Review and act on Targets

Once a Campaign is running, the Target tab is where you track every entity in the Targeting funnel and act on the ones that need your attention.

For background on funnel statuses and how Targets advance, see Targeting.


Review and act on Targets

1

Open the Target tab

From the Targeting application, select the Target tab. The funnel at the top shows a live count of Targets at each status: Potential Targets, Targeted, Validated, Exploitable, Exploited, and Remediated.

Target tab showing the full funnel with counts at each status and In progress targets below
The Target tab showing funnel status counts

The count under Potential Targets reflects every asset that matched a Trigger across your active Packages. As Agents work through them, counts shift across the funnel in real time.

2

Open a Target and read the detail view

Click any status card to filter the list to Targets at that stage, then select a Target to open its detail view.

Targeted status selected showing an in-progress target with package, trigger, underlying asset, and linked investigation details
A Targeted asset selected in the list

The top of the detail view shows a one-line status summary reflecting what the last Agent found. A confirmed finding reads as something like “[OUTCOME: SUCCESS] RDP vulnerability confirmed on port 3389.” An inconclusive one reads as “[OUTCOME: FAILURE] Inconclusive validation, no fresh RDP evidence found.”

In the top-right corner, four controls are available:

  • Status dropdown: Change the Target’s current status manually without waiting for Agent work to complete.
  • Send to Operator: Open the Target and its full context in an Operator session to investigate manually.
  • Copy link: Copy a direct link to this Target to share with teammates or include in documentation.
  • Pop out: Open the Target in a new tab.

Below the header, the Process pipeline shows where the Target currently sits and what steps remain.

Target detail view showing process stages, trigger context, rules of engagement, and Continue options
Target detail view showing the process pipeline and status

If an Agent session is currently running and you want to stop it, click Abort in the Target list.

3

Explore the Target's context

Below the Process pipeline, the detail view shows the targeted object and the context around it.

Object details

Click View all details to open the full object properties panel. This shows the object’s properties, including Environment, application name, application version, first seen, and last seen, as well as any tags associated with the object. Add or remove tags directly from this panel.

View all details popout for MICROSOFT_SQL_SERVER 15.0.2000 showing properties including Environment, Application Name, Application Version, first seen and last seen timestamps, Method Target tags, a Comments field, and Related Objects at the bottom
The View all details panel showing object properties and tags for a Software Application target

Issues tab

The Issues tab lists any Issues related to this Target that Method has found in the Environment. Review this to understand the broader risk picture around the targeted object before deciding how to proceed.

Issues tab showing one Info severity Issue, Application Discloses Software Type and Version, with the Issue detail panel open on the right displaying description, remediation guidance, and related objects
The Issues tab with a related Issue open, showing its description, severity, and remediation guidance

Sources tab

The Sources tab shows how the targeted object was originally discovered. For each source, you can see the GUI-level steps the Tool took, the raw JSON output, and the full Tool execution output. This is the Tool’s own record of how it found and characterized the object.

Sources tab with Service Fingerprint (TCP) selected on the left and the Steps view on the right, showing three workflow steps: downloadFile, a shellCommand running a fingerprinting tool, and a shellCommand to clean up. JSON and Tool Output tabs are also available.
The Sources tab showing the workflow steps used to discover the Application Name property via Service Fingerprint (TCP)

Linked Objects

The Linked Objects tab shows all Objects related to the targeted asset as a graph and a list with last-sighting timestamps. Use this to understand what the asset connects to and when it was last observed.

Linked Objects tab showing asset properties and metadata
Linked Objects tab showing related assets and metadata
Graph view of related objects including Web File, URL, and Web Application nodes
Related Objects graph showing asset relationships

Rules of Engagement and Package

The detail view also shows the Rules of Engagement applied to this Target and the Package that selected it. You can navigate directly to the Package configuration from here to review or adjust its settings.

4

Review Agent findings

Any Agents that have run on this Target are listed in the detail view. Click an Agent to open its session. The Conversation tab shows the Agent’s full reasoning: the context it was given, the tool calls it made, the Objects it loaded, and the conclusion it reached. The Details tab shows the Agent’s configuration for that run, including its type, model, Targets, and the MCP Tools it had access to.

