> For the complete documentation index, see [llms.txt](https://docs.vectra.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.vectra.ai/operations/exposure/findings.md).

# Findings

## What is Exposure Findings?

Vectra AI Exposure Findings helps security teams identify, prioritize, and reduce their organization’s attack surface by highlighting exposed assets, risky communications, and potential entry points attackers could exploit.

**The problem it solves:** the attack surface is always in motion. New assets, cloud workloads, AI agents, and unmanaged devices appear constantly, and risk can resurface between scan cycles — a device reconnects, a legacy protocol gets re-enabled, credentials move in cleartext. Traditional tools weren’t built for this. Vulnerability scanners focus on known, in-scope software; EDR focuses on managed endpoints. Neither gives a continuous view of what’s actually traversing the network. (Vectra’s 2026 State of Threat Exposure Management [report](https://cdn.prod.website-files.com/64e50cbe2b6f932c04238c14/6a4b76d1b6065a6e6d1055b3_V_2026-State-of-Threat-Exposure-Management_070126_FNL_compressed.pdf) found that 100% of analyzed environments had newly observed devices, and 98% contained at least one attacker-relevant exposure condition.)

**How Exposure Findings approaches it:** it identifies exposed attack paths from observed network behavior, not from a scan or a static inventory. By analyzing real communication — no agents, no scan windows — Vectra surfaces attacker-relevant conditions such as cleartext credentials, SMBv1 usage, weak TLS, or unmanaged devices communicating on the network. Every finding is network-validated, tied to the assets it affects, and enriched with remediation steps, compliance mapping, and investigation evidence.

**The outcome:** a continuous, evidence-based view of which exposed paths need attention first. Findings reactivate automatically if risk resurfaces and go inactive when the exposure quiets down, so teams can prove whether a remediation actually worked. The result is faster prioritization, a cleaner handoff to IT/infrastructure teams, and clearer evidence for security leaders, auditors, and the board.

Vectra doesn’t scan configurations, it observes live network metadata and behavior to find security gaps(e.g., a “Weak TLS Cipher” finding means Vectra saw that cipher actually being used, not just that the configuration allowed it).

## Licensing

Exposure Findings is available exclusively on the **Vectra AI Pro tier** — it is not included in the Base tier.

* Available only on the Vectra AI Platform.
  * Findings is only available in RUX deployments.
  * Quadrant UX deployments are not supported.
  * If you are unsure of your deployment type please see [Analyst UX options (RUX vs QUX)](/deployment/getting-started/analyst-ux-options-rux-vs-qux.md).
* Requires a network metadata retention license of **14 days or longer**.
* Reach out to your accounts team to learn more <https://www.vectra.ai/about/contact>

## How it works

* **Passive network data, not scans or agents:** Findings are derived from observed network communication (metadata), not from active scanning or endpoint agents. This means Vectra sees what’s actually happening on the wire — including devices and traffic that scanners and EDR can’t reach (unmanaged, OT/IoT, agentless assets).
* **Always validating:** Findings aren’t a one-time snapshot. Vectra continuously re-checks whether the underlying exposure condition is still present. A finding is marked **Active** while the behavior is still being observed, and **Inactive** once it’s no longer seen (mitigated or simply quiet). If the same exposure resurfaces later, the finding automatically flips back to Active — so teams get a live, self-correcting signal instead of a stale report.
* **Near real-time discovery:** New findings are reported as they’re observed, typically under 30 mins of the underlying behavior occurring.
* **Enriched, not just flagged:** Every finding is tied to the impacted asset(s) and comes with a severity score, remediation guidance, and compliance framework mapping, so analysts don’t have to research what a finding means before acting on it.

## Types of Findings, remediation, compliance coverage, and widgets

Findings are grouped into categories such as **Risky Protocols**, **Network Exposure**, **Sensitive Data Exposure**, and **Cryptographic Hygiene** (see the full table in [List of Finding Types](#list-of-finding-types)).

