* Manage multiple clients or business units
***
## Why It Matters
This isn’t just a directory — it’s a **reporting and ownership layer**.
### Key Benefits
* Professional, branded reports for clients
* Clear ownership of security findings
* Multi-vendor / multi-team support
* Better tracking of assessment responsibility
* Strong value for consulting and MSSP models
***
## Explore Live Demo
Create vendors and generate branded vulnerability reports instantly.
# SLA Analytics
Source: https://docs.snapsec.co/products/vm/sla-analytics
Track, enforce, and optimize vulnerability remediation timelines with real-time SLA visibility, violations tracking, and automated reporting.
## Overview
**SLA Analytics** provides a real-time view of how effectively your organization is resolving vulnerabilities within defined timelines.
It transforms SLA tracking from a passive metric into an **active operational system** — helping teams identify breaches, enforce accountability, and continuously improve remediation performance.
You can monitor:
* SLA compliance across all vulnerabilities
* Breached and at-risk issues
* Team and owner performance
* Severity-based remediation trends
Every vulnerability is continuously tracked against SLA deadlines — ensuring zero blind spots in remediation timelines.
***
## SLA Dashboard
The **Dashboard** gives a high-level snapshot of SLA performance across your organization.
### Key Metrics
* **Total Tickets** — All tracked vulnerabilities
* **Total Breached** — Issues that exceeded SLA timelines
* **Total Compliant** — Resolved within SLA
* **Unassigned** — Vulnerabilities without ownership
* **At Risk** — Close to breaching SLA
***
### Visual Insights
* **SLA Compliance Overview**
* % of compliant vs breached vulnerabilities
* **Violations by Severity**
* Identify which severity levels are failing SLAs
* **Violations by Department**
* Understand which teams are lagging
* **Business Unit Breakdown**
* Track SLA performance across organizational units
The dashboard refreshes automatically, ensuring decisions are always based on current data.
***
## SLA Violations
The **Violations** view is your **execution layer** — where teams actively track and resolve SLA breaches.
### What You See
* Vulnerability title and source
* Severity and current state
* Assigned owner
* Time overdue (in days)
***
### Powerful Controls
* **Advanced Filters**
* Filter by severity, violation type, state, owner, team, department, and more
* **Column Customization**
* Toggle visible columns for tailored workflows
* **CSV Export**
* Download filtered data for reporting or audits
Focus instantly on critical SLA breaches using filters — no need to scan large datasets manually.
***
## SLA Leaderboard
The **Leaderboard** provides visibility into **ownership and accountability**.
### Metrics Tracked
* **Total Vulnerabilities**
* **Breached**
* **At Risk**
* **Compliant**
* **Compliance %**
This allows organizations to:
* Identify high-performing teams
* Detect bottlenecks in remediation
* Drive accountability across owners
Turn SLA compliance into a measurable performance metric across teams.
***
## SLA Configuration
Define how SLA timelines are calculated across your organization.
### Configuration Options
* **Severity-Based Timelines**
* Set resolution deadlines for Critical, High, Medium, and Low
* **Weekend Inclusion**
* Include or exclude specific days in SLA calculations
* **Holiday Exceptions**
* Import iCal calendars to exclude non-working days
Once configured, SLA tracking is automatically applied to all vulnerabilities.
***
## Weekly Reports
Automate SLA reporting for stakeholders with scheduled summaries.
### Features
* **Recipient Management**
* Add multiple stakeholders
* **Flexible Scheduling**
* Weekly frequency, day, and time selection
* **Manual Trigger**
* Use **Send Now** for instant reporting
***
### What Reports Include
* SLA compliance percentage
* Breached and at-risk vulnerabilities
* Severity breakdown
* Overall remediation performance
Keep leadership aligned with automated, consistent SLA reporting — no manual effort required.
***
## Exporting Reports
You can export SLA insights at any time for audits or executive reporting.
Navigate to the SLA Dashboard section.
Use the **Export Report** button to download structured data.
Use exported data for compliance audits, leadership updates, or internal tracking.
Exported reports include organization-wide SLA metrics, breakdowns, and performance indicators.
***
## Why SLA Analytics Matters
SLA Analytics helps organizations:
* Prevent SLA breaches before they happen
* Improve remediation speed and efficiency
* Align security and engineering teams
* Provide audit-ready compliance visibility
* Eliminate manual tracking and reporting
It turns vulnerability management into a **measurable, enforceable process**.
***
## Explore Live Demo
Experience real-time SLA tracking, violation management, and automated reporting — all in one unified platform.
# Vulnerabilities
Source: https://docs.snapsec.co/products/vm/vulnerabilities
View, manage, and remediate all vulnerabilities across assessments from a unified interface.
## Overview
The **Vulnerabilities** section provides a unified view of all identified security issues across assessments, assets, and teams.
It allows you to track, prioritize, and manage vulnerabilities from discovery to resolution — all in one place.
Every vulnerability is tracked with full context — including severity, ownership, activity, and evidence — ensuring complete visibility across the remediation lifecycle.
***
## What You Can Do
* **View All Vulnerabilities**
* Access a centralized list across all assessments
* **Track Status**
* Monitor states like *In Review, Re-test, Fixed in Staging, Resolved*
* **Assign Ownership**
* Clearly see who is responsible for remediation
* **Prioritize Fixes**
* Focus on critical issues using severity and SLA indicators
***
## Filtering and Search
Use filters to quickly find relevant vulnerabilities:
* **Severity**
* **Assessments**
* **Owners**
* **State**
* **Business Unit / Departments**
* **SLA Status**
Combine filters to narrow results — for example, *High severity vulnerabilities in Re-test assigned to Backend Team*.
