● heimdallX Help Center

New to security? No problem.
We'll walk you through it.

heimdallX is an AI security platform that scans your web, exposure, code, and cloud the way an attacker would, uses AI to verify what can actually be broken into, and then tells you what to fix first. This guide explains every feature — starting from the core concepts — so that anyone new to security jargon can follow along, one step at a time, alongside real screenshots.

New here

Security basics in 5 minutes

To get the most out of heimdallX, you only need to understand four ideas. They're not hard.

1. Attack surface — the sum of all the “doors and windows” an attacker could target. That includes your website, subdomains, open ports, employee emails, even public code repositories.

💡 In plain terms The more doors and windows a house has, the more ways a burglar can get in. Think of your attack surface as “a list of every entrance to your company.”

2. Vulnerability / finding — the doors and windows that are unlocked or weak. For example: an expired certificate, a missing security header, or a leaked password. heimdallX collects these problems into findings.

3. Severity — a rating for how dangerous a problem is. In order — Critical High Medium Low Info — and the more severe it is, the sooner you should fix it.

4. Exploitability — “Will this vulnerability actually be used in an attack?” A high-severity issue can be hard to exploit in practice, and the reverse happens too. heimdallX uses signals like EPSS and CISA KEV to surface “what's truly dangerous.”

💡 Key idea Good security isn't about “fixing every single problem” — it's about “fixing the things most likely to actually be exploited, first.” heimdallX sets exactly that priority for you. Whenever an unfamiliar word comes up, check the glossary anytime.

New here

Run your first scan in 3 steps

No credit card required. Sign in with a Google or Apple account and you're ready to go.

  1. 1. Sign in

    Go to heimdallx.ai/app and click Continue with Google or Continue with Apple. Your workspace and project are created automatically, so there's nothing to set up.

  2. 2. Run a scan

    Click + New scan at the top, pick a module (Web & assets / Digital exposure / Code security / Cloud), enter the target domain, email, or repository, then click Run scan.

  3. 3. See the results

    Usually within a few minutes, the Overview screen fills in with your security posture score and findings. Progress updates in real time.

heimdallx.ai/app
heimdallX login screen — sign in with Google or Apple
The login screen — start securely with a Google or Apple account.
💡 Tip If it's your first time, try running a web scan on a domain you own. In a few minutes you'll see exactly “how your site looks to an attacker.”
Core concepts

Workspaces & projects

heimdallX organizes your assets in two levels — a team-wide workspace, and projects inside it.

A workspace is the top-level space for a team or organization; your plan and teammates are tied to it. A project is like a folder inside it that separates assets, scans, and findings (for example: “Production site,” “Staging,” “Customer A”).

💡 In plain terms Workspace = the company building, project = each office inside it. Scan results and findings are always stored in “the office (project) you currently have open.”

You can switch or create workspaces and projects anytime from the workspace / project switcher at the top left. When you sign in, a default workspace and a “Default project” are already set up, so you can jump straight into scanning.

Note If you can't see your results, check that the right project is selected at the top left. You may have scanned in a different project.
Dashboard

Overview — your security posture at a glance

The first screen you land on after signing in. Every scan result is distilled into a single score and a priority list.

Your security posture score (0–100, graded A–F) is the average of your assets' latest scores, shown against an industry benchmark.

💡 In plain terms It's like a school report card. It shows what score (and grade) you got out of 100, and “whether you're doing better than the average company.”

On the right, posture by module shows the score for each of web, exposure, code, and cloud, while risk trend shows how your posture changes as you run more scans. The cards up top show open findings (the count of critical and high), top fixes, the number of monitored assets, and your last scan time; the number badges in the left sidebar tell you how many items have piled up on each screen.

heimdallx.ai/app · Overview
heimdallX Overview dashboard — security posture score, risk trend, posture by module
The Overview dashboard — security posture B (77/100), per-module scores, and risk trend on one screen.
💡 Tip Use ↓ CSV / ↓ PDF report at the top right to export the current screen anytime. Most list screens support the same.
Scanning

Run a scan

Click + New scan and the runner appears, where you choose the module and target.

