Run your first discovery
Connect a scope you control, run a first discovery, triage what matters, and route a signal to the person who can fix it.
Command reference is provisional
The workflow below is the intended path, but some exact command names, flags, and integration names are still being finalised. Anything unverified is marked with a TODO. Check seecop --help for your CLI version, or ask the team, before scripting it into automation.
What you will do
Register a scope, verify that you control it, run a discovery, read the highest-priority findings, and hand one to an owner. Seecop is read-only by default: it observes your estate and never changes it without explicit permission.
Prerequisites
- A Seecop account.
- Administrative access to the domains or networks you want to assess, so you can complete scope verification.
- A terminal and about ten minutes.
1. Authenticate
Sign in so the CLI can talk to your workspace.
# Authenticate the CLI. TODO(platform): confirm the auth flow.
seecop login2. Connect a scope
A scope is the explicit boundary of what Seecop may look at — domains, CIDR ranges, and cloud accounts. Start narrow; you can widen it later.
# Register the domains, ranges, and cloud accounts Seecop may assess.
# TODO(platform): confirm subcommand names and flag syntax.
seecop scope create production \
--domain example.com \
--cidr 203.0.113.0/24
# Confirm the scope exists.
seecop scope list3. Verify the scope
Before active discovery runs, prove you control the scope. This keeps the platform safe by construction and keeps your audit trail clean.
# Prove control of a scope before any active discovery runs.
# TODO(platform): confirm the supported verification methods.
seecop scope verify production# Illustrative output — exact wording varies by CLI version.
verification record found for example.com
scope production is active (read-only)4. Run a discovery
Run a standard discovery against the scope. Passive checks run first; active checks stay within the profile you choose.
# A standard profile runs passive discovery plus safe active checks.
# TODO(platform): confirm profile names and flags.
seecop scan run --scope production --profile standard# Illustrative output.
scan <scan-id> queued
scan <scan-id> completed — 214 assets, 37 services, 9 exposures5. Triage findings
Seecop ranks findings by exploitability and business context, not raw severity alone. Start with the highest-priority items and read the evidence before you act.
# List only what is worth looking at this week.
seecop findings list --scope production --min-severity high
# Read the evidence and blast radius for a single finding.
seecop findings show <finding-id># Illustrative output.
ID SEVERITY ASSET TITLE
<finding-id> high api.example.com Admin console exposed
<finding-id> high vpn.example.com Outdated TLS on edge6. Route a signal
Send the finding to its owner with the context and evidence attached, so the next action is obvious.
# Route a finding to its owner with context attached.
# TODO(platform): confirm route targets and integration names.
seecop signal route --finding <finding-id> --to oncall@example.com
# Or connect a channel once, then route by tag.
seecop integrations connect slack --channel "#security"Next steps
- See the full capability set on the Seecop overview.
- Want help defining your first scope? Talk to the team.