Skip to content
English
  • There are no suggestions because the search field is empty.

Attaxion Quick Start Guide

Set up your attack surface monitoring, review discovered assets, prioritize vulnerabilities, and configure notifications and remediation workflows.

Attaxion is a cloud-based exposure management platform that discovers your organization’s Internet-facing assets and identifies their security vulnerabilities, giving you a complete picture of your attack surface.

To start using the platform, sign up for the free trial.

1. Start scanning your domain

After you sign up and verify your email address, Attaxion automatically identifies the domain from your email address and suggests adding it as a root asset.

Confirm the prompt to start scanning. Attaxion will use the domain to:

  • discover related child assets, such as subdomains, IP addresses, open ports, SSL certificates, and email addresses;
  • identify vulnerabilities and other security issues affecting those assets;
  • suggest other neighboring domains and IP addresses that may belong to you as root asset candidates that you may approve or reject.

Learn more about adding and scanning a root asset and the asset types Attaxion can discover.

2. Review your discovered assets

Attaxion will begin building a picture of your external attack surface as discovery and scanning progress. The time required and the number of assets found will depend on the size and complexity of your infrastructure — child assets usually start appearing in your discovered attack surface within hours, but it may take over a day to discover most of them.

Open the Assets tab to review everything Attaxion has discovered. You can filter and sort the inventory, check which root asset each item is associated with, review the issues affecting it, and open the asset details tab to see more information about the asset.

See The “Assets” Tab Explained and “Asset Details” View Explained help center articles to learn more about this part.

3. Expand your attack-surface coverage

Your email domain is only a starting point. Add other domains, IP addresses, cloud accounts, or other supported root-asset types that belong to your organization to improve coverage of your external attack surface.

Each additional root asset gives Attaxion another starting point from which to discover related infrastructure. This is particularly useful when your organization operates multiple brands, domains, networks, or cloud environments.

Learn how to add more root assets.

4. Review root asset candidates

While scanning your root assets, Attaxion may find neighboring domains or other assets that could also belong to your organization, but are not directly related to the root asset in question. These appear under Management → Root Asset Candidates.

Review each candidate and its discovery path, then:

  • approve it if it belongs to your organization and should become a root asset, so that Attaxion scans it regularly and discovers its child assets;
  • decline it if it is unrelated to your organization or should not be included.

Learn how to review, approve, and decline root asset candidates.

5. Remove irrelevant assets

Discovery may occasionally produce assets that do not belong to your organization or that you do not want included in your attack-surface inventory.

You can mark these assets as false positives. They and their child assets will be moved to Archived Assets, removed from the active asset list, and excluded from future vulnerability scans. You can restore them later if/when necessary.

Learn how to mark an asset as a false positive.

6. Review and prioritize vulnerabilities

As Attaxion scans your assets, detected vulnerabilities and other security findings appear in the Issues tab. You can start by reviewing critical and high-severity issues, the number of affected assets, and vulnerabilities known to be actively exploited.

Open an issue to review:

  • its severity and CVSS score;
  • affected assets;
  • available evidence and technical details;
  • CVE, CWE, CISA KEV, and EPSS information where applicable;
  • recommended remediation steps;
  • its current remediation status.

See The “Issues” Tab Explained and “Vulnerability Details” View Explained help center articles to learn more about handling issues in Attaxion.

To focus remediation efforts, learn how to prioritize vulnerabilities using CISA KEV and EPSS.

7. Enable continuous monitoring and notifications

Attaxion continuously monitors your external attack surface and notifies you when it discovers new security issues. You can receive notifications by email or connect Attaxion to Slack to get notifications there.

In your notification settings, you can choose the severity level for issues that should trigger alerts.

Learn how to connect Slack to Attaxion and configure notification settings for team members.

8. Remediate and track issues

After reviewing and prioritizing an issue, use the remediation guidance in the Vulnerability Details view to decide how it should be addressed. Update the issue’s status as remediation progresses so Attaxion accurately reflects your team’s work.

Connect Attaxion to Jira to enable one-click ticket creation directly from the Vulnerability Details view. This helps transfer the issue’s details into your existing remediation workflow without manually creating each ticket.

Learn how to connect Jira to Attaxion.

Read more about working with Attaxion and its additional features in the next section.