A scan is how heimdallX actually inspects a target to find problems. Just choose the module (what to check) and the target (where to check) — the rest is automatic.

heimdallx.ai/app · New scan
New web scan runner — pick a module, enter the target, agree to active validation
The new-scan runner — pick a module tab, enter your target, then run the scan.
🔐 Active validation Check “I own this target and authorize non-destructive probes,” and heimdallX safely confirms real vulnerabilities like reflected XSS, SQL errors, and open redirects. Use it only on assets you own or manage. “Non-destructive” means safe tests that won't break your system.
💡 Tip You can also just tell the in-app AI analyst, “Run a web scan on example.com.” The scan starts right away without opening the runner.
Scanning

Scan modules in detail — what does each find?

Four modules check for risk from different angles. Here's what each one actually looks at, spelled out.

Web & assets

Enter a domain and heimdallX checks and analyzes your DNS and subdomains (your site's address structure), TLS certificate (the padlock icon), security headers (HSTS, CSP, and more), technology fingerprint (which server and framework you run), open ports, and whether anything has leaked — all with AI.

Free and up

Digital exposure

Enter an email, username, or domain and heimdallX checks for accounts caught in past breaches (HIBP), your email anti-spoofing setup (SPF/DMARC), and exposed public profiles. You'll learn “whether your information has already leaked.”

Pro and up

Code security

Point it at a GitHub repository and it audits for secrets accidentally committed (API keys, passwords), sensitive files, and vulnerabilities in the source code itself (SAST static analysis).

Business

Cloud (CSPM)

Inspects your cloud settings to find misconfigurations (for example, a publicly exposed storage bucket) and risky permission combinations (toxic combinations).

Business
💡 In plain terms Web = “checking the front door,” Digital exposure = “checking whether your info is circulating on the black market,” Code = “checking whether a password got written into the blueprints,” Cloud = “checking the locks and key management on your warehouse.” Every tricky acronym is unpacked one by one in the glossary.
Scanning

Managing assets

Every domain, email, and repository you scan is registered as an asset, with its score and history tracked.

An asset is each individual thing you want to protect (a site, an email, a repository). Each asset shows its latest grade, its number of open findings, and its last scan time; click one to see just that asset's scan history and findings — handy for focusing on a specific site or account.

heimdallx.ai/app · Assets
Asset list — grade and finding count per domain and email
Assets — grade and open-finding count for each registered domain and email.
Scanning

Proving an asset is yours

Passive scanning needs no proof. Anything that touches the target does — and this is how you give it.

A passive scan reads what is already public: certificates, DNS, headers, third-party records. You can run one against any domain you like, because we are not doing anything to it that a browser doesn't.

An active scan is different. It sends probes — parameter payloads, a port sweep — and that is only acceptable against something you own. So the “actively probe this target” checkbox requires the target to be a verified asset in your workspace, and a scan that asks for active probing without one is refused with an explanation rather than quietly downgraded.

💡 In plain terms Reading a shop's opening hours off the front door is passive. Trying the handle is active. We will only try the handle on a door you can show us the deed to.

How to verify (about two minutes).

  1. Open Assets, add the domain if it isn't there, and press Verify.
  2. We show you a token. Publish it as a DNS TXT record — either on the domain itself or on _heimdallx.<your-domain> — with the token as the value.
  3. Wait for DNS to propagate (usually seconds, occasionally up to an hour on a slow provider) and press Verify again.

Verification is per asset and does not expire, so you do this once per domain. You may delete the TXT record afterwards, but leaving it in place means re-verification is instant if the asset is ever recreated. Subdomains of a verified domain are covered.

