Umbra
Capability inventory · 66 features

Everything Umbra ships,
on one page.

66 shipped capabilities across attack-surface mapping, AI-verified exploitation, internal-network agents, search, reports, integrations, and access control. Click any card for the full doc: what it does, what it produces, why it matters, how to use it.

surface

Attack-surface mapping

Find every exposed service across IPs, CIDRs, hostnames, and internal networks, then keep watching as the surface drifts.

cloud

Cloud security posture

Read-only across AWS, Google Cloud & Azure: the exposure a port scan can't see, proven with an anonymous read, chained into attack paths, and shipped with the exact command that fixes each one.

vulnerability

Vulnerability intelligence

Surface the CVEs that matter, and prove which ones are real on this exact service, not on a generic version-string match.

ai

AI exploit engine

Anthropic Claude reasoning against real services: non-destructive, audit-logged, and cost-capped per run and per workspace.

deepaudit

Deep Audit · paid web app audit

Point at a URL, pay $100/scan (+ $75 per extra host), get an audit pipeline that goes well beyond pattern-matching DAST. JupiterSec finds what rules find; the AI Explorer finds the rest.

Deep Audit run

End-to-end paid audit: 56-module DAST scan, AI triage, AI exploration, merged report ($100/scan + $75 per extra host, AI hard-capped at ~$30/scan).

Active AI Triager

Triager probes ambiguous findings live against the target instead of pattern-matching to false-positive guards. Confirms what's real, rejects what's noise.

Tier 1 · endpoint hypothesis

Reads JupiterSec's recon model and proposes the endpoints + vuln classes most likely to harbour real bugs. Narrows the search before any probe fires.

Tier 2 · scenario playbooks

Ten scripted scenarios for the classes static rules can't reach: IDOR/BFLA, OAuth redirect bypass, JWT confusion, GraphQL abuse, mass assignment, price manipulation, role tampering, workflow bypass, multi-step ATO, cross-tenant UUID.

Tier 3 · open hunt

Opus-grade open exploration on the full recon bundle (clustered endpoints + JS-derived URLs + discovered params). Hunts for what the scripted scenarios missed.

Live scan timeline

Module-by-module progress: recon iterations, crawl complete, JS endpoint discovery, fuzzbox phases, every scanner module's start + complete, not a frozen progress bar.

Triager review queue

Findings the AI couldn't judge with high confidence land in a per-scan review queue with the original JupiterSec payload + error reason: review, accept, or replay.

Partial-coverage transparency

When a scan hits its time or AI budget mid-run, the report renders with a clear partial-coverage badge. You see what was covered and what wasn't, no silent drop-offs.

pentest

Internal pentest assessments

One click. A whole catalog of techniques fires against every live service the agent already discovered. Three safety tiers, one rollup view, every finding tagged by the technique that produced it.

agents

Internal Network Agent

A 5 MB Go binary that turns your internal network into a first-class part of the same dashboard (no inbound port, no VPN).

One-line install

Linux amd64 / arm64, macOS Apple Silicon, Windows amd64. Paste-once enrollment token, outbound HTTPS only.

Recurring internal scans + scan windows

Schedule internal CIDR scans on a cadence, optionally restricted to a maintenance window; auto re-probe when services flip to gone.

AI exploit network leg (HTTP)

The cloud AI routes every internal-target HTTP request through the agent. RFC1918 web apps + admin panels become first-class for exploit validation.

Binary-protocol testing via the agent

Same relay, raw bytes. AI talks Postgres, MySQL, Redis, MongoDB, SSH and friends through the agent: auth-method discovery + banner grabs on internal databases.

CIDR allowlist enforced at the agent

Pushed on every heartbeat; the agent refuses to probe outside its authorised scope, defence in depth above the cloud-side check.

Signed auto-update + rollback

sha256 + ed25519 verification before swap; auto-rollback if the new binary doesn't heartbeat within 5 minutes.

Captured task logs

Every task ships a timestamped log buffer back to the dashboard. Click 'Logs' on a task row to read it inline.

Health, uninstall, proxy, pinning

Loopback /healthz, --uninstall, HTTPS proxy support, --pinned-version override, JSON config file.

System service install (systemd / launchd / Windows SCM)

One-line --install registers the agent as a proper system service that persists across reboots and SSH disconnects. Linux + macOS + Windows; --disable / --enable / --status lifecycle commands included.

reports

Reports + workflow

From a one-page CVE proof to a board-ready risk report. Stateful findings, exec-shaped dashboards, multiple reports for multiple audiences. Same source of truth.

Findings dashboard

Every AI-verified finding across the surface, filterable by severity / kind / company / agent / internal-vs-external.

Findings lifecycle

Stateful findings (open → in_progress → fixed → verified), assignee, due date, history, bulk actions. The operating system for a remediation program.

Executive dashboard

"What to fix this week": KPI tiles (critical open, overdue, MTTR, fixed-this-week) + top-10 priority queue, above the findings list.

Executive report (board-ready)

Org-level PDF for the board: posture KPIs, opened-vs-closed trend chart, top remediations, top open risks. Print → Save as PDF.

Per-target full findings report

One page per target: every host, every service, every verified finding, ready to hand off.

Management report (per-run)

Non-technical executive summary of a single AI run: multilingual, print-ready, shareable.

Weekly email digest

One email a week with critical / high open, fixed-this-week, MTTR, top 5 open risks. Same data as the executive dashboard, delivered to the inbox.

Compliance evidence pack

Map Umbra's data to SOC 2, ISO 27001, NIS2, and GDPR Article 32 control IDs. Generate the artifact, hand it to your auditor, no spreadsheet reconciliation.

Shareable compliance pack

Mint a password-gated public link to a redacted compliance evidence pack. Hand it to your customer's security team instead of writing a questionnaire response.

Activity feed + What's new

Every state change in the org. Filter by time window, type, or scope. The audit trail for security ops.

integrations

Integrations

Push findings where your team already lives. Investigate from Slack without opening the dashboard. Two-way sync with the ticketing system you already use.

workspaces

Workspaces + access

Multi-tenant from day one. Role-scoped access, SSO, audit log of every privileged action.

That's the whole surface.

Free tier covers asset discovery + CVE matching against an unlimited number of targets. AI validation, internal-network agents, and Slack unlock on Starter and above.