Skip to content

Investigation playbook

Use this when a report, exposure, or alert arrives.
All steps use the live dashboard pages.

Read How Exploit Shield works first if the lists are unclear.

Every case

  1. Open Reports. Find the row. Read ownership, severity, and confidence.
  2. Open the report detail.
  3. Open Exposures. Match repository, file, and secret type.
  4. If ownership is third-party or joint, open Vendor Monitoring and the vendor detail.
  5. Choose one status:
    • False positive — not real, or not yours.
    • Remediated — you finished the fix you own.
    • Leave open — still working.

Do not use the vendor grade as the close action.

First-party

Ownership is first-party. This is attributed to your org.

  1. Confirm the repository and file on Exposures.
  2. Open the repository link if it is present.
  3. If the secret is real, rotate or revoke it in your systems. That work is outside this dashboard.
  4. When you consider the leak handled, mark Remediated on the exposure and the report.
  5. If the row is not your org or not a real secret, mark False positive.

The dashboard does not rotate the secret for you.

Joint

Ownership is joint. The event is shared.

  1. Do the first-party checks for anything your org controls.
  2. Open the vendor scorecard for the other party.
  3. Mark Remediated only when your part is done. Say so in your own ticket system if you use one.
  4. Do not treat a vendor A grade as “we are done.”

Third-party

Ownership is third-party. This is vendor-attributed.

  1. Open Vendor Monitoring. Find the vendor. Select Open.
  2. Read the incident summary, severity, and confidence.
  3. Use the scorecard as posture, not as closure.
  4. If the incident is wrong, use the false-positive control on that incident when the page offers it.
  5. If the incident is real, handle vendor outreach in your TPRM process. The dashboard does not send vendor email.

When an alert arrives

Alerts fire on attribution reports that meet your rule.
Default new rule: High severity and 80% confidence.

The webhook does not include the secret value.
It includes rule name, severity, confidence, title, repository link, and report id.

  1. Open Reports. Find report_id.
  2. Follow the ownership playbook above.
  3. If you expected an alert and did not get one, see Troubleshooting.

When is it remediated?

Mark Remediated when you finished the work you own:

  • First-party: you rotated or removed the secret, or you accepted the residual risk in your process.
  • Third-party: you finished the vendor follow-up you own.

The mark hides the row by default so you can focus on open work.
It is not a proof that the file is gone from the public internet.