Everything Umbra ships,
on one page.
66 shipped capabilities across attack-surface mapping, AI-verified exploitation, internal-network agents, search, reports, integrations, and access control. Click any card for the full doc: what it does, what it produces, why it matters, how to use it.
Attack-surface mapping
Find every exposed service across IPs, CIDRs, hostnames, and internal networks, then keep watching as the surface drifts.
RustScan-driven port scans on every target, rescheduled on an operator-tunable cadence with per-target scan windows.
Status, full headers, response body, page title, TLS cert chain, favicon hash, and a non-HTTP banner grab for every open port.
Curated rules + nuclei tech-detection assign product, version, vendor, category, and CPE to every probed service.
OS attribution per host, voted from every service-level fingerprint we've collected for it, no banner-spoof fragility.
Country, region, city, ASN, AS-org for every IP, free, powered by an offline DB-IP Lite + GeoLite2 dataset.
Visual topology of the whole surface: hosts, services, and their relationships on one pan/zoom canvas. A first-class nav module, not a static export.
Discover unlimited; pay for what you watch. Hot-swap tracked hosts in or out without re-scanning the world.
Group targets by acquisition, business unit, or product line. Filter findings by company; share reports per-tenant.
Paste 10,000 targets at once, attach per-target exclude lists (IPs / CIDRs) honoured by both RustScan and ignore rules.
Tag every target with owner, criticality, data classification, and vendor. Risk-ranking finally reflects what hurts the business, not raw CVSS.
Cloud security posture
Read-only across AWS, Google Cloud & Azure: the exposure a port scan can't see, proven with an anonymous read, chained into attack paths, and shipped with the exact command that fixes each one.
AWS, Google Cloud & Azure, read-only: world-readable data, privesc to admin, secrets in config, internet-open services. ~75 checks across 37 enumerators.
Internet-reachable workload → its identity → the specific data it can read. Public storage proven by an anonymous, credential-free read.
Every finding ships the exact aws / gcloud / az command that removes it, built from its real resource id, with a guardrail: read-only, never auto-applied.
Export any scan to a branded PDF: cover, posture summary, and every finding with its fix inline. Same template as the pentest reports.
Vulnerability intelligence
Surface the CVEs that matter, and prove which ones are real on this exact service, not on a generic version-string match.
Matched against the full NVD corpus, gated by the detected version so patched builds don't false-positive. CISA KEV + EPSS rank what to fix first; matches are tagged version-confirmed vs product-only, and you can mark a CVE not-affected to suppress it.
Click 'Verify' on any CVE. The AI agent runs the exploit chain end-to-end and writes a one-page PoC. Optional auto-verify runs it for you on new actively-exploited (KEV) findings.
AI exploit engine
Anthropic Claude reasoning against real services: non-destructive, audit-logged, and cost-capped per run and per workspace.
Autonomous tool-use loop: read PoCs, build hypothesis, run test requests, return one of three verdicts with a real proof.
Deterministic nuclei default-logins run on demand: no LLM cost, no surprises, runs the same checks every time.
Step-by-step run timeline with the exact requests/responses; share a public, password-gated link with the team that needs the fix.
Per-plan bundled monthly allowance, top-up balance, per-run cost estimate, hard ceilings before kicking off.
Named AI persona that ranks your top issues and answers 'why is this severity / what's the fix' from inside each finding drawer.
Deep Audit · paid web app audit
Point at a URL, pay $100/scan (+ $75 per extra host), get an audit pipeline that goes well beyond pattern-matching DAST. JupiterSec finds what rules find; the AI Explorer finds the rest.
End-to-end paid audit: 56-module DAST scan, AI triage, AI exploration, merged report ($100/scan + $75 per extra host, AI hard-capped at ~$30/scan).
Triager probes ambiguous findings live against the target instead of pattern-matching to false-positive guards. Confirms what's real, rejects what's noise.
Reads JupiterSec's recon model and proposes the endpoints + vuln classes most likely to harbour real bugs. Narrows the search before any probe fires.
Ten scripted scenarios for the classes static rules can't reach: IDOR/BFLA, OAuth redirect bypass, JWT confusion, GraphQL abuse, mass assignment, price manipulation, role tampering, workflow bypass, multi-step ATO, cross-tenant UUID.
Opus-grade open exploration on the full recon bundle (clustered endpoints + JS-derived URLs + discovered params). Hunts for what the scripted scenarios missed.
Module-by-module progress: recon iterations, crawl complete, JS endpoint discovery, fuzzbox phases, every scanner module's start + complete, not a frozen progress bar.
Findings the AI couldn't judge with high confidence land in a per-scan review queue with the original JupiterSec payload + error reason: review, accept, or replay.
When a scan hits its time or AI budget mid-run, the report renders with a clear partial-coverage badge. You see what was covered and what wasn't, no silent drop-offs.
Internal pentest assessments
One click. A whole catalog of techniques fires against every live service the agent already discovered. Three safety tiers, one rollup view, every finding tagged by the technique that produced it.
Run assessment → 84 techniques (54 native / $0) × N services × 3 safety tiers, fanned out as parallel AI runs with one rollup view. Catalog spans Active Directory, databases & datastores, remote access, cloud & federated identity, network & infrastructure devices, and web & CI/CD.
