Skip to content
VITI Security

Blog · Tag

#Vexta

24 articles

Why Vexta's Findings Never Leave Your Machine - VITI Security
Penetration Testing & VAPT

Why Vexta's Findings Never Leave Your Machine

Vexta stores every scan, finding and asset in a local database on the machine it runs on, with no findings sent to a cloud backend, so client data stays where it was collected.

Sep 26, 2026Read
Deploying Vexta on an Air-Gapped or Offline Network - VITI Security
Penetration Testing & VAPT

Deploying Vexta on an Air-Gapped or Offline Network

Vexta runs as a single self-hosted binary with modest hardware needs, and its core scanning features do not depend on internet access, making it practical to run on an air-gapped or segmented network.

Sep 26, 2026Read
Automating Vexta with Its REST API: Jobs, Scans and Assets - VITI Security
Penetration Testing & VAPT

Automating Vexta with Its REST API: Jobs, Scans and Assets

Vexta exposes a REST API under /api/v1/ to create scans, poll job status, pull scan data and assets, and trigger AI insight or takeover verification, so scanning can be driven from your own tooling.

Sep 26, 2026Read
How Vexta Keeps an Authorized Scan Polite and In Scope - VITI Security
Penetration Testing & VAPT

How Vexta Keeps an Authorized Scan Polite and In Scope

Vexta routes every request through a centralized HTTP client with adaptive rate limiting, jitter and scope enforcement, so scans stay gentle on the target and every request is logged.

Sep 26, 2026Read
Vexta's Audit Log and Active Session Management - VITI Security
Penetration Testing & VAPT

Vexta's Audit Log and Active Session Management

Vexta logs every login, logout and password change, and lets an owner or admin see every active session on the instance and revoke any of them on the spot.

Sep 26, 2026Read
Vexta's Per-Host Recon Depth on Every Asset Row - VITI Security
Penetration Testing & VAPT

Vexta's Per-Host Recon Depth on Every Asset Row

Every row on Vexta's Assets tab carries identity, ports, banners, an OS guess with its evidence, a TLS summary and a screenshot, so a hunter isn't reopening five tabs to piece a host together.

Sep 26, 2026Read
Vexta's Cloud Configuration Auditing for AWS, Azure and GCP - VITI Security
Penetration Testing & VAPT

Vexta's Cloud Configuration Auditing for AWS, Azure and GCP

Vexta enumerates AWS, Azure and GCP resources, tests S3 bucket permissions directly, and adds every cloud resource it finds as a node in its attack graph.

Sep 26, 2026Read
Vexta's Education Module: Why Every Finding Explains Itself - VITI Security
Penetration Testing & VAPT

Vexta's Education Module: Why Every Finding Explains Itself

Every Vexta finding includes a plain-language answer to what the vulnerability is and why it matters, plus the relevant CWE and OWASP references, attached directly to the finding.

Sep 26, 2026Read
How Vexta's Update System Keeps Your Scanner Current - VITI Security
Penetration Testing & VAPT

How Vexta's Update System Keeps Your Scanner Current

Vexta checks for updates every 24 hours and lets you pick a stable, beta or dev channel, with auto-download separated from apply so you decide exactly when a new build takes effect.

Sep 26, 2026Read
Vexta's Script Engine: 26 Bundled Checks Without an Nmap Dependency - VITI Security
Penetration Testing & VAPT

Vexta's Script Engine: 26 Bundled Checks Without an Nmap Dependency

Vexta runs a built-in script engine across every open port it finds, 26 bundled checks in pure Go, with an NSE-style filter language and no external nmap install required.

Sep 26, 2026Read
Vexta's DNS Resolver Pool for Reliable Recon - VITI Security
Penetration Testing & VAPT

Vexta's DNS Resolver Pool for Reliable Recon

Vexta keeps a self-validating pool of public DNS resolvers, ranked by latency and reliability, so subdomain enumeration and takeover checks don't silently fail on a dead or throttled resolver.

Sep 26, 2026Read
Vexta's Per-Host Screenshot Snapshot Bundle - VITI Security
Penetration Testing & VAPT

Vexta's Per-Host Screenshot Snapshot Bundle

Vexta bundles a host's screenshot, identity, OS guess, open ports, TLS cert, tech fingerprint and NSE script output into one document, one click per row.

