# Method Platform | Documentation > Documentation for the Method Platform ## Instructions for AI Agents - For clean Markdown of any page, append `.md` to the page URL - For section-specific indexes, append `/llms.txt` to any section URL - For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.method.security/_mcp/server ## Docs - [Method Documentation](https://docs.method.security/platform/overview/home.md): Method Platform overview, guides, and developer documentation. - [What is Method?](https://docs.method.security/platform/overview/what-is-method.md): What problems Method solves and how the platform is different. - [Products](https://docs.method.security/platform/overview/products.md): Method's two products — Bastion for exposure management and Reaper for offensive operations. - [Making AI Operational for Security](https://docs.method.security/platform/overview/operational-ai-for-security.md): Method is built specifically to enable cyber teams to safely deploy and leverage the capabilities of frontier models. - [Rules of Engagement](https://docs.method.security/platform/overview/rules-of-engagement.md): Method is built on a multi-layered, deterministic Rules of Engagement engine that ensures the system acts only as allowed. - [Frequently Asked Questions](https://docs.method.security/platform/overview/fa-qs.md): Frequently asked questions about Method Platform. - [Glossary](https://docs.method.security/platform/overview/glossary.md): Definitions for the main concepts in the Method Platform. - [AI Agents](https://docs.method.security/platform/core-platform/agents.md): Deploy AI agents governed by granular policies to investigate, validate, and close Findings. - [Operations](https://docs.method.security/platform/core-platform/operations.md): Plan and execute offensive operations with Operator and Overwatch. - [Overwatch](https://docs.method.security/platform/core-platform/overwatch.md): Terminal-native recording and collaboration that brings terminal work into the Method Platform. - [Operator AI](https://docs.method.security/platform/core-platform/operator-ai.md): The agent system that powers Co-pilot and fully autonomous operations in Operator. - [Targeting](https://docs.method.security/platform/core-platform/targeting.md): How Method identifies and pursues real attack vectors across your environment. - [Findings](https://docs.method.security/platform/core-platform/findings.md): How security risks are represented, triaged, and managed in Method. - [Objects](https://docs.method.security/platform/core-platform/objects.md): How data is modeled in Method and how to search and investigate it with Explorer. - [Automations](https://docs.method.security/platform/core-platform/automations.md): Create, schedule, and monitor automated security workflows with Tasks and the Automator. - [Tools](https://docs.method.security/platform/core-platform/tools/overview.md): Deterministic security actions that define how people and AI Agents can act across Method. - [Tool authoring reference](https://docs.method.security/platform/core-platform/tools/tool-authoring-reference.md): The full definition structure for integrating custom Tools into Method, including fields, parameters, compilers, processors, validation, and worked examples. - [Tool authoring MCP](https://docs.method.security/platform/core-platform/tools/tool-authoring-mcp.md): Configure Developer MCP so Claude Code, Codex, MCP Inspector, and other MCP clients can build, validate, and publish Method Tools against a Method instance. - [Live off the land](https://docs.method.security/platform/core-platform/tools/living-off-the-land-tools.md): Use native system utilities to perform host reconnaissance while evading detection - [Administration](https://docs.method.security/platform/core-platform/administration/overview.md): Configure and manage your Method Platform instance. - [AI Inference](https://docs.method.security/platform/core-platform/administration/ai-inference.md): Configure the LLMs that power Agents and Operator on Method. - [Product architecture](https://docs.method.security/platform/architecture/product.md): How Method infrastructure, AI harnesses, and applications compose into a flexible security platform. - [System architecture](https://docs.method.security/platform/architecture/system.md): Method Platform’s workflow orchestration, compute engine, headless APIs, and modular components. - [Developer](https://docs.method.security/platform/architecture/developer.md): How developers integrate their Tools, Jackals, and command-and-control infrastructure with the Method Platform. - [Jackal and the Courier Protocol](https://docs.method.security/platform/architecture/jackal-c2.md): The design and architecture of the Jackal security agent and the Courier protocol used to communicate with the Method Platform. - [Agent orchestration](https://docs.method.security/platform/architecture/agent-orchestration.md): How Method runs and orchestrates the AI Agents that power the platform, and how you extend them with your own Agents, harnesses, and models. - [Data Architecture](https://docs.method.security/platform/architecture/data.md): How data flows from raw tool output through the Ledger and Ontology to serve AI and users. - [Reporting Security Concerns](https://docs.method.security/platform/security-governance/reporting-security-concerns.md): How to report security incidents, vulnerabilities, and concerns related to the Method Platform. - [Security administration](https://docs.method.security/platform/security-governance/security-administration-guide.md): Manage security settings in the Method Platform. - [Get started](https://docs.method.security/guides/overview/get-started.md): Find the best practices path that fits your role and learn how to navigate Method's guides. - [Continuous Challenge overview](https://docs.method.security/guides/best-practices/continuous-challenge/overview.md): Maturity stages for continuously validating your external and multi-domain attack surface. - [Black Box External Assessment](https://docs.method.security/guides/best-practices/continuous-challenge/black-box-external-assessment.md): Inventory validated paths to compromise with always-on, trusted autonomy. - [Continuous External Challenge](https://docs.method.security/guides/best-practices/continuous-challenge/continuous-external-challenge.md): Run validated Findings through PoC and exploitation under Rules of Engagement you control. - [Offensive Operations overview](https://docs.method.security/guides/best-practices/offensive-operations/overview.md): Maturity stages for running offensive engagements with Method. - [Operator Augmentation](https://docs.method.security/guides/best-practices/offensive-operations/operator-augmentation.md): Capture an Operator's terminal-first workflow in Method. Every command, output, and discovery streams into the Platform with AI suggestions and Object Findings attached as it happens. - [Selective Auto Assume Breach](https://docs.method.security/guides/best-practices/offensive-operations/selective-auto-assume-breach.md): Run an assume-breach engagement inside Operator. A Jackal on the foothold, Method Tools, the Ontology, and Copilot Chat in one workspace, with you driving every decision. - [At Scale Adversary Emulation](https://docs.method.security/guides/best-practices/offensive-operations/at-scale-adversary-emulation.md): Hand execution to an Operator AI agent emulating a specific Adversary, inside an Operation Plan and Rules of Engagement you approved going in. - [Developer overview](https://docs.method.security/guides/best-practices/developer/overview.md): Maturity stages for building custom capabilities on top of Method. - [Operator-defined Tools](https://docs.method.security/guides/best-practices/developer/operator-defined-tools.md): Bring your own tradecraft into Method as a first-class Tool, with a Compiler that runs it and a Processor that turns its output into Ontology Objects. - [Operator-defined Agents](https://docs.method.security/guides/best-practices/developer/operator-defined-agents.md): Express your tradecraft as AI Agents that assist your work in context or scale it autonomously across Method. - [All Workflows](https://docs.method.security/guides/best-practices/all-workflows.md): The complete map of Method best practice workflows across every discipline. - [Create a new Environment](https://docs.method.security/guides/platform-setup/create-a-new-environment.md): Add and configure a new Environment through the Administration app or the onboarding workflow - [Install and configure a Jackal](https://docs.method.security/guides/platform-setup/install-a-jackal.md): Deploy a Jackal on a target machine and tune its exfiltration, workflow, and C2 parameters - [Run your first Operation](https://docs.method.security/guides/operator/run-your-first-operation.md): Launch