Expanding any finding type surfaces: **Details** — what was observed and why it matters. **Remediation** — recommended steps to close the exposure. **Compliance mapping** — the relevant CIS Controls, NIST CSF, PCI-DSS, and ISO 27001 references, so teams can tie remediation work directly to audit and compliance requirements.

At the top of the Findings page, three widgets give an at-a-glance view of posture:

| Widget                      | What it shows                                                                                         |
| --------------------------- | ----------------------------------------------------------------------------------------------------- |
| **Active Open Findings**    | Total count of active findings currently awaiting review.                                             |
| **Active and Monitored**    | Total count of active findings currently being tracked/investigated by the team.                      |
| **Inactive and Remediated** | Findings for which no related behavior has been observed in the last 14 days or have been remediated. |

## Getting Started with a Finding

**Quick start (≈10 minutes to first value):**

1. Go to **Exposure → Findings** ([generic portal link](http://portal.vectra.ai/exposure) — resolves to your tenant).
2. Filter: **Status = Active**, **Score = High**.
3. Review the top 5 findings — expand each to see details and impacted assets.
4. Take action — set a **Review State** (e.g.In Progress, or Risk Accept).

That alone gives immediate visibility into your highest-risk exposures. The fuller workflow below goes step by step.

### Widgets

Start at the top of the page with the three widgets (Active Open, Active and In Progress, Inactive and Remediated) — see [#types-of-findings-remediation-compliance-coverage-and-widgets](#types-of-findings-remediation-compliance-coverage-and-widgets "mention")) to understand overall posture: what’s outstanding, what’s already being worked, and what’s been resolved.

### High-severity findings

Use the filter bar to narrow to **Status = Active** and **Finding Score = High**. This surfaces the riskiest, currently-observed exposures first.

Each row in the findings table includes:

| Column                      | What it means                                                                                                         |
| --------------------------- | --------------------------------------------------------------------------------------------------------------------- |
| **Finding Type / Category** | The specific exposure (e.g., Exposed RDP, Weak TLS Cipher) and its category (Network Exposure, Risky Protocol, etc.). |
| **Findings Score**          | Vectra assigned severity: **High**, **Medium**, or **Low**.                                                           |
| **Number of Assets**        | How many hosts/entities are currently affected by this finding type — a quick sense of blast radius.                  |
| **Status**                  | **Active** (behavior still observed) or **Inactive** (mitigated or no longer seen).                                   |
| **Review State**            | Where the finding sits in your team’s triage workflow.                                                                |

Filter and sort on any of these to build your own working queue (e.g., “everything High and Active”).

### Review a Finding Type

Expand a finding type to see: Full **details** of what was detected and why it’s a risk. **Remediation** guidance — concrete steps to close the exposure. **Compliance** mapping to CIS Controls, NIST CSF, PCI-DSS and ISO 27001. The **context panel**, which lists impacted assets and the exposure path.

### Review the actual traffic

From a finding, use the **Investigate pivot** to jump directly into the underlying network evidence — no manual query-building required. Vectra generates the relevant query automatically and opens it in Advanced Search/Investigate, showing the actual session(s) where the exposure condition was observed (e.g., the specific HTTP session where a cleartext password appeared).

### Review assets impacted

From the context panel, drill into the assets tied to a finding to see: **Asset context** — device type, groups, EDR presence, etc. **Importance** — how critical the asset is to the business. **Urgency score** — Vectra AI’s read on how urgently this asset needs attention. **Groups** the asset belongs to.

This is what lets you prioritize, e.g., a Medium finding on a crown-jewel server over a High finding on a low-importance device.

### Go to the asset and review threat + exposure context together - \*coming soon

Open the asset page to see full asset details and threat context in one place. Detections (active threat behavior) and Findings (exposure/posture) are brought together on the asset, so an analyst can immediately see both “is this under active attack” and “is this exposed” — and prioritize accordingly, rather than having to cross-reference two separate tools.

