Ethiack Docs

Version 3.0

Release notes for Ethiack Portal version 3.0, released 2026-06-30.

Version 3.0 is the biggest update to Ethiack since launch. The portal was rebuilt from the ground up, visually, structurally, and functionally, to reflect what the platform has become: a single place to run continuous adversarial exposure validation and on-demand pentests, on your terms.

🚀 Features

✨ A New Look: Cleaner, Modern, Cosmic

Every screen was redesigned to cut noise and sharpen focus. Less clutter. More signal. The risks that matter are always front and center.

The redesigned Ethiack Portal dashboard

🧭 Onboarding That Matches Your Goal

Getting started now begins with a choice: continuous validation or pentest. Each path is purpose-built.

For continuous validation, you can import multiple domains at once via CSV. Asserting ownership is simpler. For pentest, you define assets, set your testing policy, add credentials if needed, and launch. No back-and-forth with the Ethiack team.

🤖 Launch Pentests Directly From the Portal

Hackian-powered agentic pentests can now be launched directly from the portal. Three engagement types:

  • Swift: up to 3 assets, 30 credits. Fast validation for when you need answers now. Results within 24 hours.
  • Depth: up to 5 assets, 50 credits. Supports grey-box testing with credentials for authenticated attack paths. Results within 3 days.
  • Expert: agentic AI and elite human hacker intelligence, working as one offensive force. For the assets where certainty matters most.

Swift and Depth run fully autonomously. Pick your scope, spend your credits, see Hackian working.

Pentest type selection: Swift, Depth, Expert, and Continuous Test

📊 Dashboard Rebuilt Around Your Security Posture

At the top: your Risk Score, risk trend, and unresolved vulnerability count. An instant posture snapshot on login. The Security Trends section shows vulnerability data over time alongside your Mean Time to Resolve (MTTR).

Dashboard Quick Insights and Security Trends

The Deep Dive section surfaces critical findings, your most exposed assets, active tests, and latest comments, all without leaving the dashboard.

Dashboard Deep Dive section

🗂️ Asset Details: Deeper Context on Every Asset

The asset listing is cleaner. The new Asset Details page centralizes everything that matters: risk level and importance, IP, provider, location, technology stack, identified vulnerabilities, services, paths discovered, associated tests, and screenshots where available.

Asset details services panel

⏱️ Exploit Timeline: The Full Life of Every Risk

Every finding now includes an Exploit Timeline: a chronological view from when the asset entered scope, to CVE publication, to the moment Hackian validated it on your attack surface.

Three metrics turn raw dates into real insight:

  • Time to Validate (TTV): how fast Ethiack confirmed the exposure once it became relevant.
  • Time to Exploit (TTE): how fast a vulnerability moved from CVE publication to active exploitation in the wild (KEV addition).
  • Time to Remediate (TTR): how long from finding to resolution, whether a fix or accepted risk.

These benchmark your detection and remediation speed against how fast attackers move, in hard numbers.

Exploit Timeline showing Asset Added, CVE Published, TTV, TTE, and TTR milestones

🔎 Findings: More Signal, Less Friction

The findings list cuts low-value noise and leads with critical context. Filtering now lives in a dedicated panel. On the finding detail page, a Quick Info section surfaces the asset, test, CWE, and CVSS score immediately. EPSS score and KEV catalog presence appear in the Risk Indicators panel when relevant: evidence-based exploitability, not theoretical severity.

Findings list with severity, KEV, and EPSS columns
Finding detail page showing Quick Info and Risk Indicators panels

🔍 Content Discovery on Wildcards and Internal Assets

Continuous testing now reaches wildcard domains and internal assets, not just public hosts. Fewer blind spots for organizations with large, dynamic subdomain footprints or internal apps reachable through a beacon.

🌟 Improvements

  • Credits replace hours across the platform to support the flexibility agentic pentest types require. Existing customers will receive separate communication on their credit balance and the conversion from existing hours.
  • Reports, activity, and assistant pages are refreshed on the new design system.
  • Copy IPs and user agents for whitelisting directly from the portal. Update your organization's logo and name from Settings.

🧙 Hackian Engine Features

  • Upgraded continuous test scheduling for more instant detection of new assets and vulnerabilities
  • Real-time reporting of findings, no need to wait for the end of a run to see results
  • Added vulnerability detection modules for GeoNetwork, Zammad, BookStack and GeoDocs

🛠️ Bug Fixes

  • We reduced false-positive sources across our continuous vulnerability modules.
  • Fixed leaked credential matches occasionally pulling in out-of-scope email domains.
  • Fixed multi-line finding steps not rendering correctly in markdown reports.
  • Fixed a scheduling bias where some assets were consistently tested before others.
  • Fixed a stuck queue that could stall content discovery jobs.

Thank you for trusting Ethiack to keep your attack surface visible, validated, and one step ahead of attackers.

On this page