Skip to content

How Exploit Shield works

Exploit Shield finds leaked secrets and vendor incidents for your organization.
You review them in the dashboard. You mark false positive or remediated. You can send alerts.

There is no separate Impact findings screen in the live dashboard.

Lifecycle

text
Secret found
    → Exposure row (secret list)
    → Attribution report (ownership)
    → If vendor-attributed: vendor incident + scorecard grade
    → If a rule matches: alert webhook
    → You investigate
    → You mark false positive or remediated
StageWhere you see itWhat it is
Secret foundExposuresOne leaked credential or token. Severity is 0–10.
AttributionReportsOne attributed event. Includes ownership.
OwnershipReports filter and columnsFirst-party, joint, or third-party.
Vendor postureVendorsLetter grade from a 0–100 scorecard.
AlertAlertingWebhook when a report meets your rule.
InvestigationReport detail, exposure row, vendor incidentYou read evidence and decide.
RemediationFalse positive / Remediated controlsYou mark the row. Hidden by default.

Three lists

Do not treat these as one list.

ListPageGrain
Exposures/exposuresSecret in a file and repository
Reports/reportsAttribution event with ownership
Vendor incidents/vendors/:idIncident on a vendor scorecard

A report is not an exposure.
A vendor grade is not a report.
A grade is vendor posture. It is not “does this reach us.”

See Objects and terms and Scoring and attribution.

Who does each step

StepWho
Add domains, vendors, integrationsAdmin
Add users and rolesAdmin
Add alert destinations and rulesAdmin
Flip Pending to ActiveNot a dashboard action. Wait for review.
Read Reports, Exposures, VendorsAny signed-in user
Mark false positive or remediatedSigned-in user, when the page allows it
Change your own roleNobody. The API rejects that edit.

What you do after you find a row

Use the investigation playbook.
The short path:

  1. Open the report. Read ownership and confidence.
  2. Open matching exposures for the secret and repository.
  3. If ownership is third-party, open Vendor Monitoring.
  4. If it is not real or not yours, mark False positive.
  5. If you fixed it, mark Remediated. That mark is yours. The product does not prove the repository is clean.