Skip to content

15-minute quickstart

Do this with an admin role.
See Roles.

This path configures the dashboard.
It does not promise findings in 15 minutes. Findings appear after Status is Active and a scan has produced rows.

Prerequisites

  • A dashboard URL
  • A sign-in account. Sign-in uses PropelAuth. See Sign in.
  • Your primary hostname, such as example.com
  • A short list of important vendor hostnames
  • One webhook URL if you want alerts (Discord, Microsoft Teams, Google Chat, SIEM, CTI, or Other)

Timed path

MinutesActionSuccess check
0–2Sign in. Confirm the sidebar footer shows API Status Connected.Dashboard loads.
2–6Open ConfigurationsDomain / keyword. Add your primary domain and keywords.A new row exists. Status is Pending.
6–10Open Vendors. Add critical vendors. Optional: add integrations.Vendor rows exist. Status is Pending.
10–13Open Users. Add analysts.Each person has an email and a role.
13–15Open Alerting. Add one destination and one rule.One enabled destination. One enabled rule.

Detail: Configurations, Users, Alerting.

Add a domain

The Add identifier dialog. Required field: Domain. Keywords are comma-separated. Notes are optional. Select Save.

What Pending means

StatusWhat it meansWhat you do
PendingYou saved the row. Hunt does not use it yet.Wait. You cannot flip this in the dashboard.
ActiveReview finished. Hunt can use the term.Refresh Reports and Exposures.

Do not invent a wait time. Refresh later. If rows stay Pending, ask the person who reviews hunt terms.

After 15 minutes

  1. Confirm API Status stays Connected.
  2. When a domain row is Active, open Reports and Exposures.
  3. If both lists are empty, the scan has not delivered rows yet. Check again later.

Then read How Exploit Shield works and the investigation playbook.