### Dig into the specific host session (Host Investigation pivot)

From the asset/host view, pivot into Investigate scoped to that specific host to see the exact session/traffic window where the finding was observed — useful when you need forensic-level detail on one host rather than the finding-type-wide view.

### Select Review State

Set a **Review State** on a finding (per affected entity) to track it through your triage process:

| Review State      | Meaning                                                                                                |
| ----------------- | ------------------------------------------------------------------------------------------------------ |
| **Open**          | Default state for every newly discovered finding.                                                      |
| **In Progress**   | Currently being investigated/worked.                                                                   |
| **Risk Accepted** | Known and expected in your environment. Vectra AI stops surfacing this specific finding going forward. |
| **Remediated**    | Select this state after the risk has been mitigated.                                                   |

Review state is retained until manually changed, so the whole team can see what’s already been triaged.

### Come back and review Risk-Accepted findings

Risk-accepted findings are hidden from the default view by design (to cut noise) but aren’t deleted — filter **Review State = Risk Accepted** any time to audit what’s been accepted, confirm it’s still valid, or catch anything that should be re-opened. You can go back until 90 days and view the Findings after which it's purged.

## List of Finding Types

<table><thead><tr><th>Finding Type</th><th>Description</th><th>Category</th><th width="127.578125">CIS v8.1</th><th>NIST CSF 2.0</th><th>ISO 27001:2022</th><th>PCI-DSS v4.0.1</th></tr></thead><tbody><tr><td>Passwords in Cleartext over HTTP</td><td>Cleartext credentials detected in network traffic.</td><td>Sensitive Data Exposure</td><td>3.10</td><td>PR.DS-02</td><td>A.8.5</td><td>8.3.2</td></tr><tr><td>Credential File in SMB</td><td>Credential file discovered on an SMB share.</td><td>Sensitive Data Exposure</td><td>3.11</td><td>PR.DS-01</td><td>A.8.24</td><td>8.3.2</td></tr><tr><td>Internal MCP over HTTP</td><td>Internal MCP (Model Context Protocol) traffic observed over unencrypted HTTP.</td><td>Sensitive Data Exposure</td><td>3.10</td><td>PR.DS-02</td><td>A.8.5</td><td>8.3.2</td></tr><tr><td>Certificate Expired</td><td>One or more certificates have expired.</td><td>Cryptographic Hygiene</td><td>3.10</td><td>PR.DS-02</td><td>A.8.24</td><td>4.2.1</td></tr><tr><td>Certificate Expiring (&#x3C; 60 days)</td><td>Certificate(s) approaching expiration within 60 days.</td><td>Cryptographic Hygiene</td><td>3.10</td><td>PR.DS-02</td><td>A.8.24</td><td>4.2.1</td></tr><tr><td>Weak TLS Cipher</td><td>TLS session observed using an outdated or weak cipher.</td><td>Cryptographic Hygiene</td><td>3.10</td><td>PR.DS-02</td><td>A.8.24</td><td>4.2.1</td></tr><tr><td>Deprecated TLS Version — Server</td><td>Server-side TLS session using a deprecated TLS version.</td><td>Risky Protocol</td><td>3.10</td><td>PR.DS-02</td><td>A.8.24</td><td>4.2.1</td></tr><tr><td>Deprecated TLS Version — Client</td><td>Client-side TLS session using a deprecated TLS version.</td><td>Risky Protocol</td><td>3.10</td><td>PR.DS-02</td><td>A.8.24</td><td>4.2.1</td></tr><tr><td>Dangerous SSL Version — Client</td><td>Client using a dangerously outdated SSL version.</td><td>Risky Protocol</td><td>3.10</td><td>PR.DS-02</td><td>A.8.24</td><td>4.2.1</td></tr><tr><td>Dangerous SSL Version — Server</td><td>Server using a dangerously outdated SSL version.</td><td>Risky Protocol</td><td>3.10</td><td>PR.DS-02</td><td>A.8.24</td><td>4.2.1</td></tr><tr><td>SMBv1 Client</td><td>Device acting as a client over deprecated SMBv1.</td><td>Risky Protocol</td><td>4.8</td><td>PR.PS-01</td><td>A.8.20</td><td>2.2.4</td></tr><tr><td>SMBv1 Server</td><td>Device acting as a server over deprecated SMBv1.</td><td>Risky Protocol</td><td>4.8</td><td>PR.PS-01</td><td>A.8.20</td><td>2.2.4</td></tr><tr><td>NetBIOS Usage</td><td>Legacy NetBIOS name resolution in use.</td><td>Risky Protocol</td><td>4.8</td><td>PR.PS-01</td><td>A.8.20</td><td>2.2.4</td></tr><tr><td>LLMNR Usage</td><td>Legacy LLMNR name resolution in use.</td><td>Risky Protocol</td><td>4.8</td><td>PR.PS-01</td><td>A.8.20</td><td>2.2.4</td></tr><tr><td>IPMI Usage</td><td>Open IPMI management protocol detected.</td><td>Risky Protocol</td><td>4.8</td><td>PR.PS-01</td><td>A.8.20</td><td>2.2.4</td></tr><tr><td>FTP Usage</td><td>Cleartext FTP traffic/credentials observed.</td><td>Risky Protocol</td><td>3.10</td><td>PR.DS-02</td><td>A.8.5</td><td>4.2.1</td></tr><tr><td>Telnet Usage</td><td>Cleartext Telnet traffic/credentials observed.</td><td>Risky Protocol</td><td>3.10</td><td>PR.DS-02</td><td>A.8.5</td><td>2.2.7</td></tr><tr><td>Exposed Telnet</td><td>Device exposing Telnet externally.</td><td>Network Exposure</td><td>13.4</td><td>PR.IR-01</td><td>A.8.22</td><td>1.4.2</td></tr><tr><td>Exposed RDP</td><td>Device exposing RDP externally.</td><td>Network Exposure</td><td>13.4</td><td>PR.IR-01</td><td>A.8.22</td><td>1.4.2</td></tr><tr><td>Exposed SMB</td><td>Device exposing SMB externally.</td><td>Network Exposure</td><td>13.4</td><td>PR.IR-01</td><td>A.8.22</td><td>1.4.2</td></tr></tbody></table>