***
## Vulnerability States
Each vulnerability moves through defined states:
* **In Review**
* **Triaged**
* **Re-test**
* **Fixed in Staging**
* **Resolved**
* **Risk Accepted**
* **False Positive / Not Applicable**
State changes are reflected instantly across dashboards and reports.
***
## Creating a Vulnerability
* Click **Create Vulnerability**
* Add details like title, severity, and affected asset
* Link it to an assessment
Manual creation is useful for adding findings from external tools or internal reviews.
***
## Vulnerability Details
Clicking a vulnerability opens a **single unified view** containing all information needed for remediation.
***
### Description & Reproduction
This section includes:
* **Title & Description**
* **Steps to Reproduce**
* **Impact**
* **Remediation Guidance**
It serves as the **primary reference** for developers fixing the issue.
***
### Activity & Collaboration
* Add comments and tag team members
* Track all updates and system changes
* Create blockers if remediation is blocked
All communication stays tied to the vulnerability — ensuring full traceability.
***
### Report Details Panel
Key information includes:
* **Severity & CVSS**
* **Owner & Collaborators**
* **Current State**
* **Assessment Source**
* **Affected Asset**
* **CWE Classification**
* **SLA Status**
* **Reported Date**
Use this panel to quickly assess risk and decide remediation priority.
***
### Attachments & Revalidation
Within the same view:
* Upload screenshots, logs, and PoCs
* Track revalidation details
* Maintain proof for audits
Evidence ensures vulnerabilities are verifiable, reproducible, and audit-ready.
***
## Why It Matters
The Vulnerabilities section centralizes everything required to manage security issues effectively.
It ensures:
* Clear understanding of each issue
* Structured collaboration between teams
* Complete audit trail with activity and evidence
* End-to-end tracking from discovery to resolution
***
## Explore Live Demo
Experience how Snapsec helps teams track and remediate vulnerabilities in a unified workflow.
# Vulnerability Groups
Source: https://docs.snapsec.co/products/vm/vulnerability-groups
Organize and manage related vulnerabilities across assets and assessments in unified, customizable groups.
## Overview
**Vulnerability Groups** enable you to organize vulnerabilities from multiple assets, assessments, and sources into logical collections — such as all *Access Control* issues or *API-related* vulnerabilities.\
This helps teams prioritize fixes, track themes, and export consolidated reports with ease.
Groups can be defined by vulnerability types, impacted components, responsible teams, or business context. They act as dynamic workspaces to simplify remediation management across large vulnerability datasets.
***
## Use Cases
* Group all *Access Control* or *Authentication* issues across multiple systems.
* Maintain separate vulnerability lists per *team* or *department*.
* Create category-based views (e.g., *API Vulnerabilities*, *Web XSS Issues*, *Encryption Weaknesses*).
* Generate consolidated reports for specific vulnerability families.
***
## Creating or Updating a Group
Navigate to **Vulnerability Management → Vulnerabilities → Groups**.
Provide a **name** (e.g., “XSS” or “API Vulnerabilities”) and an optional **description** to help categorize the group.
Once saved, your new group will appear in the list, ready to be populated with vulnerabilities.
To rename or edit a group’s description, click the **three-dot menu (⋯)** on the card and select **Edit**.
***
## Viewing Vulnerabilities in a Group
Click on the **group name** or the **‘View’** link beside the vulnerability count.
View all vulnerabilities added to that group, along with their severity, state, and associated assessments.
Click any vulnerability title to open its detailed view and remediation information.
***
## Adding or Removing Vulnerabilities
Open the group’s **Manage** option from the menu.
Search across all vulnerabilities and select the ones you wish to add to the group.
To remove, deselect items or use the **Remove** button in the group management view.
Groups can be configured to automatically include vulnerabilities matching filters like CWE, severity, or keywords.
You can group vulnerabilities from **different assessments and sources** — ideal for tracking recurring issues across your environment.
***
## Exporting Group Data
You can export grouped vulnerabilities either as a **CSV file** for analysis or as a **PDF report** for sharing and documentation.
### Export CSV
Click the three-dot (⋯) menu beside your chosen group.
A CSV file will be generated containing all vulnerabilities, including metadata such as title, severity, CVSS, asset, and owner.
### Export PDF Report
Generate a detailed **Consolidated Vulnerability Report** with full details, affected assets, CVSS scores, and remediation steps.
The report will automatically compile and download, formatted for executive or audit-ready reviews.
***
## CWE-Based Grouping
Vulnerability Groups support organizing findings using **CWE (Common Weakness Enumeration)** classifications.\
This allows teams to group vulnerabilities based on **root cause patterns**, not just individual findings.
### How CWE Grouping Helps
CWE-based grouping enables teams to:
* Track recurring **weakness classes** (e.g., CWE-79, CWE-89, CWE-287) across applications
* Identify **systemic security flaws** instead of isolated bugs
* Prioritize remediation based on **root causes**, not just severity
* Align remediation efforts with **secure coding standards** and training programs
***
### Creating a CWE-Based Group
Open **Vulnerability Groups** and create a new group or edit an existing one.