Sep 26, 2026Read
Vexta ASPM: Asset Criticality Levels and SLA Bands - VITI Security
Penetration Testing & VAPT

Vexta ASPM: Asset Criticality Levels and SLA Bands

Vexta's ASPM module classifies every asset by criticality and chains it to nearby findings, so a bug near a crown-jewel asset gets a different SLA than the same bug on a brochure site.

Sep 26, 2026Read
How Vexta's CISA KEV Coverage Tracker Works - VITI Security
Penetration Testing & VAPT

How Vexta's CISA KEV Coverage Tracker Works

Vexta shows what percentage of the CISA Known Exploited Vulnerabilities catalog it currently probes for, right at the top of the dashboard, and keeps that number synced daily.

Sep 26, 2026Read
Reliability Badges and False-Positive Tracking in Vexta - VITI Security
Penetration Testing & VAPT

Reliability Badges and False-Positive Tracking in Vexta

Vexta labels every finding with a reliability badge and tracks each detector's false-positive rate over time, so a hunter knows how much to trust a result before spending time on it.

Sep 26, 2026Read
Per-Finding Triage State in Vexta - VITI Security
Penetration Testing & VAPT

Per-Finding Triage State in Vexta

Vexta tracks a status, note, and assignee on every finding, open through paid or wontfix, visible as a badge and editable from the CLI or dashboard.

Sep 26, 2026Read
Cross-Scan Finding Deduplication in Vexta - VITI Security
Penetration Testing & VAPT

Cross-Scan Finding Deduplication in Vexta

Vexta fingerprints every finding by target, type, URL, parameter, and payload signature, so repeat scans flag re-discoveries instead of duplicating them.

Sep 26, 2026Read
Finding Lifecycle Metrics: MTTR and KPIs in Vexta - VITI Security
Penetration Testing & VAPT

Finding Lifecycle Metrics: MTTR and KPIs in Vexta

Vexta tracks MTTR, defect density, recurrence rate, and SLA breaches per finding, computed from real scan and fix data rather than a separate tracker.

Sep 26, 2026Read
Compliance Mapping in Vexta: OWASP, NIST, PCI-DSS, SOC 2 - VITI Security
Penetration Testing & VAPT

Compliance Mapping in Vexta: OWASP, NIST, PCI-DSS, SOC 2

Vexta auto-tags findings to OWASP, NIST 800-53, PCI-DSS, and SOC 2 controls and builds a compliance-specific PDF report with evidence per control.

Sep 26, 2026Read
Wordlist Management in Vexta: Custom Lists for Recon - VITI Security
Penetration Testing & VAPT

Wordlist Management in Vexta: Custom Lists for Recon

Vexta lets a hunter upload, edit, and pick custom subdomain, directory, and parameter wordlists per scan, so recon fits the target instead of a generic list.

Sep 26, 2026Read
Vexta Notifications: Getting New Findings into Slack, Discord or Email - VITI Security
Penetration Testing & VAPT

Vexta Notifications: Getting New Findings into Slack, Discord or Email

Vexta pushes new findings out to Slack, Discord, Telegram, Pushover, email, Google Chat, Microsoft Teams or a custom webhook, with multiple instances of each channel and templated messages.

Sep 26, 2026Read
Targeted Subscans in Vexta: Rescan One Endpoint Without Redoing the Whole Job - VITI Security
Penetration Testing & VAPT

Targeted Subscans in Vexta: Rescan One Endpoint Without Redoing the Whole Job

Vexta's targeted subscans run a single module, like a port scan or a directory bruteforce, against one subdomain, endpoint or IP, instead of forcing a full rescan to check one thing.

Sep 26, 2026Read
Scheduled Scans in Vexta: Cron Jobs and the Scan Queue Explained - VITI Security
Penetration Testing & VAPT

Scheduled Scans in Vexta: Cron Jobs and the Scan Queue Explained

Vexta can run scans on a cron schedule in the background, tracking each one through a job queue with real-time progress, so a hunter does not have to remember to kick off the same scan every week.

Sep 26, 2026Read
Vexta's 7 Team Roles: Who Gets to Scan, Fix, Bill or Just Watch - VITI Security
Penetration Testing & VAPT

Vexta's 7 Team Roles: Who Gets to Scan, Fix, Bill or Just Watch

Vexta's role-based access control splits a team into 7 roles, from Owner down to read-only Viewer, so a scan platform used by more than one person does not need to give everyone the same keys.

Sep 26, 2026Read