Product · Findings & Evidence

Every finding includes
the proof behind it.

Hayrok findings are not based solely on scanner output, severity scores, or theoretical relationships. Every confirmed finding is supported by evidence collected during the validation workflow.

One Place

Unified
findings.

One place brings together confirmed results across objectives, environments, assets, and validation methods—filterable across every dimension that matters to triage.

Filter By

SeverityValidation statusObjectiveMethodAssetEnvironmentBusiness serviceCrown jewelControl responseDetection responseOwnerSLA statusRevalidation stateEvidence confidence

The finding, at a glance

Every finding shows:

TitleSeverityValidation resultConfidenceBusiness impactAffected assetsObjectiveScenarioValidation methodsFirst observedLast validatedOwnerSLAStatus

Mode-level evidence

A finding can contain evidence from multiple validation methods—showing which were attempted, confirmed, or inconclusive.

Exposure
Control
Detection
Runtime presence
Reachability analysis
Attack path simulation
Autonomous penetration testing

The Proof

Evidence types
within a finding.

Attack path

What it establishes

Entry point, affected asset, required conditions, identity transitions, runtime dependencies, reachability, control-interruption points, detection visibility, crown-jewel destination, business impact.

Control

What it establishes

Control name/type, expected vs. observed behavior, allow/block result, policy response, enforcement point, timestamp, relevant logs, compensating controls, and failure explanation.

Detection

What it establishes

Source, rule/analytic, event and alert timestamps, latency, severity, correlated telemetry, ATT&CK technique, detection status, missing telemetry, recommended improvement.

Business impact

What it establishes

Sensitive-data exposure, revenue interruption, customer impact, availability, regulatory obligations, ransomware blast radius, privileged access, critical-asset reachability, operational dependencies.

Remediation

What it establishes

Recommended fix, priority, suggested owner, affected component, control and detection improvements, temporary mitigation, validation prerequisites, references, expected risk reduction.

Close the Loop

Revalidation.

Initiate revalidation from the finding drawer. The view compares original evidence, remediation summary, new evidence, control changes, detection changes, attack-path changes, and residual risk—reaching a final status.

A finding is not considered verified until the relevant scenario has been rerun successfully.

Evidence vs. Score

Why proof-per-finding
matters.

Severity scores ask reviewers to trust an abstraction. Attaching the request/response, control behavior, detection result, runtime confirmation, and attack-path context to each finding lets engineers, owners, and auditors judge the risk from the actual evidence.

Decisions on Facts

“Settle remediation debates with facts—not severity scores.”

Engineers, owners, and auditors judge from the same evidence.

FAQ

Frequently asked
questions.

What makes a Hayrok finding different?

It's confirmed by evidence collected during validation, not by severity scores or theoretical relationships alone.

Where do I manage findings?

In a unified view filterable by severity, status, objective, method, asset, environment, business service, crown jewel, control/detection response, owner, SLA, revalidation, and evidence confidence.

What does a finding show?

Title, severity, validation result, confidence, business impact, affected assets, objective, scenario, methods, timing, owner, SLA, and status.

What evidence types are included?

Mode-level, control, detection, runtime, attack-path, and business-impact evidence, plus remediation guidance.

How is control effectiveness shown?

Control evidence records expected vs. observed behavior, allow/block, enforcement point, logs, and failure explanation.

How is detection shown?

Detection evidence includes source, rule, timestamps, latency, ATT&CK technique, status, and missing-telemetry notes.

How do I remediate?

Each finding includes a recommended fix, priority, owner, mitigations, prerequisites, references, and expected risk reduction.

When is a finding "verified"?

Only after successful revalidation of the relevant scenario.

Can I see how a finding fits an attack path?

Yes—attack-path evidence links the finding to progression toward crown jewels.

Keep Exploring

Connected to
everything.

Move from finding management to
evidence-backed risk reduction.

See why the finding matters, inspect the proof, assign remediation, and confirm the fix.