# Kikimora ## Docs - [Creating an auth record](https://docs.kikimora.io/auth-records/creating-an-auth-record.md): Create an authentication record inline from the web application wizard, with every field, constraint, and validation message. - [Auth records overview](https://docs.kikimora.io/auth-records/index.md): What an authentication record stores, and the two wizards where you select or create one. - [Adding approved software](https://docs.kikimora.io/compliance-approved-software/adding-software.md): Register applications on the approved list one at a time through the Create New wizard, or in bulk by uploading a CSV. - [Approved software overview](https://docs.kikimora.io/compliance-approved-software/index.md): Maintain an allow-list of authorized applications and let Kikimora flag anything installed on your endpoints that falls outside it. - [Reading the charts](https://docs.kikimora.io/compliance-approved-software/reading-the-charts.md): Interpret the approved software metric cards, the unapproved software trend chart, and the ranked list of worst-offending endpoints. - [Reviewing results](https://docs.kikimora.io/compliance-approved-software/reviewing-results.md): Scope the approved software table to a single endpoint, configure its columns, and use filters and row actions to manage entries. - [Creating a custom policy](https://docs.kikimora.io/compliance-hardening/creating-a-custom-policy.md): Build your own SCA benchmark with the four-step wizard by picking checks from a base policy and assigning target endpoints. - [Hardening overview](https://docs.kikimora.io/compliance-hardening/index.md): Automated Security Configuration Assessment benchmarks that measure how closely your endpoints follow standards such as the CIS benchmarks. - [Reading the charts](https://docs.kikimora.io/compliance-hardening/reading-the-charts.md): Interpret the hardening dashboard's pass rate gauge, check status totals, and policy breakdown, and scope them all to a single benchmark. - [Reviewing results](https://docs.kikimora.io/compliance-hardening/reviewing-results.md): Drill from policy-level compliance statistics down through per-endpoint scores to individual check evaluations. - [Viewing a check](https://docs.kikimora.io/compliance-hardening/viewing-a-check.md): Open the check preview overlay to read a rule's description, rationale, remediation steps, and the evaluation script behind it. - [Integrity monitoring overview](https://docs.kikimora.io/compliance-integrity-monitoring/index.md): Track real-time changes to system files, directories, and Windows Registry keys on managed endpoints, fed continuously by endpoint agents. - [Reviewing results](https://docs.kikimora.io/compliance-integrity-monitoring/reviewing-results.md): Read the integrity monitoring endpoint table, then drill into a host's monitored file changes and Windows Registry changes. - [Drilling down from a widget](https://docs.kikimora.io/dashboard/drilling-down.md): Every Dashboard widget links into the module that owns its data. Reference of all 13 View More destinations and the filters each one pre-applies. - [Dashboard overview](https://docs.kikimora.io/dashboard/index.md): The Kikimora Dashboard aggregates risk, vulnerability, endpoint, and exposure metrics into 13 widgets that link straight into the modules behind them. - [Reading the charts](https://docs.kikimora.io/dashboard/reading-the-charts.md): Change the time range on Dashboard time-series charts and read the tooltips that break down findings by status for each period. - [Browsing endpoints](https://docs.kikimora.io/endpoints/browsing-endpoints.md): Search, filter, and shape the endpoints inventory table, and open an individual host's detail view. - [Endpoint details](https://docs.kikimora.io/endpoints/endpoint-details.md): Reference for the five telemetry tabs on a host — network interfaces, ports, processes, policy checks, and installed packages. - [Fetching vulnerabilities](https://docs.kikimora.io/endpoints/fetching-vulnerabilities.md): Trigger an on-demand vulnerability update for selected endpoints, and understand the selection behavior, hourly rate limit, and permissions. - [Endpoints overview](https://docs.kikimora.io/endpoints/index.md): The inventory of agent-monitored hosts, their connectivity states, and how background telemetry synchronization is throttled. - [Adding assets by domain](https://docs.kikimora.io/exposure/adding-assets-by-domain.md): Discover attack-surface assets by querying the DNS records and SSL certificates behind a root domain, then save the candidates you want to monitor. - [Adding assets by IP address](https://docs.kikimora.io/exposure/adding-assets-by-ip.md): Add an internet-facing IPv4 address straight to your monitored inventory, bypassing domain candidate discovery, and understand the validation rules. - [Inspecting asset details](https://docs.kikimora.io/exposure/asset-details.md): Open an exposure asset to review its CVEs, EPSS exploit-prediction scores, and the open ports and service banners discovered on it. - [Exposure overview](https://docs.kikimora.io/exposure/index.md): Continuously discover and monitor your internet-facing attack surface — domains, hostnames, and IP addresses — and export the findings as a report. - [Kikimora documentation](https://docs.kikimora.io/index.md): User documentation for the Kikimora security and vulnerability management platform, covering every module from the dashboard to compliance. - [Browsing assets](https://docs.kikimora.io/infrastructure/browsing-assets.md): View, filter, sort, and customize the infrastructure inventory table, and inspect