For the complete documentation index, see llms.txt. This page is also available as Markdown.

Findings

Findings help you to identify, prioritize, and remediate network-validated attack-surface exposures.

What is Exposure Findings?

Vectra AI Exposure Findings helps security teams identify, prioritize, and reduce their organization’s attack surface by highlighting exposed assets, risky communications, and potential entry points attackers could exploit.

The problem it solves: the attack surface is always in motion. New assets, cloud workloads, AI agents, and unmanaged devices appear constantly, and risk can resurface between scan cycles — a device reconnects, a legacy protocol gets re-enabled, credentials move in cleartext. Traditional tools weren’t built for this. Vulnerability scanners focus on known, in-scope software; EDR focuses on managed endpoints. Neither gives a continuous view of what’s actually traversing the network. (Vectra’s 2026 State of Threat Exposure Management report found that 100% of analyzed environments had newly observed devices, and 98% contained at least one attacker-relevant exposure condition.)

How Exposure Findings approaches it: it identifies exposed attack paths from observed network behavior, not from a scan or a static inventory. By analyzing real communication — no agents, no scan windows — Vectra surfaces attacker-relevant conditions such as cleartext credentials, SMBv1 usage, weak TLS, or unmanaged devices communicating on the network. Every finding is network-validated, tied to the assets it affects, and enriched with remediation steps, compliance mapping, and investigation evidence.

The outcome: a continuous, evidence-based view of which exposed paths need attention first. Findings reactivate automatically if risk resurfaces and go inactive when the exposure quiets down, so teams can prove whether a remediation actually worked. The result is faster prioritization, a cleaner handoff to IT/infrastructure teams, and clearer evidence for security leaders, auditors, and the board.

Vectra doesn’t scan configurations, it observes live network metadata and behavior to find security gaps(e.g., a “Weak TLS Cipher” finding means Vectra saw that cipher actually being used, not just that the configuration allowed it).

Licensing

Exposure Findings is available exclusively on the Vectra AI Pro tier — it is not included in the Base tier.

  • Available only on the Vectra AI Platform.

    • Findings is only available in RUX deployments.

    • Quadrant UX deployments are not supported.

    • If you are unsure of your deployment type please see Analyst UX options (RUX vs QUX).

  • Requires a network metadata retention license of 14 days or longer.

  • Reach out to your accounts team to learn more https://www.vectra.ai/about/contact

How it works

  • Passive network data, not scans or agents: Findings are derived from observed network communication (metadata), not from active scanning or endpoint agents. This means Vectra sees what’s actually happening on the wire — including devices and traffic that scanners and EDR can’t reach (unmanaged, OT/IoT, agentless assets).

  • Always validating: Findings aren’t a one-time snapshot. Vectra continuously re-checks whether the underlying exposure condition is still present. A finding is marked Active while the behavior is still being observed, and Inactive once it’s no longer seen (mitigated or simply quiet). If the same exposure resurfaces later, the finding automatically flips back to Active — so teams get a live, self-correcting signal instead of a stale report.

  • Near real-time discovery: New findings are reported as they’re observed, typically under 30 mins of the underlying behavior occurring.

  • Enriched, not just flagged: Every finding is tied to the impacted asset(s) and comes with a severity score, remediation guidance, and compliance framework mapping, so analysts don’t have to research what a finding means before acting on it.

Types of Findings, remediation, compliance coverage, and widgets

Findings are grouped into categories such as Risky Protocols, Network Exposure, Sensitive Data Exposure, and Cryptographic Hygiene (see the full table in List of Finding Types).

Expanding any finding type surfaces: Details — what was observed and why it matters. Remediation — recommended steps to close the exposure. Compliance mapping — the relevant CIS Controls, NIST CSF, PCI-DSS, and ISO 27001 references, so teams can tie remediation work directly to audit and compliance requirements.

At the top of the Findings page, three widgets give an at-a-glance view of posture:

Widget
What it shows

Active Open Findings

Total count of active findings currently awaiting review.

Active and Monitored

Total count of active findings currently being tracked/investigated by the team.

Inactive and Remediated

Findings for which no related behavior has been observed in the last 14 days or have been remediated.

