Where everything
the agent finds lives.
The agent is how you talk to it. The platform is the system of record: findings, assets, scans, scores and compliance evidence persist here, across a dashboard and thirteen modules, and you can open any of it at any time.
13 modules · 4 built-in scanners · one conversation
[ dashboard ]
Dashboard
Thirteen widgets aggregate risk, vulnerability, endpoint and exposure metrics into one screen: counters for overdue and remediated findings, the top Kikimora Scores, findings by month, disconnected endpoints, the most critical and the most under-prioritized CVEs. Every widget has a View More that opens the module behind it, already filtered to what the widget was showing.
ask the agent
Martin Malinov
- Home
- Dashboard
Dashboard
| Vulnerability Name | CVE | Kikimora Score |
|---|---|---|
| Apache Log4j2 RCE (Log4Shell) | CVE-2021-44228 | 94.60 |
| Netlogon Elevation of Privilege (Zerologon) | CVE-2020-1472 | 92.10 |
| Citrix NetScaler session hijack (Citrix Bleed) | CVE-2023-4966 | 88.70 |
| Remote Desktop Services RCE (BlueKeep) | CVE-2019-0708 | 86.40 |
| Exchange Server SSRF (ProxyLogon) | CVE-2021-26855 | 84.10 |
| SQL Injection in Authentication Endpoint | – | 77.90 |
Total Vulnerabilities
3,218
| Endpoint Name | IP Address | Unapproved Software |
|---|---|---|
| db-prod-02.kikimora.internal | 10.0.0.22 | 318 |
| mail-gw.kikimora.internal | 172.16.0.5 | 258 |
| fileserver-01 | 192.168.10.30 | 208 |
Endpoints
| CVE | Avg. Kikimora Score | Affected Assets |
|---|---|---|
| CVE-2020-1472 | 92.10 | 1 |
| CVE-2021-44228 | 91.30 | 9 |
| CVE-2023-4966 | 88.70 | 2 |
| CVE-2019-0708 | 78.40 | 12 |
| CVE | Vulnerability | Kikimora Score | CVSS Score |
|---|---|---|---|
| CVE-2018-15473 | OpenSSH username enumeration | 57.00 | 5.3 |
| CVE-2022-22965 | Spring Framework RCE (Spring4Shell) | 68.40 | 6.1 |
| CVE-2023-38408 | OpenSSH ssh-agent RCE | 64.20 | 5.9 |
- 13 widgets
- Overdue vs new
- Most under-prioritized CVEs
[ vulnerabilities ]
Vulnerabilities
Every finding lands in one repository, whether a Qualys WAS scan, the endpoint agent, exposure discovery or a pentester found it, and a rescan updates the entry instead of duplicating it. Each finding carries a lifecycle (Open, In Progress, Closed, False-Positive), an owner, a Time to Resolve for SLA tracking, an activity log and a proof-of-concept viewer.
ask the agent
Martin Malinov
- Home
- Vulnerabilities
Vulnerabilities
Total Vulnerabilities
3,218
| Name | CVE | CVSS Score | Kikimora Score | Asset | Impact | Status | Owner | |
|---|---|---|---|---|---|---|---|---|
| Apache Log4j2 RCE (Log4Shell) | CVE-2021-44228 | 10.0 | 94.60 | host-003.kikimora.internal | Critical | Open | DP | |
| Netlogon Elevation of Privilege (Zerologon) | CVE-2020-1472 | 10.0 | 92.10 | dc-01.kikimora.internal | Critical | Open | MR | |
| Citrix NetScaler session hijack (Citrix Bleed) | CVE-2023-4966 | 9.4 | 88.70 | vpn.kikimora.io | Critical | In Progress | DP | |
| Remote Desktop Services RCE (BlueKeep) | CVE-2019-0708 | 9.8 | 86.40 | workstation-22.kikimora.internal | Critical | Open | AO | |
| Exchange Server SSRF (ProxyLogon) | CVE-2021-26855 | 9.8 | 84.10 | mail-gw.kikimora.internal | Critical | Open | MR | |
| SQL Injection in Authentication Endpoint | – | 8.8 | 77.90 | shop.kikimora.io | High | Open | DP |
- Open · In Progress · Closed · False-Positive
- Time to Resolve
- Activity log and PoC viewer
[ exposure ]
Exposure
Continuous discovery of the domains, hostnames and IP addresses tied to your organisation, through DNS and certificate data. Each asset records its open ports and service banners, and every CVE found on it carries an EPSS exploit probability. Shodan and the locally deployable Network Scanner are built in, and the whole view exports as a report.