If it doesn't verify: check the record from outside your network (dig TXT _heimdallx.example.com), confirm your provider hasn't wrapped the value in extra quotes, and remember that a CDN or registrar's “DNS proxy” can cache the old answer for its TTL.

Scanning

Attack Surface Discovery (EASM) — find assets you forgot

Enter a single root domain and heimdallX automatically finds your scattered external assets (subdomains and more).

EASM (External Attack Surface Management) discovers “assets you didn't even know you had.” Enter a domain and it digs through Certificate Transparency (public certificate records) and DNS to map out subdomains and hidden assets, with AI flagging risky shadow assets (like an abandoned test server).

💡 In plain terms As a company ages, it accumulates old sites and servers nobody remembers. Attackers go straight for these “forgotten back doors.” Asset discovery builds that back-door list for you automatically.
heimdallx.ai/app · Discovery
Attack Surface Discovery (EASM) — discover external assets from a root domain
Asset discovery — enter a root domain, click “Discover,” and it maps your external footprint.
Understanding results

Reading findings

Every finding is classified by severity, module, and category, and you can search and filter them.

CRITICAL HIGH MEDIUM LOW INFO

Each finding shows its target asset, module, and category (HTTP headers, email security, sessions, brand protection, and so on). Expand a finding and you'll see its evidence, impact, how to fix it, and CWE — plus exploitability signals like EPSS and CISA KEV.

💡 In plain terms EPSS is “the probability (%) that this vulnerability will actually be used in an attack,” and CISA KEV is “a list, confirmed by a government agency, of vulnerabilities already being exploited in the wild.” When these are high, it's a signal to fix the issue right now, regardless of severity.
heimdallx.ai/app · Findings
Findings list — severity filter, search, categories
Findings — real results like missing HSTS/CSP/SPF·DMARC and look-alike domains.
💡 Tip Use the severity filter and search box at the top to narrow things down, like “Medium and up” or “HTTP headers.” You can also use the module tabs to view web, exposure, code, and cloud separately.
Understanding results

Remediation — what to fix first

The same issue across multiple assets is grouped into one and sorted by how much risk you remove.

It gives you a priority queue so that “fixing once resolves it everywhere.” Each item shows how many assets it affects (multi-asset) and its expected impact, so you can knock down the biggest risks first when time is limited.

heimdallx.ai/app · Remediation
Remediation priority queue — sorted by impact
Remediation — a fix-first queue ranked by impact.
Understanding results

Attack surface — the exposure map

Visualizes the path from asset → finding → exploit, in the order an attacker reaches them first.

The exposure map connects each asset to its most dangerous finding with a line, so you can see at a glance which spots are “entry points.” The fix-first queue below prioritizes by severity × confidence × exploitability, and also shows whether a “PoC exists / actively exploited” and a recommended fix-by deadline. A PoC (Proof of Concept) means “example code that actually breaks this vulnerability is already public,” which is a danger sign.

heimdallx.ai/app · Attack Surface
Attack surface exposure map — assets linked to findings, fix-first queue
Attack surface — the exposure map and an exploitability-based fix-first queue.
Understanding results

Breach & attack simulation

An AI red team weaves your findings into the attack path (kill chain) a real attacker would follow.

Click Run simulation and your findings are mapped to MITRE ATT&CK tactics and techniques (reconnaissance → initial access → privilege escalation → impact), and each attack chain's likelihood of success is calculated.

💡 In plain terms A red team is “a team on your side that plays the attacker and actually tries to break in.” A kill chain is the steps an attack goes through to succeed (recon → break-in → spread → damage), and a chokepoint is a “pressure point” where blocking just one step brings the whole thing down. AI pinpoints that pressure point for you.
heimdallx.ai/app · Breach Sim
Breach & attack simulation — MITRE ATT&CK kill chain, likelihood of success, chokepoints
Breach & attack simulation — ATT&CK-mapped attack chains and chokepoint fixes.
Threat intelligence

External threats (DRP) — watching the outside world too

Digital Risk Protection — correlates leaks, dark web/Telegram chatter, malware IOCs, ransomware victim posts, and brand impersonation with your assets, then ranks them by TALON score.