Agent session for Validating MICROSOFT_SQL_SERVER 15.0.2000 showing status Completed, five objects loaded, the Agent's reasoning about an inconclusive MSSQL validation, and the outcome: [OUTCOME: FAILURE] Inconclusive validation of MSSQL 15.0.2000 on 172.16.30.50:1433
The Conversation tab showing an Agent's tool calls, loaded objects, and outcome
Details tab for Challenger Object Cloud Bucket Validation showing Agent Type as Targeting Validation, model as Large Model Default using Azure OpenAI GPT-5.4, target Issue type as Cloud Bucket, and the full list of recommended MCP Tools
The Details tab showing the Agent's type, model, targets, and MCP Tools for the session

For the full recorded output, select the Reports tab. Each Agent that ran on the Target generates a report. Reports are grouped by Agent type (Validation, Pentest, Exploit) and titled with the outcome and confirmation status: for example, “[OUTCOME: SUCCESS]” or “[OUTCOME: FAILURE] Inconclusive.” The report body is broken into three sections:

  • Summary: A short account of what the Agent found and what it concluded.
  • Reasoning: The Agent’s step-by-step logic for how it reached its conclusion.
  • Evidence: The specific data, tool outputs, and observations the Agent used to support its finding.
Reports tab with three reports listed under Exploit, Pentest, and Validation Agent groups. The OUTCOME: SUCCESS Exploit report is open on the right, showing the full title, Summary section with reproduction details, and Reasoning section with vector, original sink, and rungs walked.
The Reports tab showing reports grouped by Agent type, with an Exploit report open
5

Act on Targets at Rules of Engagement gates

When a Target reaches a status where your Rules of Engagement require approval, it appears in the Required input group. Review the Agent’s findings in the detail view and Reports tab before deciding.

At Validated

Click the Validated status card to see Targets where validation has completed and input is required.

Validated status selected showing required input targets with a Proceed and Abort prompt
Validated status showing Targets requiring input
Target detail showing Validated status pending approval, with Proceed to Pentest Agent and Stop here options
Validated Target detail showing the approval gate

Click Proceed to Pentest Agent to allow the Agent to continue to pentesting, or Stop here to hold the Target at Validated.

At Exploitable

Click the Exploitable status card. Targets in Required input have hit a Rules of Engagement gate before exploitation.

Exploitable status selected showing a target with Need user input status and Proceed and Abort options
Exploitable status showing Targets pending user input

Select a Target and click Proceed to authorize exploitation, or Abort to stop the Agent. After proceeding, the Target moves out of Required input and into In progress.

Target list showing Required input count decremented and In progress count incremented after proceeding
Target moved to In progress after proceeding
6

Send a Target to an Agent manually

From the Continue section at the bottom of any Target detail view, you can route the Target to a specific Agent without waiting for the automated pipeline.

Continue section showing Send to Validation Agent, Send to Pentest Agent, Send to Exploit Agent, and Send to Operator options
Agent options in the Continue section
  • Send to Validation Agent: run or re-run validation
  • Send to Pentest Agent: escalate directly to pentesting
  • Send to Exploit Agent: escalate to exploitation
  • Send to Operator: open the Target in Operator for manual investigation
7

Understand blocked Targets

A blocked Target is waiting on input beyond a standard Rules of Engagement approval. The Agent may have hit an ambiguous finding, lacked enough context to continue, or reached a point where it needs human direction.

Open the Target’s detail view, select the Reports tab, and open the [OUTCOME: BLOCKED] report. The report explains what the Agent found, why it stopped, and what evidence it reviewed.

Reports tab showing an OUTCOME: BLOCKED report with detailed reasoning, evidence reviewed, and narrative stub
Blocked Target report explaining why the Agent stopped

In the example above, the Agent had insufficient pentest context to continue. A reasonable next step is to send the Target to a Pentest Agent to develop a PoC, then route it to an Exploit Agent once a confirmed exploit path exists.

8

Mark Targets as Remediated or Deferred

Once you address a Target’s security concern, move it to Remediated to close it out.

If the concern is real but not immediately fixable, move it to Deferred. Common reasons to defer:

  • The asset is owned by a third party and remediation requires external coordination
  • A vendor patch is pending and no workaround is available
  • You reviewed the risk and consciously accepted it for a defined period
  • Operational constraints prevent remediation right now

Deferred Targets remain tracked in the funnel. They are not closed: they are set aside with the expectation of revisiting them. When circumstances change, move a Deferred Target back into the active pipeline or close it as Remediated.


Next steps