Beyond detection
Finding issues is table stakes. heimdallX proves what's exploitable, emulates the adversary, watches your surface around the clock, and ships the controls enterprises require. Explore each capability below.
Exploitability Validation Core
Stop chasing severity. Rank by what's actually exploitable — EPSS probability, CISA KEV, and proven reachability.
- EPSS exploit-probability weighting
- CISA KEV known-exploited priority floor
- Version-aware CVE matching — zero invented CVEs
Proof-based Active Testing
Confirm vulnerabilities by safely triggering them — reflected XSS, error-based SQLi and open redirects, proven not guessed.
- Consent-gated, non-destructive GET probes
- Reflected-XSS, error-SQLi & open-redirect proof
- Same-origin, rate-limited, self-identifying agent
Attack Simulation & MITRE ATT&CK
See findings the way an adversary chains them — mapped to MITRE ATT&CK tactics and techniques.
- MITRE ATT&CK coverage matrix
- Tactic → technique mapping per scenario
- Severity-weighted kill-chain view
Continuous Attack-Surface Discovery
Watch your external footprint change over time — new hosts, shadow IT and disappearing assets, run after run.
- Snapshot + delta across every run
- New / gone host detection
- Shadow-IT (risky new host) flagging
Software Composition Analysis
Find vulnerable dependencies — most of your risk lives in code you didn't write.
- npm + PyPI manifest parsing
- OSV-backed vulnerability matching
- SBOM inventory · CVEs flow to Validation Core
Live Threat Intelligence
Know what's being exploited in the wild today — KEV, EPSS and emerging-exploit signals wired straight into your queue.
- Daily CISA KEV & EPSS feed sync
- Emerging-exploit & public-PoC alerts
- Auto re-prioritizes findings as threats move
External Threats & Digital Risk Protection
Watch the outside-in too — leaked credentials, dark-web & Telegram chatter, malware/C2 IOCs, ransomware victim posts and look-alike domains, all correlated to your assets and ranked by TALON.
- Leaks, dark web, ransomware, brand-abuse & IOCs in one feed
- TALON composite scoring + ATOM account-takeover chains
- AI briefing & threat-knowledge graph, gated to Pro / Business
Attack-Surface Graph
See your whole external footprint as one living graph — assets, services, exposures and how an attacker pivots between them.
- Live asset ↔ service ↔ exposure graph
- Shortest attacker path to crown-jewel assets
- Blast-radius view for every finding
Attack-Path & Breach Simulation
Chain individual findings into end-to-end attack paths — see how a breach actually unfolds, before it does.
- Multi-step exploit-chain construction
- Likelihood-weighted breach scenarios
- Mapped to MITRE ATT&CK stages
Cloud Security Posture (CSPM)
Catch the cloud misconfigurations attackers love — public buckets, open ports, over-broad IAM — mapped to the same fix-first queue.
- Public storage & exposed-service checks
- Over-permissive IAM & policy findings
- CIS-benchmark aligned, one unified queue
Continuous Monitoring & Alerting
Set it and stay covered — scheduled re-scans, drift detection and alerts the moment your exposure changes.
- Scheduled re-scans & DRP collection
- Change/drift alerts on new exposure
- Routed to Slack, webhook or email
SOC Console & Telemetry Ingestion
Ship your cloud, identity and VCS logs in — heimdallX normalises them, runs detections, and turns each one into an incident an analyst can work to closure.
- Metered log ingestion with an API key — cloud audit, identity, VCS, syslog
- Sigma-compatible detections mapped to MITRE ATT&CK
- AI triage, MTTA / MTTR targets and suppression rules
CI Gate, SARIF & Public API
Run heimdallX from your pipeline: a scan per build, SARIF into code scanning, an SBOM per release — and a gate that breaks the build only on what was demonstrated.
- Per-workspace CI keys, reference GitHub / GitLab workflows
- SARIF 2.1.0 + CycloneDX SBOM per scan
- Gate on the proven tier only — never on a model's guess
AI Security Analyst
An AI analyst on every finding — it explains the risk, drafts the fix, and answers 'so what?' in plain language.
- Plain-language 'why it matters' per finding
- One-click PR-ready fix prompts
- Ask-anything copilot over your posture
Executive & Board Reporting
Turn technical findings into a board-ready story — posture, business risk and a dated remediation roadmap, one click to PDF.
- Auto-generated executive brief
- 0–30 / 30–60 / 60–90-day roadmap
- One-click PDF / CSV export
Integrations & Workflow
heimdallX fits your stack — Slack, webhooks, SIEM and ticketing — with an API and audit trail behind every action.
- Slack, webhook & email alert routing
- SIEM / ticketing export via API
- Append-only audit log on every action
AI Remediation & Fix
Every finding ships with a clear, PR-ready fix — and a one-click prompt your AI coding agent can apply.
- Per-finding fix steps & config snippets
- Copy-ready Claude Code fix prompt
- Owner routing in fix-first order
Continuous Compliance Evidence
Map every finding to the frameworks auditors ask about — with a timestamped evidence trail.
- OWASP · PCI-DSS · ISO 27001 · SOC 2 · CIS · NIST CSF · GDPR · HIPAA · EU AI Act mapping
- Per-control "last checked" freshness
- Timestamped evidence trail
AI Cost Governance & FinOps
Run AI-driven security at scale without runaway bills — per-workspace token tracking, hard budget caps and an admin operations console.
- Per-workspace AI token & cost tracking
- Hard budget caps, enforced not just alerted
- Admin operations console + audit trail
Enterprise Controls
SSO, SCIM, granular roles and an append-only audit log — the controls security teams must have.
- SAML SSO on every plan · SCIM on Business
- Granular RBAC (owner / admin / analyst / viewer)
- Append-only audit log + team workspaces
See what attackers see — before they do
Run your first scan in under two minutes. Free, no credit card, real findings.
Launch heimdallX