Review and act on Targets

Once a Campaign is running, the Target tab is where you track every entity in the Targeting funnel and act on the ones that need your attention.

For background on funnel statuses and how Targets advance, see Targeting.


Review and act on Targets

1

Open the Target tab

From the Targeting application, select the Target tab. The funnel at the top shows a live count of Targets at each status: Potential Targets, Targeted, Researched Targets, Vulnerable Targets, Compromised Targets, and Remediated Targets.

The Targeting funnel showing counts at each status: Potential Targets, Targeted, Researched Targets, Vulnerable Targets, Compromised Targets, and Remediated Targets, with Exhausted and Blocked sub-counts
The Target tab showing funnel status counts

The count under Potential Targets reflects every asset that matched a Trigger across your active Packages. As Agents work through them, counts shift across the funnel in real time.

2

Open a Target and read the detail view

Click any status card to filter the list to Targets at that stage, then select a Target to open its detail view.

The Targets tab with the Targeted status card selected, filtering the list to Targeted assets; a Target is highlighted in the Stale group showing its Web Targeting Package, Targeted then Waiting status, KB Targeting Environment, and linked investigation counts
A status card selected with a Target highlighted in the filtered list

The Target detail view opens on the Overview tab, with Linked Objects and Reports tabs alongside it. The top of the view shows a one-line status summary reflecting what the last Agent found. A confirmed finding reads as something like “Confirmed RDP vulnerability on port 3389.” An inconclusive one reads as “Inconclusive validation, no fresh RDP evidence found.”

In the top-right corner, four controls are available:

  • Status dropdown: Change the Target’s current status manually without waiting for Agent work to complete.
  • Send to Operator: Open the Target and its full context in an Operator session to investigate manually.
  • Copy link: Copy a direct link to this Target to share with teammates or include in documentation.
  • Pop out: Open the Target in a new tab.

Below the header, the Process pipeline shows where the Target currently sits and what steps remain.

Target Overview tab showing the Process pipeline with Researched pending approval to proceed, the Targeted Object APACHE 2.4.38, Rules of Engagement and Target Package, and the timeline of Agent runs and Continue options
The Overview tab showing the process pipeline and status

If an Agent session is currently running and you want to stop it, click Abort in the Target list.

3

Explore the Target's context

The Overview tab’s timeline shows how the Target was selected and what has run on it so far: the Selected for Targeting entry names the Rules of Engagement and Target Package that selected it, and each subsequent entry records an Agent run.

Open the full Object details

Next to the Targeted Object, click View all details to open its full properties panel.

Target Overview tab with the View all details button highlighted next to the Targeted Object APACHE 2.4.38
The View all details button on the Targeted Object

The Object’s own panel opens with Overview, Targets, Findings, and Sources tabs. The Overview tab shows the Object’s properties, such as Environment and Application Version, along with first- and last-seen timestamps, any tags associated with the Object, a comments field, and a graph of related Objects.

Overview tab for a Software Application Object named APACHE 2.4.38, showing Linked Objects and Findings counts, Properties including Environment, Application Name, and Application Version, an Asset Owner tag, a Comments field, and a Related Objects graph
The Object's Overview tab showing properties, tags, and related Objects

The Findings tab lists any Findings related to this Object that Method has found in the Environment. Review this to understand the broader risk picture around the targeted Object before deciding how to proceed.

Findings tab for the APACHE 2.4.38 Object, listing four Application Discloses Software Type and Version Findings with an Info severity filter
The Findings tab listing Findings related to the Object

The Sources tab shows how each of the Object’s properties was discovered. Select a property to see the Tool’s raw JSON output, or switch to the Steps or Tool Output views for the GUI-level record of how the Tool found and characterized it.

Sources tab for the APACHE 2.4.38 Object with Application Name selected on the left and its JSON source record on the right, showing the property's origin and trigger signal
The Sources tab showing how the Application Name property was discovered

Use the Linked Objects tab without leaving the Target

The Target’s own Linked Objects tab shows the same Object details, properties, and related Findings inline, so you don’t need to open the full panel to get an overview. It also includes a Generate action for producing Finding reproducibility information and Object raw signal on demand.

Linked Objects tab on a Target showing Object Details for APACHE 2.4.38, its Properties and Tags, a Raw Signal section with a Generate button, and four related Findings under Other Findings on this Object
The Target's Linked Objects tab showing Object details and related Findings
4

Review Agent findings

Any Agents that have run on this Target are listed in the Overview tab’s timeline. Click an Agent run to open its session. The Conversation tab shows the Agent’s full reasoning: the context it was given, the tool calls it made, the Objects it loaded, and the conclusion it reached. The Details tab shows the Agent’s configuration for that run, including its type, model, Targets, and the MCP Tools it had access to.

