Modules and extensions
Coverage is selected in Workbench. Modules and extensions belong to a project. They are not enabled by turning the CLI into a scanner.
Modules
Modules are the detection catalog available to an authorized assessment.
When you set up a scan in Workbench:
- Open the project
- Choose the modules that match the authorized surface
- Confirm scope and identities
- Start the assessment from Workbench
Module output lands in Findings, with HTTP Records and OAST callbacks attached when those records exist.

Typical surfaces:
- Authenticated web and API assessments
- Source review
- