Product Guide

What each part of SilentBolt does, and how you actually use it.

SilentBolt is a multi-tenant platform for external attack surface scanning and AI-driven attack orchestration. You onboard a domain, verify that you own it, scan it, triage what comes back, share the report, and — when you want to go deeper — run an orchestration session on top of that scan. The modules below follow that order.

Dashboard

The landing page. It aggregates every onboarded domain into one view: a risk snapshot by severity, recent scans, finding trends, the most exposed targets, and a critical-alert feed.

How to use it

  1. 01Open Critical Alerts first — new critical or high findings, failed scans and regressions land here.
  2. 02Read the Risk Snapshot for open findings by severity and the trend direction versus the previous period.
  3. 03Click into any scan under Recent Scans that finished overnight.
  4. 04Use Top Exposed Targets to decide where the next deep dive goes.

NoteFindings Trends needs at least two completed scans on the same domain before it shows anything meaningful.

Targets

A target is a domain you own and want scanned. Nothing runs against it until ownership is verified and an admin authorizes it, so scanning stays scoped to assets you are allowed to test.

How to use it

  1. 01Targets → Add Target: enter the domain, set the environment (production, staging, development) and any tags.
  2. 02Verify ownership with the generated DNS TXT record, or via the email challenge sent to an admin address on the domain.
  3. 03Have an admin authorize the domain — a separate approval step from verification.
  4. 04Scan history, tags, environment and deletion all live on the domain record.

NoteWildcards are not accepted. Add the base domain and the discovery phase enumerates subdomains itself. Deleting a domain also deletes its scans, findings and reports.

Scans

A scan is one full pass of the assessment pipeline over an authorized domain: subdomain discovery, WAF detection, surface mapping, vulnerability scanning, then post-processing that scores risk, detects drift and builds the reports.

How to use it

  1. 01Scans → New Scan → pick a verified and authorized domain, and optionally a scan template.
  2. 02Follow the event timeline on the scan detail page while it runs; cancelling keeps the partial results.
  3. 03When it reaches done, review the discovered hosts, endpoints and findings.
  4. 04For continuous coverage, use Scans → Scheduled Scans with a cron expression and a timezone.

NoteIf a WAF is detected the scan profile automatically drops to stealth. Each scan has a one-hour execution cap, and your plan sets a monthly scan quota.

Findings

Findings are what a scan actually found — template matches plus heuristic signals such as exposed admin panels or forgotten endpoints. Each carries severity, evidence and a drift label showing whether it is new, changed, resolved or a regression.

How to use it

  1. 01Findings → filter by severity, domain or governance status.
  2. 02Open a finding for its evidence, the matched URL, host and path, and the remediation guidance.
  3. 03Set the governance status — open, in progress, false positive, accepted risk, resolved or reopened — with a note explaining why.
  4. 04Select checkboxes and use Bulk Actions when triaging many similar findings at once.

NoteAccepted risk requires an expiry date. Every transition, bulk ones included, is written to the audit trail with actor, timestamp and note.

Reports

Every completed scan produces two reports automatically: a PDF written to be read end to end, and a JSON carrying the same records in machine-parsable form.

How to use it

  1. 01Scan detail → Reports → Download PDF for stakeholders and clients.
  2. 02Download JSON to feed a SIEM, a ticketing pipeline or your own archive.
  3. 03The PDF covers the executive summary, scan metadata, risk breakdown, every finding with evidence and remediation, the discovered hosts and endpoints, and the scan scope.
  4. 04Share the file through whatever channel you already use — email, chat or a client portal.

NoteReports exist only for scans that reached done, and the download endpoints are authenticated.

Attack Orchestration

Orchestration takes a completed scan further. The AI reads its hosts, endpoints, technology stack and existing findings, ranks the penetration test types worth running and configures the tool arguments — you decide what actually executes.

How to use it

  1. 01From a completed scan click Launch Orchestration, or start a new session from Attack Orchestration.
  2. 02Get Suggestions: the AI returns a ranked list of test types — web app, API, cloud and others — each with its rationale.
  3. 03Select the test types you want, then Prepare to have the tool workflow built.
  4. 04Start the session and watch the live output; you can cancel at any point, and a report is generated per test type as its steps complete.

NoteA session always needs a completed scan behind it, and steps run one at a time — sessions with many tools take a while.

Integrations

Integrations push SilentBolt events out to the tools your team already watches. They are outbound only — SilentBolt sends, it does not pull data back.

How to use it

  1. 01Integrations → Add Integration → choose Microsoft Teams, Telegram, GitHub or Jira.
  2. 02Enter the provider credentials: a Teams incoming webhook URL, a Telegram bot token and chat ID, a GitHub token with repository scope, or a Jira URL, email, API token and project key.
  3. 03Subscribe the events you care about: scan completed, finding created, finding escalated.
  4. 04Run Test Connection, confirm the message arrived, then activate the integration.

NoteEach integration has its own dispatch log, so you can check whether an event actually left the platform.

Ready to run it against your own domain?

Start with a single verified domain. The first scan tells you more than any documentation page can.