Agent session titled Validating APACHE 2.4.38 on the Conversation tab, showing status Completed, two completed Web Request tool calls, Mark Finding as Validated and Create Finding Report tool calls, and the resulting OUTCOME: SUCCESS Report
The Conversation tab showing an Agent's tool calls and outcome
Details tab for Challenger Object Cloud Bucket Validation showing Agent Type as Targeting Research, Target Finding Types of Cloud Bucket, and the list of recommended tools
The Details tab showing the Agent's type, model, Targets, and MCP Tools for the session

For the full recorded output, select the Target’s Reports tab. Each Agent that ran on the Target generates a Report there. Reports are grouped by Agent type (Research, Pentest, Compromise) and titled with the outcome and confirmation status. The Report body is broken into three sections:

  • Summary: A short account of what the Agent found and what it concluded.
  • Reasoning: The Agent’s step-by-step logic for how it reached its conclusion.
  • Evidence: The specific data, tool outputs, and observations the Agent used to support its finding.
Reports tab with three Reports listed under Compromise, Pentest, and Research Agent groups. The OUTCOME: SUCCESS Compromise Report is open on the right, showing the full title, Summary section with reproduction details, and Reasoning section with vector, original sink, and rungs walked.
The Reports tab showing Reports grouped by Agent type, with a Compromise Report open
5

Act on Targets at Rules of Engagement gates

When a Target reaches a status where your Rules of Engagement require approval, it appears in the Required input group. Review the Agent’s findings in the detail view and Reports tab before deciding.

At Researched

Click the Researched Targets status card to see Targets where Research has completed and input is required.

The Targeting funnel with the Researched Targets card selected, showing 252 Researched Targets with 0 Exhausted and 94 Blocked sub-counts
The Targeting funnel with the Researched Targets card selected
Researched Target Overview tab for Confirm Apache 2.4.38 banner exposed on HTTP service, with the Process pipeline showing the Researched stage highlighted and Pending approval to proceed alongside Configure Pentest Agent and Stop here options, above the APACHE 2.4.38 Targeted Object
Researched Target detail showing the approval gate

Click Configure Pentest Agent to allow the Agent to continue to pentesting, or Stop here to hold the Target at Researched.

At Vulnerable

Click the Vulnerable Targets status card. Targets in Required input have hit a Rules of Engagement gate before Compromise.

The Targeting funnel with the Vulnerable Targets card selected, showing 38 Vulnerable Targets with a Required input list including a Target titled Confirm arbitrary file read on datasheet endpoint exposing server files, with Proceed and Abort options
The Vulnerable Targets card selected, showing Targets pending user input

Select a Target and click Proceed to authorize Compromise, or Abort to stop the Agent. After proceeding, the Target moves out of Required input and into In progress.

Use the status groups in the left rail to track where Targets sit: Required input, In progress, Exhausted, and Blocked. Select a group to filter the list to Targets in that state.

The Targeting funnel with the Vulnerable Targets card selected showing 74 Vulnerable Targets, the Required input, In progress, Exhausted, and Blocked status groups highlighted in the left rail, and a Target titled Confirm SQL injection on login endpoint disclosing backend query details awaiting user input with Proceed and Abort options
Status of the Vulnerable Targets being acted on by Compromise Agents
6

Send a Target to an Agent manually

From the Continue section at the bottom of any Target’s Overview tab, you can route the Target to a specific Agent without waiting for the automated pipeline.

Target Overview tab with the Continue section highlighted at the bottom, showing four cards: Send to Research Agent, Send to Pentest Agent, Send to Compromise Agent, and Send to Operator, above the timeline of prior Research and Pentest Agent runs
Agent options in the Continue section
  • Send to Research Agent: run or re-run Research
  • Send to Pentest Agent: escalate directly to pentesting
  • Send to Compromise Agent: escalate to Compromise
  • Send to Operator: open the Target in Operator for manual investigation
7

Understand blocked Targets

A blocked Target is waiting on input beyond a standard Rules of Engagement approval. The Agent may have hit an ambiguous finding, lacked enough context to continue, or reached a point where it needs human direction.

Open the Target’s detail view, select the Reports tab, and open the Blocked Report. The Report explains what the Agent found, why it stopped, and what evidence it reviewed.

Target Reports tab showing a Research Report titled Blocked, does not resolve from this vantage. The open Report explains that every live probe failed at DNS resolution, so the Agent could not confirm or invalidate the Target and returned a Blocked verdict rather than marking it Not reachable.
Blocked Target Report explaining why the Agent stopped

In the example above, the Agent could not resolve the target host from its vantage point and had insufficient evidence to reach a conclusive verdict. A reasonable next step is to confirm the host is reachable from another vantage, or send the Target to an Operator for manual investigation.

8

Mark Targets as Remediated or Deferred

Once you address a Target’s security concern, move it to Remediated to close it out.

If the concern is real but not immediately fixable, move it to Deferred. Common reasons to defer:

  • The asset is owned by a third party and remediation requires external coordination
  • A vendor patch is pending and no workaround is available
  • You reviewed the risk and consciously accepted it for a defined period
  • Operational constraints prevent remediation right now

Deferred Targets remain tracked in the funnel. They are not closed: they are set aside with the expectation of revisiting them. When circumstances change, move a Deferred Target back into the active pipeline or close it as Remediated.


Next steps