If everything so far has been about “inspecting your own inside,” external threats watch “how your story is circulating out there.”

💡 In plain terms DRP (Digital Risk Protection) is like a “security camera outside your company.” It watches the dark web (an anonymous black market you won't find with a normal search), IOCs (traces of an attack), ransomware leak boards, and more to tell you “whether your company's information is being traded.” TALON is the risk-ranking score for these external threats.

Click Collect now and it gathers real feeds like ransomware.live, abuse.ch, OpenPhish, and HIBP along with dark web/Telegram chatter, then connects them to your domains and emails. Results are split into Leaks / Dark web & Telegram / Brand / ATOM / Graph tabs, and turning on Monitor collects them automatically on a schedule.

heimdallx.ai/app · External threats
External threat intelligence — TALON score, leaks, dark web, IOCs
External threat intelligence — outside risks (leaked credentials, dark web, malware URLs) sorted by TALON score.
Threat intelligence

Threat Intel — what's being exploited right now

Shows the vulnerabilities being actively exploited around the world (CISA KEV + EPSS) live, with AI picking out the ones relevant to your environment.

A CVE is “a unique ID assigned to each publicly disclosed vulnerability (e.g., CVE-2026-10520).” Threat Intel sorts the CVEs being actively exploited right now by EPSS probability and ransomware association, and attaches “why it matters” and “what to do” to each one.

💡 In plain terms It's like the news telling you “which cold is going around this season.” There are tens of thousands of vulnerabilities out there, but you can focus on the ones actually spreading right now. If any of them overlap with your environment, deal with those first.
heimdallx.ai/app · Threat Intel
Threat Intel — CISA KEV + EPSS live CVE watchlist
Threat Intel — a live CVE watchlist sorted by CISA KEV totals, EPSS probability, and ransomware association.
Threat intelligence

AI Briefing — what to check right now

AI sums up your most severe findings and top TALON external threats into a “check these now” list.

When there are so many screens you don't know where to start, open the AI Briefing and it picks out “the few things you really need to handle today,” with a ranking, recommended actions, and deep links to the relevant screens. Five minutes each morning is enough to grasp your organization's risk status.

heimdallx.ai/app · AI Briefing
AI security briefing — the key items to check now and recommended actions
AI Briefing — top-priority items organized by ranking, recommended action, and deep link.
Threat intelligence

Continuous monitoring & alerts

Don't stop at a single scan — re-scan your assets daily or weekly so you never miss a change.

Set a target and a cadence (e.g., daily) under New monitor and re-scans are scheduled automatically. The recent changes area compares new and resolved findings after each re-scan to tell you whether your posture is improving or getting worse, and you can get alerts when a new risk is detected.

💡 In plain terms Security isn't a one-time cleanup; it's more like sweeping away the dust that piles up every day. A monitor is your “scheduled regular checkup.”
heimdallx.ai/app · Monitoring
Continuous monitoring — scheduled re-scans and change tracking
Continuous monitoring — active monitors re-scanned daily, with change tracking.
Detection & response

Incidents — the SOC console

Where a detection becomes a case somebody owns, with an AI first-pass verdict already attached.

A finding says something is wrong with an asset. An incident says something is happening: repeated failed logins, a new critical on a monitored target, a detection from the telemetry you forward to us. Alerts about the same thing on the same asset fold into one case instead of arriving as twenty messages, and a case that has already paged you does not page again for an hour unless it escalates.

Each case carries a status (open → acknowledged → in progress → resolved), an owner, an SLA clock for acknowledgement and for resolution, and a timeline of everything that touched it. High and critical cases are automatically submitted for advisory first-pass triage — classification, confidence, and a recommended next step. A model verdict is labelled separately from a deterministic rule-based fallback. Provider or accounting failures can delay or prevent a verdict; the incident and its security page do not depend on it.

