Appearance
15-minute quickstart
Do this with an admin role.
See Roles.
This path configures the dashboard.
It does not promise findings in 15 minutes. Findings appear after Status is Active and a scan has produced rows.
Prerequisites
- A dashboard URL
- A sign-in account. Sign-in uses PropelAuth. See Sign in.
- Your primary hostname, such as
example.com - A short list of important vendor hostnames
- One webhook URL if you want alerts (Discord, Microsoft Teams, Google Chat, SIEM, CTI, or Other)
Timed path
| Minutes | Action | Success check |
|---|---|---|
| 0–2 | Sign in. Confirm the sidebar footer shows API Status Connected. | Dashboard loads. |
| 2–6 | Open Configurations → Domain / keyword. Add your primary domain and keywords. | A new row exists. Status is Pending. |
| 6–10 | Open Vendors. Add critical vendors. Optional: add integrations. | Vendor rows exist. Status is Pending. |
| 10–13 | Open Users. Add analysts. | Each person has an email and a role. |
| 13–15 | Open Alerting. Add one destination and one rule. | One enabled destination. One enabled rule. |
Detail: Configurations, Users, Alerting.

The Add identifier dialog. Required field: Domain. Keywords are comma-separated. Notes are optional. Select Save.
What Pending means
| Status | What it means | What you do |
|---|---|---|
| Pending | You saved the row. Hunt does not use it yet. | Wait. You cannot flip this in the dashboard. |
| Active | Review finished. Hunt can use the term. | Refresh Reports and Exposures. |
Do not invent a wait time. Refresh later. If rows stay Pending, ask the person who reviews hunt terms.
After 15 minutes
- Confirm API Status stays Connected.
- When a domain row is Active, open Reports and Exposures.
- If both lists are empty, the scan has not delivered rows yet. Check again later.
Then read How Exploit Shield works and the investigation playbook.