Runners

Runners are tenant-scoped agents that execute security tooling and push normalized results back into ExposureX.

Supported tools

  • semgrep for SAST
  • gitleaks for secrets
  • trivy for SCA, filesystem, IaC and container checks
  • nuclei for DAST/templates and safe re-verification
  • recon wrappers such as subfinder, dnsx, naabu, httpx, and katana when installed

Command lifecycle

  1. Runner sends heartbeat.
  2. Runner polls /api/v1/agent/commands.
  3. Runner acknowledges, starts, completes, or fails the command.
  4. Runner pushes CTIS/SARIF findings and assets.