💡 In plain terms Findings are the state of your house. Incidents are the doorbell ringing. This screen is the list of doorbells, ordered by which one is most likely to matter.

The console updates live — a case raised while you are looking at the list appears without a refresh. To feed it with your own logs, see log forwarding.

Roles. Viewers can read every case and change none: triage, status changes, assignment and suppression rules all require write permission, so a read-only account cannot quietly silence a detection.

Governance

Compliance evidence

Automatically maps your findings to the controls an auditor checks.

Evidence is collected continuously from your scans and mapped to five frameworks — OWASP, PCI-DSS, ISO 27001, SOC 2, and CIS. You can immediately see the number of violations per framework and your key control gaps, which dramatically cuts audit-prep time.

💡 In plain terms Compliance means “whether you're properly following the security rules you're supposed to.” Things like ISO 27001 and SOC 2 are industry-standard “security checklists.” heimdallX automatically links your findings to these checklist items, making audit prep easy.
heimdallx.ai/app · Compliance
Compliance — mapping to OWASP/PCI-DSS/ISO 27001/SOC 2/CIS
Compliance — posture per framework and your key control gaps.
Governance

Executive brief & reports

An AI security advisor synthesizes your overall posture into a board-ready briefing.

Click Generate brief and you get a one-page summary with a risk verdict (e.g., “Moderate risk — improvement needed”), your key business risks, and a 30/60/90-day roadmap. It's written in the language executives understand — “revenue, trust, regulation” — rather than technical jargon, so you can drop it straight into a report, and you can export it as Print/PDF or DOCX.

heimdallx.ai/app · Executive Brief
Executive brief — an AI-written board-level risk verdict and business risks
Executive brief — an AI-written board-level risk verdict and key business risks.
Governance

Integrations & alerts

Send scan completions, new critical findings, and posture changes to Slack, Teams, or a webhook, or to SIEM/SOAR, and turn findings into Jira, GitHub, or ServiceNow tickets.

You can't stare at a dashboard all day, so this feature sends you an alert through the tools you already use whenever something important happens. Add an integration and choose which events to alert on (scan complete / new critical finding / posture change).

💡 In plain terms A webhook is “a feature that fires an automatic notification to an address you specify whenever something new happens.” SIEM/SOAR are enterprise tools that collect security logs to analyze them and respond automatically. The CI/API keys below let you run heimdallX scans inside an automation pipeline like GitHub Actions and block the build when something's risky (a build gate).

heimdallx.ai/app · Integrations
Integrations — Slack, Teams, SIEM/SOAR, Jira, GitHub, ServiceNow, and CI/API keys
Integrations — alert channels, ticket integrations, and API keys for CI/CD.
Governance

Activity log

Records every change made in this workspace — who did it and when.

Every action — running a scan, generating a brief, adding a monitor — is kept in chronological order. Great for tracking “when did what happen” when working as a team, or as evidence for an audit.

heimdallx.ai/app · Activity
Activity log — workspace change history (who and when)
Activity log — every change in the workspace, in chronological order.
Collaboration

Team & roles

Invite teammates to your workspace and set their access with roles.

Owner

Full control, including plan, teammates, and deletion. The person who created the workspace.

Admin

Manages settings and members, and runs all scans and remediation.

Analyst

Handles day-to-day work: running scans, working findings and remediation.

Viewer

Read-only access to results and reports.

💡 In plain terms RBAC (role-based access control) is “giving people different keys depending on their job.” Just as you wouldn't hand an intern the master key, a viewer can only look, while an owner can do everything.
Collaboration

Single sign-on & directory sync

SAML 2.0 and SCIM 2.0, on every plan including the free one.

