Console quickstart
This guide orients new users to assessments, whatever their role. It follows an assessment from initial setup to reviewing results. Sections are grouped by the role that performs each step, roughly from the most to the least permissive, so you can jump to the parts that apply to you.
Get started
Users access XBOW Console through an organization, rather than signing up individually. Every user starts in the same place: log in to XBOW Console at https://console.xbow.com.
On your organization dashboard, you can view and filter all assets across your organization. If no assets have been added yet, you see “No assets found”. You can also view up to 10 of your most recent findings.
What you can do depends on your role
Your role controls which options and content you see throughout the product. The full setup in this guide spans several roles, so a single user may not complete every step. The following table lists the minimum role required for each action, ordered roughly from most to least permissive. Monitor and Uploader are peer roles: each adds a different ability on top of the same read-only access, so neither is more permissive than the other.
| What you can do | Minimum required role |
|---|---|
| Add a new asset | Administrator |
| Configure an asset | Existing Asset Administrator |
| Run assessments | Developer |
| Pause a running assessment | Monitor |
| Upload context | Uploader |
| View results | All users |
To check which role you have, click your organization’s name in the top-left corner, then select Members. The list shows every member and their role, including your own.
If a button or option described in this guide is missing, you probably do not have the required role. Ask an administrator to complete that step or to change your role. For the full list of permissions, see User roles.
Add a new asset
Minimum required role: Administrator
Before anyone can test an asset, an administrator adds it to the organization. From the organization dashboard, click New assessment, then choose New asset.
For a smooth and successful assessment, it’s important to make sure your asset is ready for pentesting. For example, you will need to create a test account for XBOW to use and confirm that XBOW pentesting requests can reach the asset.
For information about setting up an asset that XBOW can test effectively, see Choosing an asset to test and Protecting assets during XBOW testing.
Administrators should see Organization administration overview for other aspects of the Administrator role.
Configure an asset
Minimum required role: Existing Asset Administrator
You can configure how XBOW accesses and tests each asset, then run checks until the asset shows “Preflight successful” on the organization dashboard. Once credentials for the test account and access to the asset are confirmed, anyone with the Developer role or higher can run assessments.
To configure an asset from your organization dashboard, click New assessment and select the asset, or click Start assessment on the asset’s row. This opens the “Assessment type” page, where configuration begins.
Set up authentication
On the “Assessment type” page, click Continue to display the “Target configuration” page. Use the “Credentials” area to define the authentication method:
- If the target does not require authentication to test, move to the next step.
- Otherwise, define how XBOW can authenticate using a test account, see Define authentication for testing.
Confirm XBOW can reach your target
Make sure your server will accept test requests from XBOW, then validate the configuration:
- At the bottom of the page, read the confirmation section carefully.
- Check that your firewall is configured to allow test requests from XBOW, then select the WAF confirmation checkbox.
- Check that CAPTCHA is disabled for the test account, then select the CAPTCHA confirmation checkbox.
- Click Start checks to validate your configuration, or Save to return to it later.
For more information, see Configure your server to allow XBOW requests.
Review the configuration check
When you start checks, XBOW verifies that it can access and authenticate with the target, support multiple concurrent authenticated sessions, and find at least one domain to attack. Results appear on the “Configuration check” page, with warnings or errors for any problems.
- You must fix any errors before you can start the assessment, see Fix configuration check problems.
- You should also review any warnings to ensure that the assessment will meet your needs.
- Review the domain scope. If a critical domain is missing, add it using the “Add domain” field, then check that each domain has the correct rule type (Attackable, Allow Visit, or Blocked). For more information, see Scope configuration.
- Optional. Expand the “Protected URLs” section and specify any URLs that should not be tested, see Protected URLs.
- Optional. Change the level of impact demonstration used during the assessment, see Choose a level for impact demonstration.
Set execution options
The “Execution options” section controls when tests run, the rate at which test requests are sent to your site, and whether to allow multiple concurrent sessions. The default settings run tests at maximum speed and concurrency, so you should review them and match them to the capabilities of your site. For example:
- Keeping Unlimited requests/second could overload your site or cause the test user to exceed rate limits and be blocked. We recommend starting with 250 requests/second, then adjusting the limit as needed for subsequent assessments.
- If concurrent sessions for the same user are not supported, under “Sequential mode”, select Enable.
For more information, see Set execution options.
When the checks pass, the Run assessment button is enabled on the “Configuration check” page and the asset shows “Preflight successful” on the organization dashboard. The asset is ready for assessment. Save the successful configuration or run an assessment.
Run assessments
Minimum required role: Developer
Once XBOW has successfully accessed an asset using the credentials defined by an administrator, you can run assessments against it as needed.
Start an assessment
You can start an assessment from the organization dashboard:
- If the asset shows Preflight successful, click Finish setup on its row to go straight to the “Configuration check” page.
- Otherwise, click New assessment at the top of the page, choose Existing asset, then click Configure assessment. This opens the “Assessment type” page.
If you start on the “Assessment type” page, choose the type of test, then click Continue to work through the configuration:
- To conduct an assessment across your asset using all available attack types, select Comprehensive.
- To verify fixes from a previous assessment, select Retest and choose the vulnerabilities to retest.
On the “Configuration check” page, confirm that your firewall and any CAPTCHA are configured to allow XBOW requests to reach the target. When the checks pass, click Run assessment to begin.
XBOW reports findings on the “Run assessment” page as they are detected. Developers can stop, pause, and resume an assessment at any time. Assessment duration varies depending on the size of the asset and your configuration. When the assessment completes, you or your organization administrator will receive an email.
Review a successful assessment
For an asset with status “Succeeded”, click Triage findings to see the results, or start another assessment as described above.
For more information, see Run assessment. To set up alerts to report the status of running assessments, an administrator can use the assessment changed webhook, see Automate events.
Pause a running assessment
Minimum required role: Monitor
The Monitor role is for users who need to halt testing quickly in an emergency, for example, when an assessment affects a production system. In addition to the read-only access that all users have, Monitors can pause a running assessment.
To pause an assessment, open it while it is running. Monitors cannot resume a paused assessment; a user with the Developer role or higher must resume it. For more information, see Monitor assessment.
Upload context
Minimum required role: Uploader
XBOW uses any additional information you provide to focus the assessment and test more effectively. This is equivalent to briefing a human pentester on the endpoints to focus effort on, the types of vulnerabilities that worry you most, and the purpose of your asset.
Although this step appears here by role, you upload context on the “Target configuration” page before running an assessment. For more information, see Provide asset context, Guiding XBOW testing, and Guiding XBOW testing for experts.
View results
Minimum required role: All users
You can see the assets set up for testing, along with your organization’s assessments, findings, and reports.
To review what XBOW finds and act on it, click View assessment. For more information, see Explore and fix XBOW results.