Choose one or more **CWE IDs** (e.g., CWE-79: Cross-Site Scripting, CWE-287: Improper Authentication).
All vulnerabilities mapped to the selected CWE identifiers are automatically included in the group.
CWE-based groups dynamically update as new vulnerabilities are discovered or reclassified.
***
### Example CWE Use Cases
* **CWE-79 (XSS):** Track all cross-site scripting issues across web applications
* **CWE-89 (SQL Injection):** Monitor database-related injection risks
* **CWE-287 (Authentication):** Review identity and access control weaknesses
* **CWE-22 (Path Traversal):** Identify file system exposure risks
These groups help teams address **patterns of weakness**, not just individual vulnerabilities.
***
### Reporting with CWE Context
When exporting a Vulnerability Group:
* **CSV exports** include CWE IDs for each vulnerability
* **PDF reports** summarize findings by CWE category, severity, and affected assets
This makes CWE-based groups ideal for:
* Secure coding reviews
* Engineering retrospectives
* Compliance and audit reporting
* Long-term risk reduction initiatives
***
## Best Practices
* Create functional groups (e.g., *API Issues*, *Auth Flaws*) to align with engineering teams.
* Use CSV exports for bulk remediation tracking in external tools.
* Use PDF exports for client reporting or audit documentation.
* Review and refresh groups regularly to ensure updated vulnerability context.
***
## Explore Live Demo
Jump straight into the live environment and see how Snapsec unifies asset intelligence, threat detection, and vulnerability tracking — all in one dashboard.
# Assets
Source: https://docs.snapsec.co/products/vs/assets
View, manage, and scan assets to identify vulnerabilities across your attack surface.
## Overview
The Assets page provides a centralized view of all discovered assets within your environment.
It allows you to monitor vulnerability exposure, organize assets into groups, and trigger scans directly.
***
## Assets List
This table displays all assets along with their security posture.
### Key Metrics
* **Total Assets** — Total number of tracked assets
* **Vulnerable Assets** — Assets with at least one vulnerability
* **Safe Assets** — Assets with no vulnerabilities
* **Scan Coverage** — Percentage of assets scanned
### Key Features
* **Search & Filters** — Filter by group, type, vulnerability presence, or severity
* **Groups Column** — Organize assets by environment or function
* **Vulnerabilities** — Displays severity counts (C, H, M, etc.)
* **Last Scanned** — Shows scan recency
***
## Assign Assets to Groups
You can organize assets into logical groups such as:
* Development
* External Assets
* Internal Infrastructure
Click the **+ icon** next to a group to assign or update grouping.
***
## Add to Group
Choose from existing groups to categorize assets.
Grouping helps with:
* Ownership mapping
* Targeted scanning
* Better reporting
***
## Run Scan on Asset
Each asset includes quick actions:
* **Run Scan** — Start an immediate scan
* Access via the **actions menu (⋯)**
This enables on-demand security testing.
***
## Scan Confirmation
Before starting a scan:
* A confirmation dialog ensures intentional execution
* Prevents accidental scans on production systems
***
## Asset-Level Vulnerability View
Drill down into an asset to:
* View associated vulnerabilities
* Analyze severity and status
* Track remediation progress
***
## Use Cases
* Monitor **asset-level risk exposure**
* Organize assets by **environment or ownership**
* Run **targeted scans on critical assets**
* Track **scan coverage and gaps**
***
## Why This Matters
* Provides complete asset visibility
* Enables targeted vulnerability management
* Improves ownership and accountability
* Supports continuous security monitoring
***
## Explore Live Demo
See how Snapsec VS helps you track, group, and scan assets to uncover vulnerabilities in real-time.
# Dasboard
Source: https://docs.snapsec.co/products/vs/dashboard
View, analyze, and manage detected vulnerabilities across all assets with full context and remediation workflows.
## Overview
The Dashboard page provides a centralized view of all detected security issues across your assets.
It enables teams to investigate findings, track remediation status, and take action on critical risks efficiently.
***
## Dashboard List
This table displays the most critical vulnerabilities across your environment.
### Key Columns
* **Title** — Vulnerability name and endpoint
* **Asset** — Affected system or domain
* **Scanner** — Detection source
* **Severity** — Critical, High, Medium, Low
* **State** — Open, Resolved, In Review, False Positive
* **Found On** — Detection timestamp
This enables quick prioritization of high-risk issues.
***
## Time-Based Analysis
Use the time filter to analyze vulnerability patterns over time.
### Capabilities
* **Flexible Time Ranges** — 1, 3, 6, or 12 months
* **Trend Monitoring** — Identify spikes and recurring issues
* **Post-Remediation Tracking** — Validate fixes over time
This helps teams measure security improvements and detect anomalies.
***
## Vulnerability Details
Clicking a vulnerability opens a detailed investigation panel.
### Host Information
* **Host / Domain**
* **IP Address**
* **Matched Endpoint**
* **Detection Timestamp**
* **Matcher Name**
### Scanner Information
* **Scanner Name**
* **Scanner IP**
* **Heartbeat Status**
### Additional Context
* **Tags** — Classification labels
* **Timeline** — Detection history
* **Reproduction Command** — Example request (curl)
***
## Actions
Each vulnerability supports direct actions:
* **Send to VM** — Forward to Vulnerability Management
* **Suppress** — Mark as false positive or ignore
This ensures findings are actionable and manageable.