SSO is not a premium feature here. Charging for it pushes the organisations with the most users towards shared passwords, which is the opposite of what this product is for — so SAML sign-in and SCIM provisioning are available on every plan.

Setting up SAML. In your workspace settings, enable SSO and choose a slug (a short name for your organisation). That gives you three URLs for your identity provider — Okta, Entra ID, Google Workspace, Keycloak, anything that speaks SAML 2.0:

  • Metadata — /auth/saml/<slug>/metadata, which most providers can import in one step
  • Sign-in start — /auth/saml/<slug>/start
  • ACS / callback — /auth/saml/<slug>/callback

The assertion needs to carry an email address; that is what identifies the person. A user who signs in through your IdP joins the workspace with the default role you configured, and the identity is bound to your workspace — an assertion from one organisation's IdP cannot land in another's tenant.

Directory sync (SCIM). Mint a SCIM token in the same settings screen and point your provider at /scim/v2/Users. Creating a user in your directory adds them here; deactivating them there removes their access here. That second half is the part worth having: the usual way an ex-employee keeps access to a security console is that somebody forgot to click Remove.

💡 In plain terms SSO is “sign in with the account you already have”. SCIM is “and when HR switches that account off, this one switches off too”.
For developers

Keys, CI scans and log forwarding

Two kinds of key, one machine-readable spec, and a build gate that can fail a pull request.

Everything a machine can do here is authenticated with a workspace API key, sent as Authorization: Bearer <key>. Keys are shown once when you create them — only a hash is stored — and the prefix tells you what a key is for:

  • hxci_… — CI keys. Start a scan from your pipeline (POST /ci/scan) and read the result (GET /ci/scan/<id>). The result includes a SARIF document, which GitHub, GitLab and most IDEs render as inline annotations, plus a gate verdict you can turn into an exit code. The gate is configurable per call — fail only on verified findings, exclude a verification tier, set a severity floor — so you can start advisory and tighten later.
  • hxin_… — ingest keys. Post events from your SIEM, an agent or a log shipper to POST /ingest/events. They are normalised, run through detection rules and surface as incidents.

The full contract — paths, fields, error codes — is published as OpenAPI 3.1 at /openapi.json, so you can generate a client rather than copying a curl snippet. It deliberately describes only these key-authenticated endpoints: the console's own session-authenticated routes are not a public API and are free to change.

💡 In plain terms One key for “scan my code when I push”, another for “here are my logs”. Both are revocable, both are scoped to one workspace, and neither can sign in to the console.

Lost a key? Revoke it in the same screen and issue a new one; revocation takes effect on the next request. A key never grants more than the workspace it was minted in.

Reference

AI analyst — the AI that does it for you

Click AI analyst at the top and a copilot appears that reads your posture and operates the dashboard on your behalf.

Give it natural-language instructions like “What should I fix first?”, “Run a web scan on example.com,” “Summarize my security posture,” or “Set up a daily monitor for my domain,” and it will run scans, set up monitors, switch projects, and even export reports. It's an especially reassuring helper for beginners who find security jargon unfamiliar. That said, AI can make mistakes, so double-check important changes.

heimdallx.ai/app · AI analyst
heimdallX AI analyst copilot panel
AI analyst — give it natural-language instructions and it operates the dashboard directly.
Reference

What each plan includes

The modules available to you depend on your plan. For the latest pricing, see heimdallx.ai.

Free

Individuals · just getting started

  • Web & asset scans
  • Security posture score & findings
  • Digital exposure
  • Code security · Cloud

Pro

Prosumers · small teams

  • Web & asset scans
  • Digital exposure added
  • External threats (DRP) · always-on monitoring
  • Code security · Cloud

Business

Teams · organizations that need compliance

  • Everything in Pro
  • Code security · Cloud (CSPM)
  • Compliance evidence · executive reporting
  • Up to 1,000 scans/month · 100 assets
Reference

Glossary — plain-language definitions

New to security? Start here. We've gathered the terms from this guide and the app and explained them in plain language.