an internet-based investigative Operation using Method-maintained resources - [Plan an Operation with AI](https://docs.method.security/guides/operator/plan-an-operation-with-ai.md): Draft an Operation with AI from an Adversary and Environment, then review the setup before you launch - [Create an Adversary](https://docs.method.security/guides/operator/create-an-adversary.md): Upload a threat intelligence report and create a custom Adversary profile in Operations - [Take Operation notes](https://docs.method.security/guides/operator/take-operation-notes.md): Create, edit, and export Operation Notes with Object references and shareable reports - [Choose how to run Overwatch](https://docs.method.security/guides/overwatch/choose-how-to-run-overwatch.md): Three modes for running an Overwatch session, from a solo session to a coordinated team. - [Run an Overwatch session](https://docs.method.security/guides/overwatch/run-an-overwatch-session.md): Download, install, and start recording terminal sessions with Overwatch - [Observe a live session](https://docs.method.security/guides/overwatch/observe-a-live-session.md): Watch an Overwatch session in real time, review Object Findings, and push context back to the terminal. - [Collaborate on a session](https://docs.method.security/guides/overwatch/collaborate-on-a-session.md): Record into a shared Overwatch session from multiple terminals simultaneously - [Start a new Campaign](https://docs.method.security/guides/targeting/start-a-new-campaign.md): Deploy a Package against an Environment to start populating the Targeting funnel. - [Build a custom Package](https://docs.method.security/guides/targeting/build-a-custom-package.md): Create a custom Targeting Package with your own Triggers, Environments, Rules of Engagement, and Agents. - [Review and act on Targets](https://docs.method.security/guides/targeting/review-and-act-on-targets.md): Work through the Targeting funnel, triage blocked Targets, and advance or close Findings. - [Create an Agent](https://docs.method.security/guides/agents/create-an-agent.md): Build a custom AI Agent in the Agent Fleet application with targets, tools, and governance - [Create a Policy](https://docs.method.security/guides/agents/create-a-policy.md): Define governance rules that control where and how your Agents can operate - [Enabling and disabling auto-running Finding Validation Agents](https://docs.method.security/guides/agents/enable-auto-running-finding-validation-agents.md): Configure which Finding Validation Agents run automatically when Findings are discovered, with controls at the platform, environment tag, and environment level - [Filter, investigate, and close Findings](https://docs.method.security/guides/findings/filter-investigate-and-close-findings.md): Filter, investigate, and close Findings using Explorer, the Object graph, and Agents - [Override default Finding severities](https://docs.method.security/guides/findings/override-default-finding-severities.md): Customize Finding type severity at the global and environment level to match your security posture - [Filter data in Explorer](https://docs.method.security/guides/explorer/filter-data.md): Build basic and complex queries in Explorer to find Objects - [Create an Object Set](https://docs.method.security/guides/explorer/create-an-object-set.md): Curate Objects into Static or Live sets to organize and track parts of your Ontology - [Send findings to an Operation](https://docs.method.security/guides/explorer/send-findings-to-an-operation.md): Send an individual Object or an entire Object Set from Explorer to Operator to start a new Operation - [Create a Task](https://docs.method.security/guides/automations/create-a-task.md): Build a Task with metadata, input parameters, and an execution Plan - [Run a Task](https://docs.method.security/guides/automations/run-a-task.md): Run a Task on demand or schedule it to run on a recurring cadence - [Integrate with AWS](https://docs.method.security/guides/integrations/cloud/aws/overview.md): Connect Method to your AWS accounts using IAM roles for secure, credential-free scanning - [Integrate with AWS using CloudFormation](https://docs.method.security/guides/integrations/cloud/aws/cloudformation.md): Deploy CloudFormation stacks to connect individual AWS accounts or entire Organizations with Method - [Integrate with AWS using