Common workflows

Build an internet-facing inventory

  1. Create one group for the boundary you own.

  2. Add the root domains as seeds.

  3. Let recon enumerate subdomains and ports.

  4. Filter the group by HTTP status, screenshot, TLS, or open vulnerabilities.

  5. Pin the assets your team uses most often.

Create additional groups when the same asset needs to appear in another reporting or ownership boundary.

Test an authenticated web application

  1. Add the application hostname as a seed and run recon.

  2. Open the host and select the login-bearing service port, usually 443.

  3. Open Credentials and add a Form login credential with the fields used by the login form.

  4. Select Run Alkonos.

  5. Confirm the intended credential is selected before starting.

Use Auto-create a login account only when the application permits test-account registration and no saved credential exists for the target.

Scan the most important hosts in a large group

  1. Open the group and select Run all.

  2. Enter a value under Hosts to scan.

  3. Choose agents or leave the selection empty to run all enabled agents.

  4. Set a conservative rate limit for production systems.

  5. Start the run.

Alkonos selects the top hosts by relevance. Leave the count blank when every host should be scanned.

Add a repository and scan its default branch

  1. Connect GitHub under Settings → Integrations.

  2. Grant the Alkonos GitHub App access to the intended repositories.

  3. Open an asset group and select Add assets → Repository.

  4. Pick the repository and wait for branch indexing.

  5. Open the repository, select the default branch, and start a scan.

Use the Pull requests tab to launch a focused review of an indexed open PR.

Route high-signal events to Slack

  1. Connect Slack under Settings → Integrations.

  2. Open the Slack configuration drawer.

  3. Add a channel.

  4. Subscribe it only to the event types that channel should receive.

  5. Add separate routes when different teams need different events.

For a private Slack channel, invite the Alkonos bot to the channel before testing delivery.

Automate inventory and scanning with MCP

  1. Create an organization-scoped admin key under MCP & API Keys.

  2. Add the Alkonos MCP endpoint to your AI client.

  3. Ask the client to list groups or search assets first.

  4. Confirm the target IDs.

  5. Launch scans or update finding status with explicit IDs.

Use a read-only key for research and reporting workflows that must never mutate Alkonos.