Web & network basics
DNS
The “internet phone book” that turns a domain (the human-readable address, example.com) into the real server address.
Subdomain
A sub-address in front of the main domain (blog.example.com, mail.example.com, and so on). Forgotten subdomains often become an attack route.
TLS / SSL certificate
The padlock in your browser's address bar. It encrypts the connection and proves “this really is that site.” Expiry and misconfiguration are common problems.
Port
A server's “entrance number.” An unnecessary open port becomes an attack route.
HTTP security headers
Settings a server uses to tell the browser “behave safely, like this.” HSTS, CSP, and the others below are the main ones.
HSTS
A header that forces “always connect to this site over encryption (HTTPS).” Without it, connections are easier to intercept in the middle.
CSP
Content-Security-Policy. A header that limits which scripts a page can run, blocking malicious code injection (XSS).
Fingerprint
Figuring out which server, framework, and version a site runs. The step where an attacker works out “which key will fit.”
Vulnerabilities & risk assessment
Vulnerability / finding
A weakness that could be used in an attack. heimdallX collects these as findings.
Severity
A risk grade for a problem (critical, high, medium, low, info). The higher it is, the bigger the potential damage.
CVE
A unique ID assigned to each publicly disclosed vulnerability (e.g., CVE-2026-10520). A globally shared identifier.
CVSS
The standard scoring system that rates a vulnerability's severity from 0 to 10.
EPSS
Exploit Prediction Scoring System. A score predicting the probability (%) that a vulnerability will actually be exploited.
CISA KEV
A list, maintained by the U.S. agency CISA, of “vulnerabilities already being exploited in the wild.” If it's on here, treat it as top priority.
PoC
Proof of Concept. It means example code or a method to actually break a vulnerability is public — a danger sign.
CWE
A “type classification” for vulnerabilities (e.g., SQL injection, broken authentication). Helps you understand similar issues as a group.
SAST
Static Application Security Testing. A code audit that scans source code without running it to find vulnerabilities.
XSS
Cross-site scripting. An attack that plants malicious script in a web page to target its visitors.
Attacker's view & simulation
Attack surface
The sum of all entry points an attacker could target (sites, subdomains, ports, emails, code, and more).
EASM
External Attack Surface Management. Automatically finding and managing even the external assets you didn't know you had.
Red team
A team (or activity) that plays the attacker on your side, actually breaking in to find weaknesses.
Kill chain
The steps an attack goes through to succeed (recon → break-in → spread → damage).
MITRE ATT&CK
A global-standard knowledge base of attacker tactics and techniques. The simulation maps to this framework.
Chokepoint
The “pressure point” in a kill chain where blocking just one step brings the whole thing down. The best bang-for-buck fix.
External threats & intel
DRP
Digital Risk Protection. Monitoring and responding to risks outside the organization (dark web, leaks, brand impersonation).
Dark web
An anonymous network that's hard to reach with a normal search or browser. Where leaked information gets traded.
TALON
heimdallX's external-threat priority score. Ranks threats by reflecting their severity and how relevant they are to your assets.
ATOM
A method that correlates external threats against your assets and identities to pick out “only what's relevant to you.”
IOC
Indicator of Compromise. Traces of a breach (malicious IPs, URLs, hashes, and so on).
C2
Command & Control. The server an attacker uses to remotely control infected systems.
Ransomware
Malware that encrypts your files and then demands money. We monitor victim boards with DRP.
Phishing / look-alike domain
A scam using a fake address that resembles the real one (heimdall.ai vs heimdallx.ai) to trick you.
HIBP
Have I Been Pwned. A database of past breach incidents. Check whether your email has leaked.
SPF / DMARC
Authentication settings that prevent email spoofing. Without them, you're exposed to domain-impersonation phishing.
Governance & operations
CTEM
Continuous Threat Exposure Management. Not a “one-time check” but a cycle of discover, validate, fix, and monitor.
Posture (security posture)
A combined score/grade for your current security state. Like a report card.
Compliance
Following the security rules and standards you're supposed to. The frameworks below are that “checklist.”
OWASP / PCI-DSS / ISO 27001 / SOC 2 / CIS
Industry-standard security frameworks (checklists). They define requirements by area, such as payments, personal data, and authentication.
CSPM
Cloud Security Posture Management. Checks for cloud misconfigurations and risky permissions.
SIEM / SOAR
Tools that collect security logs to analyze them (SIEM) and respond automatically (SOAR). Splunk, Elastic, and so on.
Webhook
An integration method that sends an automatic notification to an address you specify whenever a new event occurs.
RBAC
Role-Based Access Control. Granting different access permissions based on someone's job (role).
MFA
Multi-factor authentication. Protects an account with a second verification step — an OTP, a fingerprint, and so on — on top of a password.
Reference