BloodHound-vocabulary principals + edges (MemberOf, AdminTo, GenericAll, WriteDACL, …) populated automatically by the ad_recon technique. No separate collector, no manual import.
Internal Network Agent
A 5 MB Go binary that turns your internal network into a first-class part of the same dashboard (no inbound port, no VPN).
Linux amd64 / arm64, macOS Apple Silicon, Windows amd64. Paste-once enrollment token, outbound HTTPS only.
Schedule internal CIDR scans on a cadence, optionally restricted to a maintenance window; auto re-probe when services flip to gone.
The cloud AI routes every internal-target HTTP request through the agent. RFC1918 web apps + admin panels become first-class for exploit validation.
Same relay, raw bytes. AI talks Postgres, MySQL, Redis, MongoDB, SSH and friends through the agent: auth-method discovery + banner grabs on internal databases.
Pushed on every heartbeat; the agent refuses to probe outside its authorised scope, defence in depth above the cloud-side check.
sha256 + ed25519 verification before swap; auto-rollback if the new binary doesn't heartbeat within 5 minutes.
Every task ships a timestamped log buffer back to the dashboard. Click 'Logs' on a task row to read it inline.
Loopback /healthz, --uninstall, HTTPS proxy support, --pinned-version override, JSON config file.
One-line --install registers the agent as a proper system service that persists across reboots and SSH disconnects. Linux + macOS + Windows; --disable / --enable / --status lifecycle commands included.
Search + investigation
Find anything in your surface in seconds: by token grammar, by free-text, or by typing it in English.
20+ tokens across services / hosts / findings / targets: product, port, cve_severity, internal, compromised, has_cve, and more.
Type 'critical CVEs on internal apache'. Claude Haiku translates to the tokenised query in <1s.
Every major view has a right-side drawer with full token documentation + click-to-run examples. Discoverable, not tucked away.
Reports + workflow
From a one-page CVE proof to a board-ready risk report. Stateful findings, exec-shaped dashboards, multiple reports for multiple audiences. Same source of truth.
Every AI-verified finding across the surface, filterable by severity / kind / company / agent / internal-vs-external.
Stateful findings (open → in_progress → fixed → verified), assignee, due date, history, bulk actions. The operating system for a remediation program.
"What to fix this week": KPI tiles (critical open, overdue, MTTR, fixed-this-week) + top-10 priority queue, above the findings list.
Org-level PDF for the board: posture KPIs, opened-vs-closed trend chart, top remediations, top open risks. Print → Save as PDF.
One page per target: every host, every service, every verified finding, ready to hand off.
Non-technical executive summary of a single AI run: multilingual, print-ready, shareable.
One email a week with critical / high open, fixed-this-week, MTTR, top 5 open risks. Same data as the executive dashboard, delivered to the inbox.
Map Umbra's data to SOC 2, ISO 27001, NIS2, and GDPR Article 32 control IDs. Generate the artifact, hand it to your auditor, no spreadsheet reconciliation.
Mint a password-gated public link to a redacted compliance evidence pack. Hand it to your customer's security team instead of writing a questionnaire response.
Every state change in the org. Filter by time window, type, or scope. The audit trail for security ops.
Integrations
Push findings where your team already lives. Investigate from Slack without opening the dashboard. Two-way sync with the ticketing system you already use.
OAuth-bound Slack app with five slash commands: /umbra services, /umbra findings, /umbra ask (NL), /umbra run, /umbra report. MS Teams + Discord on the roadmap.
Slack, email digests, and generic outbound webhooks. Per-channel severity filters; suppression rules for the noisy categories.
One click creates the three notification rules every workspace wants on day one: exploitable / KEV / critical, with sensible rate limits.
Create a Jira or GitHub Issues ticket from any finding: title, severity, PoC excerpt, replay link pre-filled. Linear on the roadmap.
Jira + GitHub Issues webhooks: close the ticket, the finding closes; close the finding, the ticket transitions. Operator-tunable status maps for any custom workflow.
Stream every Umbra finding into Splunk HEC or Microsoft Sentinel as a structured event. Correlate against the rest of your SecOps feeds.
Workspaces + access
Multi-tenant from day one. Role-scoped access, SSO, audit log of every privileged action.
Per-org isolation. Google + Microsoft OIDC sign-in. Email invites with role pre-selection.
Per-org module bundles gate what a plan unlocks; on top, an org-admin can restrict a teammate to specific modules (allow-by-default, server-enforced): lock a user to Deep Audit only. The Pro+ / Business granular-access differentiator.
viewer / member / admin / owner. Every privileged action (target add/remove, AI run, agent revoke) logged with actor + timestamp + scope.
Filter / search / paginate every privileged action in the workspace. CSV export for SOC2 / ISO27001 auditors. org_admin-gated.
Paddle-backed: subscribe, top up AI dollars, upgrade plan, all from the workspace settings. Cancel at any time.
Every dashboard surface is also a REST endpoint. Full OpenAPI spec at /api/openapi.json on every install.
Bearer-token authenticated read API at /api/v1/... (pull findings, targets, host inventory as JSON). Org admin mints keys; partner consumes them.
That's the whole surface.
Free tier covers asset discovery + CVE matching against an unlimited number of targets. AI validation, internal-network agents, and Slack unlock on Starter and above.