***
## Investigation Workflow
A typical workflow includes:
1. Identify critical vulnerabilities
2. Analyze trends and patterns
3. Investigate detailed findings
4. Take action (fix, suppress, escalate)
5. Track resolution over time
***
## Why This Matters
* Centralizes vulnerability visibility
* Enables faster triage and response
* Provides deep investigation context
* Supports trend-based decision making
* Improves remediation efficiency
***
## Explore Live Demo
See how Snapsec VS helps you detect, analyze, and act on vulnerabilities across your infrastructure in real-time.
# Groups
Source: https://docs.snapsec.co/products/vs/groups
Organize assets into logical groups for better visibility, ownership, and targeted vulnerability management.
## Overview
Groups allow you to organize assets into meaningful categories such as environments, infrastructure types, or ownership domains.
This enables better visibility, targeted scanning, and more efficient vulnerability management.
***
## Groups Overview
Each group provides a summarized view of its assets and associated vulnerabilities.
### Key Elements
* **Group Name & Description** — Defines the purpose of the group
* **Assets Count** — Number of assets within the group
* **Vulnerability Summary** — Breakdown by severity (Critical, High, Medium, Low)
* **Quick Insights** — Instantly identify high-risk groups
***
## Create a Group
To create a new group:
1. Click **Add Group**
2. Enter group details
3. Save the configuration
***
## Group Creation Modal
### Required Fields
* **Name** — Unique group identifier
* **Description** — Purpose or context of the group
Groups should reflect:
* Environment (Prod, Staging, Dev)
* Exposure (External, Internal)
* Ownership (Team-based grouping)
***
## View Group Assets
Click on a group to:
* View all assets within that group
* Analyze vulnerabilities specific to that segment
* Track scan status and coverage
***
## Use Cases
* Segment assets by **environment or exposure**
* Assign ownership for **accountability**
* Perform **targeted vulnerability analysis**
* Prioritize remediation by **group risk level**
***
## Why This Matters
* Improves asset organization and clarity
* Enables focused security operations
* Helps prioritize high-risk environments
* Supports scalable vulnerability management
***
## Explore Live Demo
See how Snapsec VS helps you organize assets into groups for better visibility and control.
# Scans
Source: https://docs.snapsec.co/products/vs/scan
Create, schedule, and monitor vulnerability scans across your assets and groups.
## Overview
Scans are the core execution engine of the Vulnerability Scanner.\
They allow you to continuously assess your assets, detect vulnerabilities, and track security posture over time.
***
## Scan List
The scan list provides a centralized view of all scan activities.
### Key Information
* **Asset Group** — Target of the scan
* **Status** — Success, Failed, In Progress
* **Triggered By** — Manual, Scheduled, or Policy-driven
* **Assets Covered** — Number of assets scanned
* **Vulnerabilities Found** — Total findings
* **Frequency** — Daily, Weekly, Monthly, Immediate
***
## Create a Scan
To initiate a scan:
1. Click **Create Scan**
2. Choose scan type
3. Select scope (group or asset)
4. Configure schedule
5. Launch scan
***
## Scan Configuration
### Scan Types
* **Full Scan** — Comprehensive security assessment
* **Quick Scan** — Faster scan focusing on high-impact vulnerabilities
### Scan Scope
* **Scan by Group** — Target all assets within a group
* **Scan by Asset** — Scan individual assets
### Scheduling Options
* **Run Immediately** — Execute scan instantly
* **Scheduled Scan** — Run at a specific time
* **Recurring Scan** — Automate periodic scans
***
## Scan Details Dashboard
Each scan provides a detailed overview:
* **Severity Breakdown** — Critical, High, Medium, Low
* **Progress Tracking** — Closed vs identified vulnerabilities
* **Trend Analysis** — Vulnerability trends over time
* **Asset Risk Overview** — Vulnerable vs safe assets
***
## Top Vulnerabilities
Quickly identify:
* Most critical vulnerabilities
* Current remediation status
* Affected assets
* Time since detection
***
## Use Cases
* Continuous security monitoring
* Scheduled compliance scans
* Rapid assessment after deployments
* Targeted scans for high-risk groups
***
## Why This Matters
* Enables proactive vulnerability detection
* Reduces attack surface continuously
* Automates security operations
* Provides actionable security insights
***
## Explore Live Demo
Experience how Snapsec VS scans your assets and uncovers vulnerabilities in real time.
# Scanners
Source: https://docs.snapsec.co/products/vs/scanners
Deploy, manage, and monitor scanning engines used to perform vulnerability assessments.
## Overview
Scanners are the execution engines responsible for performing vulnerability scans across your infrastructure.
They allow you to scale scanning operations, distribute workloads, and ensure reliable coverage across internal and external environments.
***
## Scanner List
This page provides a real-time view of all available scanners.
### Key Details
* **Scanner Name** — Identifier for the scanner
* **Status** — Active or Offline
* **Endpoint** — Scanner URL or host
* **Last Seen** — Last heartbeat timestamp
* **Vulnerability Summary** — Findings detected by the scanner
***
## Scanner Actions
### Available Actions
* **Download Scanner**\
Deploy a scanner within your infrastructure
* **Create Scanner**\
Register a new scanner instance
These actions allow you to horizontally scale scanning capacity.