When you're stuck

My scan is stuck on “In progress.”
Depending on the target's size and the queue, it can take a few minutes. Progress updates in real time, and when it's done the results appear automatically in Overview and Findings. If it looks stuck for more than a few minutes, try refreshing.
I don't see any results at all.
Check that the right workspace and project are selected at the top left. You may have scanned in a different project. Also, if you just created your account, you need to run a scan first before any data shows up.
Code/cloud scans are locked.
Code security and Cloud (CSPM) unlock on the Business plan. They're unlocked based on the workspace owner's plan.
Is it okay to turn on active validation?
Use it only on assets you own or manage. Sending active probes to someone else's system is not recommended, and the runner's consent checkbox confirms your ownership and authorization.
Frequently asked questions

FAQ

Can I use this with no security background at all?
Yes. Just enter a domain and the scan runs automatically, with each finding explaining how to fix it in plain language. Unfamiliar terms are explained in the glossary, and the AI analyst can handle things for you if you just ask.
What do I need to run a scan?
A web scan only needs the target domain. Digital exposure takes an email, username, or domain; code security takes a GitHub repository. No credit card required.
Can I scan someone else's site?
Basic reconnaissance (passive checks) observes public information. But active validation sends real probes, so you should use it only on assets you own or manage.
How is the security posture score calculated?
It averages each asset's latest scan score (0–100), shows it as an A–F grade, and compares it to an industry benchmark. Higher-severity findings drag the score down more.
Why do EPSS and KEV matter?
Severity alone makes it hard to know “whether something will actually be breached.” Looking at EPSS (exploit probability) and CISA KEV (whether it's being actively exploited) together lets you pinpoint exactly what to fix right now.
What is the TALON score?
It's the priority score for external threats (DRP). It ranks “the outside risks to deal with first” by reflecting the severity and asset relevance of leaks, dark web chatter, ransomware, and IOCs.
What's a chokepoint?
In an attack chain of several linked vulnerabilities, it's the point where blocking just that one collapses the whole chain. The simulation pinpoints this “best bang-for-buck move.”
Can I export results?
Yes. From the top right of most screens you can export as CSV or a PDF report, and the executive brief saves as PDF or DOCX.
Can I monitor continuously?
Yes. Set up daily/weekly re-scans for an asset under Monitoring and you'll get an alert when something changes. External threats are also collected automatically with a monitor.
Does it integrate with tools like Slack and Jira?
Yes. Send alerts to Slack, Teams, a webhook, or SIEM/SOAR, and turn findings into Jira, GitHub, or ServiceNow tickets. See Integrations.
Can I invite teammates?
Yes. Invite teammates to your workspace and set their access with the Owner, Admin, Analyst, and Viewer roles.
Is my data safe?
Scan results are isolated per workspace and protected by role-based access control (RBAC). For details, see our Privacy Policy.
I have more questions.
Reach out anytime at heimdallx.ai/contact, or just ask the in-app AI analyst.