Getting Started with a Finding

Quick start (≈10 minutes to first value):

  1. Go to Exposure → Findings (generic portal link — resolves to your tenant).

  2. Filter: Status = Active, Score = High.

  3. Review the top 5 findings — expand each to see details and impacted assets.

  4. Take action — set a Review State (e.g.In Progress, or Risk Accept).

That alone gives immediate visibility into your highest-risk exposures. The fuller workflow below goes step by step.

Widgets

Start at the top of the page with the three widgets (Active Open, Active and In Progress, Inactive and Remediated) — see Types of Findings, remediation, compliance coverage, and widgets) to understand overall posture: what’s outstanding, what’s already being worked, and what’s been resolved.

High-severity findings

Use the filter bar to narrow to Status = Active and Finding Score = High. This surfaces the riskiest, currently-observed exposures first.

Each row in the findings table includes:

Column
What it means

Finding Type / Category

The specific exposure (e.g., Exposed RDP, Weak TLS Cipher) and its category (Network Exposure, Risky Protocol, etc.).

Findings Score

Vectra assigned severity: High, Medium, or Low.

Number of Assets

How many hosts/entities are currently affected by this finding type — a quick sense of blast radius.

Status

Active (behavior still observed) or Inactive (mitigated or no longer seen).

Review State

Where the finding sits in your team’s triage workflow.

Filter and sort on any of these to build your own working queue (e.g., “everything High and Active”).

Review a Finding Type

Expand a finding type to see: Full details of what was detected and why it’s a risk. Remediation guidance — concrete steps to close the exposure. Compliance mapping to CIS Controls, NIST CSF, PCI-DSS and ISO 27001. The context panel, which lists impacted assets and the exposure path.

Review the actual traffic

From a finding, use the Investigate pivot to jump directly into the underlying network evidence — no manual query-building required. Vectra generates the relevant query automatically and opens it in Advanced Search/Investigate, showing the actual session(s) where the exposure condition was observed (e.g., the specific HTTP session where a cleartext password appeared).

Review assets impacted

From the context panel, drill into the assets tied to a finding to see: Asset context — device type, groups, EDR presence, etc. Importance — how critical the asset is to the business. Urgency score — Vectra AI’s read on how urgently this asset needs attention. Groups the asset belongs to.

This is what lets you prioritize, e.g., a Medium finding on a crown-jewel server over a High finding on a low-importance device.

Go to the asset and review threat + exposure context together - *coming soon

Open the asset page to see full asset details and threat context in one place. Detections (active threat behavior) and Findings (exposure/posture) are brought together on the asset, so an analyst can immediately see both “is this under active attack” and “is this exposed” — and prioritize accordingly, rather than having to cross-reference two separate tools.

Dig into the specific host session (Host Investigation pivot)

From the asset/host view, pivot into Investigate scoped to that specific host to see the exact session/traffic window where the finding was observed — useful when you need forensic-level detail on one host rather than the finding-type-wide view.

Select Review State

Set a Review State on a finding (per affected entity) to track it through your triage process:

Review State
Meaning

Open

Default state for every newly discovered finding.

In Progress

Currently being investigated/worked.

Risk Accepted

Known and expected in your environment. Vectra AI stops surfacing this specific finding going forward.

Remediated

Select this state after the risk has been mitigated.

Review state is retained until manually changed, so the whole team can see what’s already been triaged.

Come back and review Risk-Accepted findings

Risk-accepted findings are hidden from the default view by design (to cut noise) but aren’t deleted — filter Review State = Risk Accepted any time to audit what’s been accepted, confirm it’s still valid, or catch anything that should be re-opened. You can go back until 90 days and view the Findings after which it's purged.

List of Finding Types

Finding Type
Description
Category
CIS v8.1
NIST CSF 2.0
ISO 27001:2022
PCI-DSS v4.0.1

Passwords in Cleartext over HTTP

Cleartext credentials detected in network traffic.

Sensitive Data Exposure

3.10

PR.DS-02

A.8.5

8.3.2

Credential File in SMB

Credential file discovered on an SMB share.

Sensitive Data Exposure

3.11

PR.DS-01

A.8.24

8.3.2

Internal MCP over HTTP

Internal MCP (Model Context Protocol) traffic observed over unencrypted HTTP.

