Exposure management

See where a vulnerability could lead.

Most scanners stop after they find a vulnerability. SecurityAlert shows which assets, accounts, applications, and controls are connected to it, why the path matters, and whether your fix worked.

Observed vs inferredEvery graph relationship says what kind of evidence supports it.
KEV and EPSS awareKnown exploitation and exploit probability travel with each CVE.
Safe collectionRead-only snapshots and SSRF-protected web inventory, with no attack execution.
RetestableValidation results and source fingerprints show whether the path is still open.
Exposure graph

See the connections around each finding

The Exposure graph links related technical findings so your team can investigate them together. Each path shows its source, status, supporting data, and next retest date.

Graph

See the full attack path

Connect assets, identities, repositories, cloud resources, vulnerabilities, and controls. You can open the source behind every item and connection.

Workflow

Handle each path separately

Investigate, accept, resolve, or dismiss one path without changing unrelated findings. If the underlying data changes, SecurityAlert reopens it for review.

Repositories

Review CI/CD settings

Check workflow triggers, runner trust, token permissions, unpinned actions, injection risks, sensitive artifacts, and embedded credential patterns.

Secrets

Scan for secrets without storing them

Scan working-tree files, repository history, container manifests, or build artifacts. SecurityAlert keeps only redacted matches and information about their source.

Cloud

Import cloud inventory without sharing credentials

Track cloud accounts and import least-privilege inventory snapshots. Your provider credentials never need to be stored in SecurityAlert.

Web and APIs

Map the public parts of web applications

Inventory routes, forms, scripts, OpenAPI, GraphQL, WebSocket, and source-map references with one protected HTTPS request. SecurityAlert does not submit forms or fuzz the application.

Scanners

Bring in findings from existing scanners

Import results from the scanners you already use. Source IDs are preserved so duplicate findings can be identified and traced back to the original tool.

Validation

Retest after a fix

Record how a finding was tested, what was tested, and when it should be checked again. A passing result marks the original path as broken.

Controls

Check your ATT&CK coverage

Map relevant ATT&CK techniques to preventive, detective, or response controls and attach test results from your team or another tool.

From the outside in

How SecurityAlert builds an attack path

SecurityAlert starts with your public assets and adds host CVEs, certificates, email-security grades, exposed credentials, passive DNS, and your outside-in security rating.

01

Inventory

List the monitored hosts, subdomains, certificates, application routes, repositories, and imported resources.

02

Add context

Add CVE, KEV, EPSS, ransomware use, reputation, WHOIS, DNS, and control information.

03

Connect

Show how the original condition could affect an asset, account, application, or business service.

04

Respond

Set the status, record your decision, and send the work to the channel your team already uses.

05

Verify

Retest safely and keep the result with the information that opened the path.

Clear scoring

Know what each risk score is based on

SecurityAlert labels direct observations, inferred connections, test results, fixed paths, and out-of-date information differently. It does not run attack tests or ask you to store cloud credentials in this workflow.

See when the data was collected

Collection and observation dates appear with each finding, so an old scanner result cannot be mistaken for a current one.

Make a decision about one path at a time

Accepting one condition does not clear the rest of the graph. Analysts can add notes and return to each path independently.

Keep the records behind each report

Run saved queries on demand or on a schedule. Each report keeps the records that matched, not just the total number.

Start with a domain you already monitor.

You can add repositories, cloud inventory, scanner results, and controls as you need them. SecurityAlert will show how they connect to the assets it has already found.