Reveal
Reveal is a Sekoia add-on module that adds asset intelligence to your investigation workflows. It enriches the asset context panel with vulnerability data, endpoint hygiene, behavioral signals, and attack path analysis.
Use Reveal to answer questions that alerts alone cannot answer:
- What is this asset, and is it vulnerable or poorly protected?
- What activity has occurred around it recently?
- Which other assets could it put at risk?
Security teams investigate in two directions. Reactive investigations start from an alert, case, or detection. Proactive investigations start from a risk or exposure question. Reveal supports both by giving analysts the context they need to understand what an asset is, how it is protected, and what it connects to.
What Reveal provides
| Capability | Description |
|---|---|
| Asset context panel | Extends the core panel with hygiene, vulnerabilities, security controls, points of interest, and attack path visualization |
| Asset Connectors | Connects external systems such as EDR tools, vulnerability scanners, and identity providers to create and enrich asset records |
| Points of Interest | Surfaces behavioral anomalies on assets that may not trigger alerts, such as unusual authentication patterns or rare locations |
| Endpoint Hygiene | Shows firewall and disk encryption status for host assets |
| Vulnerability enrichment | Lists known CVE exposures affecting an asset, aggregated from connected scanners |
| Security controls | Shows which detection and protection technologies cover an asset and where gaps exist |
| Attack Path Visualization | Maps relationships between assets to help analysts assess lateral movement risk and blast radius |
How Reveal fits into your workflows
Reveal is designed to enrich the workflows analysts already use.
During a reactive investigation, an analyst starts from an alert or case. Reveal adds context about the involved asset: its identity, posture, exposure, recent activity, and relationships, so the analyst can assess priority, scope, and impact without pivoting to external tools.
During a proactive investigation, an analyst looks for assets that may require attention before an incident occurs. Reveal surfaces vulnerable, poorly protected, or unusually active assets so teams can prioritize remediation early.
Get started
To enable and configure Reveal, follow the Getting started with Reveal guide. It describes the required data sources, the recommended setup order, and how to validate each capability.
Related links
- Collect — Assets: Documentation on how assets are configured, discovered, and managed in Sekoia.
- Detection — IOC detection: Overview of detection capabilities in Sekoia, including rule-based and analytics-driven approaches.
- Integration — Asset categories: Reference for asset connector categories and integration setup.