Sensitive Data Exposure

3.10

PR.DS-02

A.8.5

8.3.2

Certificate Expired

One or more certificates have expired.

Cryptographic Hygiene

3.10

PR.DS-02

A.8.24

4.2.1

Certificate Expiring (< 60 days)

Certificate(s) approaching expiration within 60 days.

Cryptographic Hygiene

3.10

PR.DS-02

A.8.24

4.2.1

Weak TLS Cipher

TLS session observed using an outdated or weak cipher.

Cryptographic Hygiene

3.10

PR.DS-02

A.8.24

4.2.1

Deprecated TLS Version — Server

Server-side TLS session using a deprecated TLS version.

Risky Protocol

3.10

PR.DS-02

A.8.24

4.2.1

Deprecated TLS Version — Client

Client-side TLS session using a deprecated TLS version.

Risky Protocol

3.10

PR.DS-02

A.8.24

4.2.1

Dangerous SSL Version — Client

Client using a dangerously outdated SSL version.

Risky Protocol

3.10

PR.DS-02

A.8.24

4.2.1

Dangerous SSL Version — Server

Server using a dangerously outdated SSL version.

Risky Protocol

3.10

PR.DS-02

A.8.24

4.2.1

SMBv1 Client

Device acting as a client over deprecated SMBv1.

Risky Protocol

4.8

PR.PS-01

A.8.20

2.2.4

SMBv1 Server

Device acting as a server over deprecated SMBv1.

Risky Protocol

4.8

PR.PS-01

A.8.20

2.2.4

NetBIOS Usage

Legacy NetBIOS name resolution in use.

Risky Protocol

4.8

PR.PS-01

A.8.20

2.2.4

LLMNR Usage

Legacy LLMNR name resolution in use.

Risky Protocol

4.8

PR.PS-01

A.8.20

2.2.4

IPMI Usage

Open IPMI management protocol detected.

Risky Protocol

4.8

PR.PS-01

A.8.20

2.2.4

FTP Usage

Cleartext FTP traffic/credentials observed.

Risky Protocol

3.10

PR.DS-02

A.8.5

4.2.1

Telnet Usage

Cleartext Telnet traffic/credentials observed.

Risky Protocol

3.10

PR.DS-02

A.8.5

2.2.7

Exposed Telnet

Device exposing Telnet externally.

Network Exposure

13.4

PR.IR-01

A.8.22

1.4.2

Exposed RDP

Device exposing RDP externally.

Network Exposure

13.4

PR.IR-01

A.8.22

1.4.2

Exposed SMB

Device exposing SMB externally.

Network Exposure

13.4

PR.IR-01

A.8.22

1.4.2

REST API

Public Rest API documentation

Investigation use cases

Use case 1 — Reducing external attack surface (Exposed RDP)

Filter Findings to Status = Active, Score = High, and look for Exposed RDP/SMB/Telnet. For each hit, check the impacted asset’s Importance and Urgency score to see whether it’s internet-facing and business-critical. Use the Investigation pivot to confirm the actual exposed session/traffic, then work with IT to validate whether external access is actually needed — if not, restrict it and set the finding’s Review State so the team can track it through to Resolved.

Use case 2 — Chasing down cleartext credentials in HTTP traffic

A “Passwords in Cleartext over HTTP” finding surfaces on a host. Expand the finding to see remediation guidance and compliance mapping (relevant for audit evidence), then use the Investigation pivot to jump straight to the specific HTTP session where the credential appeared — no manual query needed. From there, check the asset page to see whether the same host has related Detections, so you know whether this is an isolated hygiene issue or part of active malicious activity.

Frequently Asked Questions (FAQ)

Can I integrate this into my existing workflows?

  • Yes — the public REST API (see REST API) is built for this, including SIEM/SOAR integration via polling.

Does this replace vulnerability scanning?

  • No. Vectra AI uses network metadata to understand actual traffic behavior and surface security gaps — it’s a different, complementary lens to scan-based tools.

How often should I review Findings?

  • Vectra AI continuously monitors for new findings; check daily for new High-severity findings.

What license do I need?

  • Vectra AI Pro tier, with at least a 14-day metadata retention license (see Licensing).

Last updated

Was this helpful?