From target definition to actionable validation in a repeatable security workflow.
Silent Bolt turns fragmented security operations into a structured flow that discovery, analysis, and execution teams can run together.
STEP 01
Define and Authorize the Target
Add the domain you want assessed, prove that you own it, and have an admin authorize it. No scan runs against a domain that has not cleared both steps.
- +Ownership proven with a DNS TXT record or an email challenge
- +A separate admin authorization before the first scan
- +Environment and tags on the target so production and staging stay apart
STEP 02
Discovery
The scan starts by enumerating what actually exists under the domain, so it works from your real footprint instead of a list someone maintains by hand.
- +Subdomain enumeration from the base domain
- +DNS and TLS records for each candidate
- +Every discovered target recorded with the source it came from
STEP 03
WAF Detection and Pacing
Before any real load reaches the target, Silent Bolt probes for a web application firewall and decides how hard it is allowed to push.
- +Automatic stealth profile when a firewall answers
- +A fifth of the request rate and half the concurrency
- +Browser-like user agents and headers instead of scanner defaults
STEP 04
Surface Mapping
Live hosts, open ports and reachable endpoints are mapped into the attack surface that the rest of the scan works on.
- +HTTP probing for live hosts, status codes and TLS
- +Port scanning across the discovered hosts
- +Crawling for endpoints, with technology fingerprinting from responses and favicon hashes
STEP 05
Vulnerability Scanning and Risk
Templates and heuristics run against the mapped surface, and a deterministic risk engine scores what comes back against the previous scan.
- +Template-based vulnerability and misconfiguration detection
- +Risk score plus drift labels: new, changed, resolved, regression
- +PDF and JSON reports generated at the end of every completed scan
STEP 06
Attack Orchestration
On a completed scan, AI reads the hosts, endpoints, technology stack and findings, ranks the test types worth running and configures the tools — you approve what executes.
- +Ranked test-type suggestions, each with its rationale
- +Intrusive tools never run without explicit human approval
- +Live step output and a report per test type