ask the agent
Martin Malinov
- Home
- Exposure
Exposure
Assets
| Domain / Name | IP Address | Host Names | Ports | Vulnerabilities | EPSS Score | |
|---|---|---|---|---|---|---|
| shop.kikimora.io | 203.0.113.10 | cdn-edge-3.kikimora.io+1 more | 443808443 | 18 | 94% | |
| portal.kikimora.io | 203.0.113.11 | – | 4438080 | 15 | 91% | |
| api.kikimora.io | 203.0.113.12 | api-lb.kikimora.io | 4438443 | 11 | 77% | |
| vpn.kikimora.io | 203.0.113.14 | – | 4431194 | 8 | 88% | |
| mail.kikimora.io | 203.0.113.15 | mx1.kikimora.io+1 more | 25587993 | 5 | 41% | |
| admin.kikimora.io | 203.0.113.13 | – | 22443 | 0 | 0% |
- Ports and banners
- EPSS per CVE
- Download Report
[ infrastructure and endpoints ]
Infrastructure and endpoints
Infrastructure is the central inventory: every known asset, populated by exposure discovery, endpoint agents and integrations, with the criticality rating that feeds the Kikimora Score. Endpoints run the built-in agent (Wazuh under the hood) and report whether they are connected, plus their network interfaces, open ports, running processes, installed packages and policy checks.
ask the agent
Martin Malinov
- Home
- Endpoints
Endpoints
| Hostname | IP Address | Status | Risk Owner | Remediation Owner | ||
|---|---|---|---|---|---|---|
| web-prod-01.kikimora.internal | 10.0.0.11 | Connected | DP | AO | ||
| db-prod-02.kikimora.internal | 10.0.0.22 | Connected | DP | MR | ||
| mail-gw.kikimora.internal | 172.16.0.5 | Disconnected | MR | – | ||
| workstation-22 | 192.168.10.8 | Connected | AO | AO | ||
| fileserver-01 | 192.168.10.30 | Connected | MR | – | ||
| k8s-node-03.kikimora.internal | 10.0.1.33 | Disconnected | DP | – |
- Connected / Disconnected
- Networks · ports · processes · packages
- Asset criticality
[ scans and web applications ]
Scans and web applications
Qualys WAS web application scanning is built in, with no licence to buy. A web application entry defines the target URL, the crawl scope and the authentication record for logged-in scanning; a scheduled scan runs it Once, Daily, Weekly or Monthly, and every run keeps its own status, timings and findings.
ask the agent
Martin Malinov
- Home
- Scans
Scans
| Scan Name | Web Application | Status | Started | End Date | Vulnerabilities | |
|---|---|---|---|---|---|---|
| shop.kikimora.io Daily ScansSchedule | shop.kikimora.io | Scheduled at: 8/26/2026 | 8/26/2026, 02:00 UTC | – | 12 | |
| portal.kikimora.io Weekly ScansSchedule | portal.kikimora.io | Scheduled at: 8/29/2026 | 8/29/2026, 02:00 UTC | – | 15 | |
| api.kikimora.io On-demand Scan | api.kikimora.io | Finished | 8/25/2026, 09:14 | 8/25/2026, 10:02 | 11 | |
| shop.kikimora.io Release 4.2 Scan | shop.kikimora.io | Running | 8/25/2026, 10:20 | – | – | |
| admin.kikimora.io Authenticated Scan | admin.kikimora.io | Finished | 8/22/2026, 02:00 | 8/22/2026, 03:15 | 3 |
- Qualys WAS built in
- Once · Daily · Weekly · Monthly
- Authenticated scans
[ manual tests ]
Manual tests
One manual test per engagement, with OWASP-style checklists for Web, Android and iOS and a Pass, Failed or N/A verdict per check. Manual vulnerabilities carry their technical scope, owners and proof of concept, and flow into the same Vulnerabilities repository as scanner findings, so they are tracked, remediated and reported together.
ask the agent
Martin Malinov
- Home
- Manual Tests
- Details
- Checklist
Manual Test
Checklists
| Name | Platform | Category Name | Status | |
|---|---|---|---|---|
| Conduct Search Engine Discovery and Reconnaissance for Information Leakage | web | OTG-INFO-001 | Pass | |
| Fingerprint Web Server | web | OTG-INFO-002 | Pass | |
| Review Webserver Metafiles for Information Leakage | web | OTG-INFO-003 | Failed | |
| Enumerate Applications on Webserver | web | OTG-INFO-004 | Pass | |
| Review Webpage Comments and Metadata for Information Leakage | web | OTG-INFO-005 | N/A | |
| Identify application entry points | web | OTG-INFO-006 | none |
- OWASP checklists
- Web · Android · iOS
- Pass · Failed · N/A

