Appearance
How Exploit Shield works
Exploit Shield finds leaked secrets and vendor incidents for your organization.
You review them in the dashboard. You mark false positive or remediated. You can send alerts.
There is no separate Impact findings screen in the live dashboard.
Lifecycle
text
Secret found
→ Exposure row (secret list)
→ Attribution report (ownership)
→ If vendor-attributed: vendor incident + scorecard grade
→ If a rule matches: alert webhook
→ You investigate
→ You mark false positive or remediated| Stage | Where you see it | What it is |
|---|---|---|
| Secret found | Exposures | One leaked credential or token. Severity is 0–10. |
| Attribution | Reports | One attributed event. Includes ownership. |
| Ownership | Reports filter and columns | First-party, joint, or third-party. |
| Vendor posture | Vendors | Letter grade from a 0–100 scorecard. |
| Alert | Alerting | Webhook when a report meets your rule. |
| Investigation | Report detail, exposure row, vendor incident | You read evidence and decide. |
| Remediation | False positive / Remediated controls | You mark the row. Hidden by default. |
Three lists
Do not treat these as one list.
| List | Page | Grain |
|---|---|---|
| Exposures | /exposures | Secret in a file and repository |
| Reports | /reports | Attribution event with ownership |
| Vendor incidents | /vendors/:id | Incident on a vendor scorecard |
A report is not an exposure.
A vendor grade is not a report.
A grade is vendor posture. It is not “does this reach us.”
See Objects and terms and Scoring and attribution.
Who does each step
| Step | Who |
|---|---|
| Add domains, vendors, integrations | Admin |
| Add users and roles | Admin |
| Add alert destinations and rules | Admin |
| Flip Pending to Active | Not a dashboard action. Wait for review. |
| Read Reports, Exposures, Vendors | Any signed-in user |
| Mark false positive or remediated | Signed-in user, when the page allows it |
| Change your own role | Nobody. The API rejects that edit. |
What you do after you find a row
Use the investigation playbook.
The short path:
- Open the report. Read ownership and confidence.
- Open matching exposures for the secret and repository.
- If ownership is third-party, open Vendor Monitoring.
- If it is not real or not yours, mark False positive.
- If you fixed it, mark Remediated. That mark is yours. The product does not prove the repository is clean.