Modules and extensions

Coverage is selected in Workbench. Modules and extensions belong to a project. They are not enabled by turning the CLI into a scanner.

Modules

Modules are the detection catalog available to an authorized assessment.

When you set up a scan in Workbench:

  1. Open the project
  2. Choose the modules that match the authorized surface
  3. Confirm scope and identities
  4. Start the assessment from Workbench

Module output lands in Findings, with HTTP Records and OAST callbacks attached when those records exist.

Modules catalog enabled on the project
Modules catalog enabled on the project

Typical surfaces:

  • Authenticated web and API assessments
  • Source review
  • Dependency inventory
  • Infrastructure files
  • Secrets in project artifacts

See Coverage for the public map of those surfaces.

Extensions

Extensions are approved add-ons. Enable them from the Workbench Extensions area. They run inside the same authorization boundary and write into the same evidence trail.

Extensions inventory in Workbench
Extensions inventory in Workbench
Do not sideload unsigned extensions. If an extension is missing from the workspace, it has not been approved for that plan or has not been enabled by an administrator.

What not to do

  • Do not start modules from an eresus-guard scan tutorial
  • Do not expect local non-MSSP module execution
  • Do not treat agent follow-up as a replacement for modules

Agent-assisted work, when enabled, still writes into the same project. It does not replace native modules.

Need a workflow that is not documented here? Email contact@eresussec.com.