***
## Create Scanner
To register a scanner:
1. Provide a **Scanner Name**
2. Enter the **Scanner URL / Endpoint**
3. Ensure the scanner is reachable
4. Click **Create Scanner**
***
## Scanner Status
* **Active** — Scanner is online and operational
* **Offline / Dead** — Scanner is unreachable or not responding
Monitoring scanner health ensures reliable scan execution.
***
## Use Cases
* Deploy scanners inside private networks
* Scan internal infrastructure securely
* Distribute scans across multiple regions
* Improve performance with parallel scanning
***
## Why This Matters
* Enables **scalable vulnerability scanning**
* Supports **internal + external asset coverage**
* Reduces scan latency through distributed architecture
* Ensures **high availability of scanning operations**
***
## Explore Live Demo
Experience how Snapsec scales vulnerability scanning using distributed scanner nodes.
# Settings
Source: https://docs.snapsec.co/products/vs/settings
Configure integrations and vulnerability synchronization with your asset inventory.
## Overview
Settings allow you to integrate your Asset Inventory with the Vulnerability Scanner and control how vulnerabilities are synchronized, categorized, and stored.
This ensures alignment between scanning results and your broader security assessments.
***
## Asset Inventory Integration
The Asset Inventory Integration links discovered vulnerabilities with your asset management system.
### Key Benefits
* Centralized asset visibility
* Context-aware vulnerability tracking
* Unified security posture across products
Click **Install** to enable integration.
***
## Vulnerability Synchronization
### Automatic Synchronization
Enable automatic syncing of vulnerabilities into your assessment workflows.
### Assessment Mapping
Select where vulnerabilities should be stored:
* Risk assessments
* Security testing programs
* Compliance frameworks
Examples:
* Post-Remediation Validation
* Business Logic Testing
* Third-Party Risk Assessment
* Attack Surface Monitoring
***
## Severity-Based Sync
Control which vulnerabilities are pushed into assessments:
* **Critical** — Always prioritize
* **High** — Important risks
* **Medium** — Moderate impact
* **Low** — Minor issues
* **Info** — Informational findings
This allows teams to focus only on actionable risks.
***
## Use Cases
* Automatically map scan results to ongoing assessments
* Align vulnerability management with compliance workflows
* Reduce manual triaging effort
* Standardize risk tracking across teams
***
## Why This Matters
* Eliminates siloed security data
* Connects scanning with business context
* Enables automated risk workflows
* Improves prioritization and reporting
***
## Explore Live Demo
Experience how Snapsec connects vulnerabilities with your asset inventory and assessments in real time.
# Suppression Rules
Source: https://docs.snapsec.co/products/vs/suppression-rules
Create and manage rules to automatically suppress non-actionable vulnerabilities and reduce noise.
## Overview
Suppression Rules allow you to automatically ignore or suppress vulnerabilities based on defined conditions.
This helps reduce false positives, eliminate noise, and focus only on actionable security issues.
***
## Suppression Rules List
This screen provides a centralized view of all suppression rules.
### Key Features
* **Search** — Find rules quickly
* **Filters** — Filter by severity or origin
* **Status Toggle** — Enable or disable rules instantly
* **Columns Control** — Customize visible fields
### Key Columns
* **Rule Name** — Name and description of the rule
* **Origin** — System-generated or manually created
* **Applies To** — Number of affected vulnerabilities
* **Status** — Active (ON) or Disabled (OFF)
***
## Create Suppression Rule
Create rules to automatically suppress vulnerabilities based on conditions.
### Rule Configuration
* **Rule Name** — Unique identifier
* **Description** — Optional explanation
### Matching Conditions
Define when a vulnerability should be suppressed:
* Select a **field** (e.g., severity)
* Choose an **operator** (equals, contains, etc.)
* Set a **value** (e.g., high, medium)
You can combine multiple conditions to create precise suppression logic.
***
## Manage Rules
Each rule includes management actions:
* **Edit Rule** — Modify conditions or metadata
* **Delete Rule** — Remove rule permanently
* **Toggle Status** — Enable or disable rule instantly
This allows full control over suppression behavior.
***
## Use Cases
* Suppress **informational findings** that are not actionable
* Ignore vulnerabilities in **test or staging environments**
* Exclude **known accepted risks**
* Reduce noise from **repeated low-impact issues**
***
## Why This Matters
* Reduces alert fatigue
* Eliminates false positives
* Improves signal-to-noise ratio
* Enables focused remediation
* Supports scalable security operations
***
## Explore Live Demo
See how Snapsec VS helps you automate noise reduction and focus only on real security risks.
# Vulnerabilities
Source: https://docs.snapsec.co/products/vs/vulnerabilities
View, analyze, and manage detected vulnerabilities across all assets with full context and remediation workflows.
## Overview
The Vulnerabilities page provides a centralized view of all detected security issues across your assets.
It enables teams to investigate findings, prioritize risks, and take action efficiently.
***
## Vulnerabilities List
This table displays all discovered vulnerabilities across your environment.
### Key Features
* **Search** — Quickly find vulnerabilities
* **Filters** — Filter by severity, scanner, state, assets, or suppressed status
* **Columns Control** — Customize visible fields
* **Severity Breakdown** — Instant counts (Critical, High, Medium, Low, Info, Suppressed)
### Key Columns
* **Title** — Vulnerability name and endpoint
* **State** — Open, In Review, Resolved, False Positive
* **Scanner** — Detection source
* **Severity** — Risk level
* **Reported On** — Detection timestamp
* **VM Ticket** — Integration with vulnerability management
***
## Actions & Workflow
Each vulnerability provides quick actions through the actions menu.
