First authorized assessment

The first Eresus Guard assessment belongs in Workbench, not in the CLI.

Open https://workbench.eresussec.com, choose a Project, and start a Scan against an authorized staging target.

New Scan setup for an authorized staging target
New Scan setup for an authorized staging target

Do not run eresus-guard scan. That command is not the customer product.

Before you start

  • The organization has Professional, Business, Enterprise, or MSSP access
  • You can log in or use SSO
  • The target, identities, and exclusions are written and authorized
  • The Web Analysis Engine is healthy under Settings → Components if the assessment needs a browser-backed path

In Workbench

  1. Open Projects and create or select the staging project.
  2. Start New Scan (web/API) or SAST Scan (source). Enter only authorized hosts or an authorized source snapshot.
  3. Attach approved modules, extensions, and test identities. Production user sessions stay out.
  4. Confirm the authorization gate, metadata IP blocking, and exclusions.
  5. Launch from Workbench. Watch Dashboard or Active Scan. Pause or stop from Workbench if the target becomes unstable.
  6. Triage in Findings. Open the finding, then HTTP Records or OAST before you export.

Findings after the first authorized run
Findings after the first authorized run

A pause is a safety action, not a failed run.

After the first run

Refine exclusions, identities, and module selection in the same project. Re-run from Scan History only while authorization still holds.

Then read:

Need a workflow that is not documented here? Email contact@eresussec.com.