Skip to content
Seecop · Quickstart

Run your first discovery

Connect a scope you control, run a first discovery, triage what matters, and route a signal to the person who can fix it.

Command reference is provisional

The workflow below is the intended path, but some exact command names, flags, and integration names are still being finalised. Anything unverified is marked with a TODO. Check seecop --help for your CLI version, or ask the team, before scripting it into automation.

What you will do

Register a scope, verify that you control it, run a discovery, read the highest-priority findings, and hand one to an owner. Seecop is read-only by default: it observes your estate and never changes it without explicit permission.

Prerequisites

  • A Seecop account.
  • Administrative access to the domains or networks you want to assess, so you can complete scope verification.
  • A terminal and about ten minutes.

1. Authenticate

Sign in so the CLI can talk to your workspace.

bash
# Authenticate the CLI. TODO(platform): confirm the auth flow.
seecop login

2. Connect a scope

A scope is the explicit boundary of what Seecop may look at — domains, CIDR ranges, and cloud accounts. Start narrow; you can widen it later.

bash
# Register the domains, ranges, and cloud accounts Seecop may assess.
# TODO(platform): confirm subcommand names and flag syntax.
seecop scope create production \
  --domain example.com \
  --cidr 203.0.113.0/24

# Confirm the scope exists.
seecop scope list

3. Verify the scope

Before active discovery runs, prove you control the scope. This keeps the platform safe by construction and keeps your audit trail clean.

bash
# Prove control of a scope before any active discovery runs.
# TODO(platform): confirm the supported verification methods.
seecop scope verify production
text
# Illustrative output — exact wording varies by CLI version.
verification record found for example.com
scope production is active (read-only)

4. Run a discovery

Run a standard discovery against the scope. Passive checks run first; active checks stay within the profile you choose.

bash
# A standard profile runs passive discovery plus safe active checks.
# TODO(platform): confirm profile names and flags.
seecop scan run --scope production --profile standard
text
# Illustrative output.
scan <scan-id> queued
scan <scan-id> completed — 214 assets, 37 services, 9 exposures

5. Triage findings

Seecop ranks findings by exploitability and business context, not raw severity alone. Start with the highest-priority items and read the evidence before you act.

bash
# List only what is worth looking at this week.
seecop findings list --scope production --min-severity high

# Read the evidence and blast radius for a single finding.
seecop findings show <finding-id>
text
# Illustrative output.
ID            SEVERITY   ASSET                 TITLE
<finding-id>  high       api.example.com       Admin console exposed
<finding-id>  high       vpn.example.com       Outdated TLS on edge

6. Route a signal

Send the finding to its owner with the context and evidence attached, so the next action is obvious.

bash
# Route a finding to its owner with context attached.
# TODO(platform): confirm route targets and integration names.
seecop signal route --finding <finding-id> --to oncall@example.com

# Or connect a channel once, then route by tag.
seecop integrations connect slack --channel "#security"

Next steps