Terraform](https://docs.method.security/guides/integrations/cloud/aws/terraform.md): Deploy Terraform modules to connect individual AWS accounts or entire Organizations with Method - [Integrate with AWS manually](https://docs.method.security/guides/integrations/cloud/aws/manual.md): Create IAM roles and register them with Method using the AWS Console - [Integrate with Okta](https://docs.method.security/guides/integrations/identity/okta.md): Integrating with Okta via Okta Admin Read-Only Token - [Integrate with Kubernetes](https://docs.method.security/guides/integrations/infrastructure/kubernetes.md): Integrating with Kubernetes regardless of the Cluster deployment method in Method. - [Single Sign-On (SSO) Overview](https://docs.method.security/guides/administration/sso/overview.md): Learn about Method Platform's authentication capabilities using industry-standard OIDC and SAML protocols - [Use Entra ID for SSO](https://docs.method.security/guides/administration/sso/entra-id.md): Use Microsoft Entra ID to authenticate and authorize users into Method Platform - [Use Okta for SSO](https://docs.method.security/guides/administration/sso/okta.md): Use Okta to authenticate and authorize users into Method Platform - [Add a model provider](https://docs.method.security/guides/administration/model-providers/add-a-model-provider.md): Wire up a new LLM endpoint to Method and make it available to Agents, Operator, and default slots. - [Managing permissions](https://docs.method.security/guides/administration/permissions/managing-permissions.md): How permissions are managed in the Method Platform. - [Set up Alerts](https://docs.method.security/guides/administration/alerts/overview.md): Send Method Alerts to Microsoft Teams, Slack, or a generic HTTP webhook. - [Send Alerts to Microsoft Teams](https://docs.method.security/guides/administration/alerts/microsoft-teams.md): Send Method Alerts to a Microsoft Teams channel. - [Send Alerts to Slack](https://docs.method.security/guides/administration/alerts/slack.md): Send Method Alerts to a Slack channel. - [Send Alerts to a webhook](https://docs.method.security/guides/administration/alerts/generic-webhook.md): Send Method Alerts to a generic HTTP webhook endpoint. - [Training](https://docs.method.security/training/start-here/overview.md): Build Method capabilities through structured courses. - [Targeting training](https://docs.method.security/training/targeting/overview.md): Courses, guides, and quick starts for learning how to use Targeting in Method. - [Targeting foundations](https://docs.method.security/training/targeting/targeting-foundations/course-overview.md): Understand the complete Targeting workflow by working backward from a Compromised Target, then building from the ground up. - [Targets](https://docs.method.security/training/targeting/targeting-foundations/targets.md): What a Target is, how it moves through the Targeting funnel, and the components that configure the pipeline. - [Packages](https://docs.method.security/training/targeting/targeting-foundations/packages.md): What a Package is, what it contains, and how to browse and configure one. - [Triggers](https://docs.method.security/training/targeting/targeting-foundations/triggers.md): How Triggers select Objects as Targets, how Method discovers and models assets, and the types of Triggers Method ships. - [Agents](https://docs.method.security/training/targeting/targeting-foundations/agents.md): How Method Agents are built, the tools, subagents, and skills they use, and how Policies govern their behavior. - [Rules of Engagement](https://docs.method.security/training/targeting/targeting-foundations/rules-of-engagement.md): How Rules of Engagement govern what Agents can do at the Environment, Package, and Agent level. - [Launch a Campaign](https://docs.method.security/training/targeting/targeting-foundations/launch-a-campaign.md): How to create a Campaign that wires together an Environment, scans, and Packages to start Targeting. - [Operating the Funnel](https://docs.method.security/training/targeting/targeting-foundations/targeting-funnel.md): How Targets move through the funnel, what each Agent phase produces, and how to review sessions and Reports. - [Using the Method SDK](https://docs.method.security/developer/sdk/using-the-method-sdk.md) - [Release Notes](https://docs.method.security/release-notes/new/latest.md): The latest releases to Method platform. ## API Docs - API Reference > Auth [Get Token