an individual asset in the preview drawer. - [Infrastructure overview](https://docs.kikimora.io/infrastructure/index.md): The central read-only inventory of every known asset across your digital footprint, and the upstream sources that populate it. - [Creating a manual vulnerability](https://docs.kikimora.io/manual-tests/creating-a-manual-vulnerability.md): Log a finding discovered during manual testing through the six-step New Vulnerability wizard, with field constraints and validation messages. - [Editing a manual vulnerability](https://docs.kikimora.io/manual-tests/editing-a-manual-vulnerability.md): Update a manual finding through the standard vulnerability edit form and return to the manual test you started from. - [Manual tests overview](https://docs.kikimora.io/manual-tests/index.md): Run human-driven security assessments alongside automated scanning, using checklists to structure the work and feeding findings into the central vulnerability repository. - [Working with checklists](https://docs.kikimora.io/manual-tests/working-with-checklists.md): Open a manual test's checklist, inspect individual checks, and record a Pass, Failed, or N/A assessment against each one. - [Risk management overview](https://docs.kikimora.io/risk-management/index.md): How Kikimora scores findings in the context of your environment, what portfolio impact points measure, and how the module connects to the rest of the platform. - [Reading the risk table](https://docs.kikimora.io/risk-management/reading-the-risk-table.md): Analyze findings in the risk table — column meanings, the Kikimora Score pill, portfolio points, sorting, and keyword filtering. - [Understanding the charts](https://docs.kikimora.io/risk-management/understanding-the-charts.md): Interpret the CVE Frequency matrix, the Kikimora Score vs CVSS scatter plot, and the portfolio composition widget, and filter each one. - [Creating a scheduled scan](https://docs.kikimora.io/scans/creating-a-scheduled-scan.md): Walk through the three-step Launch New Scan wizard, covering general information, schedule and recurrence options, and the review summary. - [Editing a scheduled scan](https://docs.kikimora.io/scans/editing-a-scan.md): Change the configuration or schedule of an existing scheduled scan, and see which fields are locked once the scan exists. - [Scans overview](https://docs.kikimora.io/scans/index.md): How Kikimora separates scheduled scan definitions from individual scan runs, what each status means, and which modules feed into scanning. - [Reading the scans list](https://docs.kikimora.io/scans/reading-scheduled-scans.md): Navigate the Scans table, understand each column, apply filters and sorting, and recognize a scheduled scan row at a glance. - [Rescanning an application](https://docs.kikimora.io/scans/scan-again.md): Re-run a finished scan with the same parameters using the Scan Again action. - [Inspecting scan runs](https://docs.kikimora.io/scans/scheduled-scan-runs.md): Expand a scheduled scan row to inspect its individual executions, read the per-run columns, and reach historical results. - [Viewing scan results](https://docs.kikimora.io/scans/viewing-results.md): Open the results of a finished scan and read the findings table, including CVE identifiers, CVSS and Kikimora scores, impact, and status. - [Activity logs](https://docs.kikimora.io/vulnerabilities/activity-logs.md): Open a finding's activity timeline to audit its history, and record manual progress notes against it. - [Browsing and filtering](https://docs.kikimora.io/vulnerabilities/browsing-and-filtering.md): Navigate the vulnerabilities table — read the summary stat cards, configure visible columns, apply advanced filters, and sort or page through findings. - [Editing a vulnerability](https://docs.kikimora.io/vulnerabilities/editing-a-vulnerability.md): Update a finding's metadata, status, risk scoring, request and response payloads, and proof-of-concept evidence. - [Vulnerabilities overview](https://docs.kikimora.io/vulnerabilities/index.md): Kikimora's central repository for security findings — where they come from, the statuses they move through, and how severity, Kikimora Score, and time to resolve are defined. - [Previewing a vulnerability](https://docs.kikimora.io/vulnerabilities/previewing-a-vulnerability.md): Open the preview sidepanel to inspect a finding's metadata, risk scoring, and technical evidence without leaving the findings list. - [Kikimora Score breakdown](https://docs.kikimora.io/vulnerabilities/score-breakdown.md): Open the score breakdown panel on any finding to see the five factors behind its Kikimora Score and how many points each one contributed. - [Creating a web application](https://docs.kikimora.io/web-applications/creating-a-web-application.md): Work through the four-step setup wizard, including target scope, scan configuration, inline auth record creation, and every field validation message. - [Editing a web application](https://docs.kikimora.io/web-applications/editing-a-web-application.md): Update an existing web application's parameters and owner assignments, and what to expect from pre-filled fields and post-save navigation. - [Web applications overview](https://docs.kikimora.io/web-applications/index.md): Web application entries define the targets, crawl scope, and authentication that Kikimora's Qualys-backed scanners need before any web scan can run. - [Viewing application details](https://docs.kikimora.io/web-applications/viewing-details.md): Navigate a web application's details view, read its vulnerabilities tab and last scan information, and preview individual findings inline.