### Available Actions
* **Send to VM** — Forward vulnerability for tracking and remediation
* **Suppress** — Mark as false positive or ignore
These actions help reduce noise and streamline remediation workflows.
***
## Vulnerability Details
Clicking a vulnerability opens a detailed investigation panel.
### Host Information
* **Host / Domain**
* **IP Address**
* **Matched Endpoint**
* **Matcher Name**
* **Scan Found On**
### Scanner Information
* **Scanner Name**
* **Scanner IP**
* **Heartbeat Status**
### Additional Context
* **Tags** — Classification labels
* **Timeline** — Detection history
* **Reproduction Command** — Example curl request
### Actions
* **Send to VM**
* **Suppress**
***
## Investigation Workflow
1. Identify critical vulnerabilities
2. Filter and prioritize findings
3. Review detailed context
4. Take action (send to VM or suppress)
5. Track remediation progress
***
## Why This Matters
* Centralizes vulnerability management
* Enables faster triage and prioritization
* Reduces false positives through suppression
* Provides deep technical context for investigation
* Improves remediation efficiency and tracking
***
## Explore Live Demo
See how Snapsec VS helps you detect, analyze, and act on vulnerabilities across your infrastructure in real-time.
# Applications
Source: https://docs.snapsec.co/products/was/applications
Manage web applications, configure scans, and monitor vulnerabilities across your attack surface.
## Overview
The Applications module is the control center for managing web applications within the Web Application Scanner (WAS).
It enables teams to onboard applications, configure scans, monitor vulnerabilities, and track security posture over time.
***
## Applications List
### Key Features
* Centralized list of all applications
* Scan status visibility (Completed, Not Scanned)
* Last scan tracking
* Quick access to application-level insights
***
## Create Application
### Configuration
* **Name** — Application identifier
* **Description** — Context about the application
This allows teams to organize and manage multiple environments (prod, staging, test).
***
## Application Dashboard
### Capabilities
* Start instant scans
* Track remediation progress
* Download scan reports
* Delete or manage applications
***
## Metrics
### Insights
* Total vulnerabilities identified
* Resolution progress tracking
* Visual security posture overview
***
## Requests & URLs (Attack Surface Visibility)
### What You Get
* Complete endpoint inventory
* HTTP method visibility (GET, POST, etc.)
* Host-level mapping
* Vulnerability mapping per endpoint
This is where WAS becomes powerful—**you’re not just scanning, you’re mapping the attack surface.**
***
## Vulnerabilities
### Features
* Severity-based prioritization (Critical → Info)
* Status tracking (In Review, Resolved, False Positive)
* Detection timeline
* Integration with VM workflows
***
## Scan History
### Includes
* Scan status
* Total requests executed
* Rules applied
* Vulnerabilities discovered per scan
* Timeline tracking
***
## Scanner Configuration
### Scan Types
* **Aggressive Scan** — Deep, comprehensive testing
* **Quick Scan** — Fast vulnerability checks
### Configuration Options
* Target URL
* In-scope URLs
* Exclusion patterns
* Authentication script support
* Scan profile selection
This enables precise and controlled scanning of complex applications.
***
## Scan Scheduling & Synchronization
### Scheduling Options
* One-time
* Hourly
* Daily
* Weekly
* Monthly
### Automation
* Auto-sync findings to assessments
* Link vulnerabilities to workflows
***
## Scan Rules
### Capabilities
* Enable/disable security rules
* View severity mapping (Critical, High, Medium)
* Track findings per rule
* Fine-tune scan behavior
***
## Why This Matters
* Provides complete control over application security testing
* Maps real attack surface instead of blind scanning
* Enables precise vulnerability detection with reduced noise
* Integrates scanning, prioritization, and remediation in one place
***
## Explore Live Demo
Discover how Snapsec WAS helps you identify and fix vulnerabilities across your applications in real time.
# Dashboard
Source: https://docs.snapsec.co/products/was/dashboard
Get a real-time overview of web application vulnerabilities, risk distribution, and security posture.
## Overview
The Web Application Scanner (WAS) Dashboard provides a centralized view of your application security posture.
It highlights vulnerability trends, severity distribution, and critical risks across all scanned applications.
***
## Security Overview
### Key Metrics
* **Total Vulnerabilities** — Overall findings across applications
* **Total Applications** — Applications under monitoring
* **Critical Vulnerabilities** — High-risk issues requiring immediate action
* **Applications with Active Scans** — Currently monitored apps
***
## Vulnerability Insights
### Distribution Views
* **Severity Distribution**\
Breakdown of vulnerabilities by Critical, High, Medium, Low, and Info
* **Vulnerabilities by Application**\
Identify which applications carry the highest risk
* **CWE Distribution**\
Understand vulnerability types based on CWE classification
***
## Top Vulnerabilities
The dashboard highlights the most critical vulnerabilities detected across applications.
### Key Details
* **Title** — Vulnerability type and endpoint
* **Status** — In Review, Open, Resolved
* **Severity** — Risk level
* **Application Name** — Affected application
* **Reported On** — Detection timeline
This helps teams prioritize remediation effectively.