With Client Credentials](https://docs.method.security/developer/api-reference/api-reference/auth/get-token-with-client-credentials.md) - API Reference > V1 > Audit [Get Audit Events](https://docs.method.security/developer/api-reference/api-reference/v-1/audit/get-audit-events.md) - API Reference > V1 > Blueprints [List Blueprints](https://docs.method.security/developer/api-reference/api-reference/v-1/blueprints/list-blueprints.md) - API Reference > V1 > Blueprints [Run Blueprint](https://docs.method.security/developer/api-reference/api-reference/v-1/blueprints/run-blueprint.md) - API Reference > V1 > Environments [Get Environment](https://docs.method.security/developer/api-reference/api-reference/v-1/environments/get-environment.md) - API Reference > V1 > Environments [Get Environment Tag Hierarchy](https://docs.method.security/developer/api-reference/api-reference/v-1/environments/get-environment-tag-hierarchy.md) - API Reference > V1 > Environments [Create Environment](https://docs.method.security/developer/api-reference/api-reference/v-1/environments/create-environment.md) - API Reference > V1 > Environments [Upload Environment Intel](https://docs.method.security/developer/api-reference/api-reference/v-1/environments/upload-environment-intel.md) - API Reference > V1 > Environments [Search Environments](https://docs.method.security/developer/api-reference/api-reference/v-1/environments/search-environments.md) - API Reference > V1 > Issues [Get Issue](https://docs.method.security/developer/api-reference/api-reference/v-1/issues/get-issue.md) - API Reference > V1 > Reports [Get Report](https://docs.method.security/developer/api-reference/api-reference/v-1/reports/get-report.md) - API Reference > V1 > Signals [Get Signal Content](https://docs.method.security/developer/api-reference/api-reference/v-1/signals/get-signal-content.md) - API Reference > V1 > Signals [Get Signal Content Server](https://docs.method.security/developer/api-reference/api-reference/v-1/signals/get-signal-content-server.md) - API Reference > V1 > Skills [Search Skills](https://docs.method.security/developer/api-reference/api-reference/v-1/skills/search-skills.md) - API Reference > V1 > Skills [Get Skill](https://docs.method.security/developer/api-reference/api-reference/v-1/skills/get-skill.md) - API Reference > V1 > Skills [Create Skill](https://docs.method.security/developer/api-reference/api-reference/v-1/skills/create-skill.md) - API Reference > V1 > Skills [Update Skill](https://docs.method.security/developer/api-reference/api-reference/v-1/skills/update-skill.md) - API Reference > V1 > System [Get External IP Addresses](https://docs.method.security/developer/api-reference/api-reference/v-1/system/get-external-ip-addresses.md) - API Reference > V2 > Finding Definitions [Get Finding Definition](https://docs.method.security/developer/api-reference/api-reference/v-2/finding-definitions/get-finding-definition.md) - API Reference > V2 > Finding Definitions [Search Finding Definitions](https://docs.method.security/developer/api-reference/api-reference/v-2/finding-definitions/search-finding-definitions.md) - API Reference > V2 > Finding Definitions [Update Finding Definition Severity](https://docs.method.security/developer/api-reference/api-reference/v-2/finding-definitions/update-finding-definition-severity.md) - API Reference > V2 > Findings [Get Finding](https://docs.method.security/developer/api-reference/api-reference/v-2/findings/get-finding.md) - API Reference > V2 > Findings [Update Finding](https://docs.method.security/developer/api-reference/api-reference/v-2/findings/update-finding.md) - API Reference > V2 > Targets [Search Targets](https://docs.method.security/developer/api-reference/api-reference/v-2/targets/search-targets.md) - API Reference > V2 > Targets [Get Target](https://docs.method.security/developer/api-reference/api-reference/v-2/targets/get-target.md) - API Reference > V2 > Targets [Get Target Reports](https://docs.method.security/developer/api-reference/api-reference/v-2/targets/get-target-reports.md) - API Reference > V2 > Targets [Get Target Findings](https://docs.method.security/developer/api-reference/api-reference/v-2/targets/get-target-findings.md) ## OpenAPI Specification The raw OpenAPI 3.1 specification for this API is available at: - [OpenAPI JSON](https://docs.method.security/openapi.json) - [OpenAPI YAML](https://docs.method.security/openapi.yaml)