## REST API

#### Public Rest API documentation

<https://apidocs.vectra.ai/api/v-3-5-findings>

## Investigation use cases

**Use case 1 — Reducing external attack surface (Exposed RDP)**

Filter Findings to **Status = Active, Score = High**, and look for Exposed RDP/SMB/Telnet. For each hit, check the impacted asset’s Importance and Urgency score to see whether it’s internet-facing and business-critical. Use the Investigation pivot to confirm the actual exposed session/traffic, then work with IT to validate whether external access is actually needed — if not, restrict it and set the finding’s Review State so the team can track it through to Resolved.

**Use case 2 — Chasing down cleartext credentials in HTTP traffic**

A “Passwords in Cleartext over HTTP” finding surfaces on a host. Expand the finding to see remediation guidance and compliance mapping (relevant for audit evidence), then use the Investigation pivot to jump straight to the specific HTTP session where the credential appeared — no manual query needed. From there, check the asset page to see whether the same host has related Detections, so you know whether this is an isolated hygiene issue or part of active malicious activity.

## Frequently Asked Questions (FAQ)

**Can I integrate this into my existing workflows?**

* Yes — the public REST API (see [#rest-api](#rest-api "mention")) is built for this, including SIEM/SOAR integration via polling.

**Does this replace vulnerability scanning?**

* No. Vectra AI uses network metadata to understand actual traffic behavior and surface security gaps — it’s a different, complementary lens to scan-based tools.

**How often should I review Findings?**

* Vectra AI continuously monitors for new findings; check daily for new High-severity findings.

**What license do I need?**

* Vectra AI Pro tier, with at least a 14-day metadata retention license (see [#licensing](#licensing "mention")).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.vectra.ai/operations/exposure/findings.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