***
## Use Cases
* Monitor application security posture in real time
* Identify high-risk applications instantly
* Track vulnerability trends over time
* Prioritize critical vulnerabilities for remediation
***
## Why This Matters
* Provides complete visibility into application-layer risks
* Enables faster detection of exploitable vulnerabilities
* Helps prioritize fixes based on severity and impact
* Strengthens overall application security posture
***
## Explore Live Demo
Experience how Snapsec WAS identifies vulnerabilities across your web applications in real time.
# Detection Rules
Source: https://docs.snapsec.co/products/was/detection-rules
Define, customize, and manage vulnerability detection logic using rule-based scanning.
## Overview
Detection Rules are the core of how vulnerabilities are identified.
They simulate attacker behavior by modifying requests and analyzing responses to detect security flaws.
***
## Rule Categories
Rules are grouped into categories for better organization:
* CRLF
* Authentication & Authorization
* Command Injection
* CORS
* Database Injection
* Error Handling & Logs
* File Inclusion
* Open Redirect
* Security Headers
* Sensitive Data Exposure
* SSRF
* XSS
* XXE
***
## Creating a Rule
Use **Create Rule** to define custom detection logic.
Each rule allows you to simulate real attack scenarios and detect application weaknesses.
***
## YAML-Based Rule Engine
Rules are written in YAML and consist of:
### Core Sections
* **Transform**
* Modify headers, query params, or body
* **Match Conditions**
* Status codes
* Response content
* **Report**
* Title
* Description
* Severity
* CWE
* CVSS
* Impact
* Mitigation
* Reproduction Steps
***
## Rule Execution Logic
Rules work by:
1. Modifying the original request
2. Sending the transformed request
3. Analyzing the response
4. Flagging unexpected behavior as vulnerabilities
***
## Rule Management
Each rule provides:
* Enable / Disable toggle
* Severity classification
* Detection description
* Number of findings
***
## Editing Rules
Rules can be modified anytime to:
* Improve detection accuracy
* Reduce false positives
* Adjust logic for application-specific behavior
***
## Deep Rule Customization
The editor allows full control over:
* Request transformations
* Matching conditions
* Reporting output
This enables detection of:
* Business logic flaws
* Authorization bypass
* Misconfigurations
* Edge-case vulnerabilities
***
## Why It Matters
Detection Rules turn your scanner into a customizable security engine.
### Key Benefits
* Adapt scanning to your application logic
* Detect beyond standard vulnerability signatures
* Reduce noise with precise matching
* Align findings with real-world attack patterns
* Enable security teams to build reusable detection logic
***
## Explore Live Demo
Create, test, and deploy custom detection logic tailored to your applications.
# Scan Profiles
Source: https://docs.snapsec.co/products/was/scan-profiles
Configure how your web application scans behave using customizable profiles.
## Overview
Scan Profiles define **how your scanner behaves during execution**.
They control request configuration, rate limits, and headers—allowing you to tailor scans for different environments like staging, production, or protected applications.
***
## Profile Configuration
### Profile Details
* **Profile Name**
Identify the purpose of the scan (e.g., *Rate Limit Profile*, *Cloudflare Bypass*)
***
## Custom Headers
Custom headers allow you to simulate real user or authenticated traffic.
### Common Use Cases
* Add `Authorization` tokens (JWT, API Keys)
* Include session cookies
* Bypass WAF/CDN protections
* Test authenticated endpoints
***
## Key Controls
### Override Host
Replace the target host during scan execution.
**Use Case:**
* Scan staging while routing through production domain
* Test internal services behind reverse proxies
***
### Rate Limiting
Control how aggressive your scan is.
* Define requests per second
* Prevent server overload
* Avoid triggering rate-limiting or blocking mechanisms
***
## Existing Profiles
Profiles can be reused across applications.
### Examples
* **Rate Limit Profile** → Controlled scanning for production
* **Host Override** → Custom routing for testing environments
* **Cloudflare Bypass** → Headers configured to bypass protections
Each profile supports:
* Edit configuration
* Delete when no longer needed
***
## Why It Matters
Scan Profiles give you control over **how your scanner interacts with real systems**.
### Key Benefits
* Safe scanning in production environments
* Authenticated testing for deeper coverage
* Reduced false positives from blocked requests
* Flexible configuration for different deployment setups
* Better alignment with real-world traffic behavior
***
## Explore Live Demo
Create scan profiles tailored for your infrastructure and security needs.
# URL Catalog
Source: https://docs.snapsec.co/products/was/url-catalog
Discover, monitor, and analyze all API endpoints and web routes across your applications.
## Overview
The URL Catalog provides a complete, continuously updated inventory of all discovered endpoints across your applications.
It enables security teams to understand the real attack surface, analyze request behavior, and map vulnerabilities directly to endpoints.
***
## API Requests Inventory
### Key Capabilities
* Full endpoint discovery across applications
* HTTP method visibility (GET, POST, etc.)
* Application-level mapping
* Vulnerability association per endpoint
* Advanced filtering (method, vulnerabilities, application)
***
## Endpoint-Level Intelligence
Each row represents a discovered endpoint enriched with security context:
* **URL** — Full endpoint path
* **Method** — Request type (GET, POST, etc.)
