Getting started¶
1. Create an asset group¶
Open Assets.
Select New group.
Give the group a name that describes a real boundary, such as
Customer-facing edgeorProduction API.Add one or more seed domains or IP addresses.
Select Create group.
Seeds are optional. When you create a group with seeds, Alkonos starts recon automatically. A seed is a starting point for discovery, not a scan result.
2. Wait for recon¶
Recon normalizes the seed, enumerates related hosts for DNS seeds, resolves addresses, probes ports, and records HTTP, TLS, technology, screenshot, and URL observations when available.
New hosts join the group as they are discovered. Open the group to watch the inventory populate.
3. Run a scan¶
From the group page:
Select Run all to scan the group.
Open a host and select Run Alkonos to scan one discovered service port.
Select several rows and use Run scan for a bulk run.
A web scan targets a service port, not only a hostname. If a host has no discovered port, let recon finish before starting the scan.
4. Review findings¶
Open Vulnerabilities to filter findings by severity, status, weakness, scanner, or date. Open a finding for evidence, impact, reproduction steps, remediation, and the originating agent trace when available.
Use the status field to move work through Open, Confirmed, In progress, Resolved, Won’t fix, or False positive.
5. Connect your tools¶
Connect Slack to route selected events to channels.
Connect GitHub to onboard repositories and scan branches or pull requests.
Create an API key for GraphQL automation.
Connect an MCP client to operate Alkonos through natural-language requests.