* **Application** — Associated application
* **Total Vulnerabilities** — Vulnerability count per endpoint
This allows teams to quickly identify high-risk endpoints instead of scanning blindly.
***
## Request Deep Dive
### What You Can Analyze
* Full HTTP request (headers, body, cookies)
* Authentication context
* Payload structure
* Origin and referrer details
* Client behavior (user-agent, headers)
This transforms WAS from just a scanner into a **request-level security analysis tool**.
***
## Why It Matters
Traditional scanners only show vulnerabilities.\
The URL Catalog shows **where and how they exist**.
### Real Value
* Maps the **true attack surface** (including hidden endpoints)
* Enables **targeted testing and validation**
* Helps prioritize vulnerabilities by endpoint exposure
* Provides context needed to reduce false positives
* Bridges the gap between **DAST and manual testing**
***
## Advanced Use Cases
### Attack Surface Mapping
Identify all exposed endpoints, including undocumented or shadow APIs.
### Vulnerability Correlation
Link vulnerabilities directly to the endpoints where they exist.
### API Security Testing
Analyze GraphQL, REST, and internal APIs in a unified view.
### Threat Investigation
Inspect raw requests to understand how vulnerabilities are triggered.
***
## Explore Live Demo
See how Snapsec URL Catalog gives you endpoint-level visibility and control over your application security.
# Vulnerabilities
Source: https://docs.snapsec.co/products/was/vulnerabilities
View, analyze, and manage all detected security issues across your applications.
## Overview
The Vulnerabilities section provides a centralized view of all security issues identified during scans.
It enables teams to understand risk, validate findings, and take action with clear remediation guidance.
***
## Vulnerability Summary
### What You See
* Total count of vulnerabilities by severity:
* Critical
* High
* Medium
* Low
* Info
This gives an immediate understanding of the overall risk posture of your application.
***
## Vulnerability List
The main table displays all detected vulnerabilities with key details:
* **Title** — Description of the issue
* **CWE** — Standard classification (Common Weakness Enumeration)
* **Severity** — Impact level of the vulnerability
* **Status** — Current state (e.g., In Review, Resolved)
* **Application** — Affected application
* **Detected On** — When the issue was identified
* **VM Ticket** — Option to send to vulnerability management
### Capabilities
* Search and filter vulnerabilities
* Filter by severity, status, application, and more
* Track remediation progress
* Send findings to VM workflow
***
## Vulnerability Details
Each vulnerability includes detailed context to help security and development teams act effectively.
### Included Information
* **Description**\
Explains what the vulnerability is and how it was identified
* **Impact**\
Describes the potential risk and consequences
* **Steps to Reproduce**\
Provides exact steps to validate the issue
* **Mitigation**\
Recommends how to fix or secure the issue
* **Tags**\
Adds contextual classification (e.g., auth, misconfiguration)
***
## Why It Matters
The Vulnerabilities section transforms scan results into actionable insights.
### Key Value
* Centralized visibility of all security issues
* Clear prioritization based on severity
* Reproducible findings for validation
* Actionable remediation guidance
* Integration with vulnerability management workflows
***
## Explore Live Demo
Explore how Snapsec helps you identify, prioritize, and fix vulnerabilities with complete context.
# Snapsec Suite Use Cases
Source: https://docs.snapsec.co/usecases/introduction
A categorized collection of real-world use cases across Snapsec’s security modules.
## Vulnerability Management
Use cases showcasing how Snapsec VM simplifies vulnerability operations and remediation workflows.
Transform ad-hoc pentesting into a continuous, centralized, and trackable security workflow.
Aggregate vulnerabilities from scanners, CI/CD, ASM, and manual tests into a single unified dashboard.
Enforce organization-wide SLAs, detect breaches, and streamline remediation accountability.
Automatically prioritize vulnerabilities using asset context, exposure, and business impact.
***
## Attack Surface Management
Use cases demonstrating how Snapsec ASM improves visibility and reduces external attack exposure.
Continuously identify every internet-facing domain, IP, API, and cloud endpoint linked to your organization.
Reveal unapproved and unmanaged assets deployed outside official security processes.
Track new ports, configuration changes, and emerging exposures in real time.
Analyze live, inactive, misconfigured, or risky assets across all environments.
***
## Asset Inventory Management
Use cases on how Snapsec AIM automates and enriches asset intelligence.
Build and maintain a live, enriched inventory of every asset across environments and teams.
Classify assets by environment, service type, ownership, and risk using policy-driven rules.
Map vulnerabilities and exposures to each asset for faster, context-aware triage.
Map each asset to responsible teams, departments, and service owners.
***
## Vulnerability Scanner (VS)
Use cases highlighting automated scanning and deep application analysis.
Automatically scan assets(APIs, Applications, Servers) for vulnerabilities on a recurring schedule.
Trigger manual or CI/CD-driven scans for immediate security validation.
Detect OWASP Top-10 vulnerabilities with comprehensive signature and behavior tests.
Re-scan assets post-fix to confirm and verify vulnerability resolution.
***
## Web Application Scanner (WAS)
Use cases showing how Snapsec strengthens API resilience.
Stress-test APIs continuously to uncover injection, validation, and parsing weaknesses.
Identify broken authentication and authorization issues across sensitive endpoints.
Detect insecure CORS, excessive exposure, debug endpoints, and configuration flaws.
Enrich endpoints with threat intelligence and identify high-risk API surfaces.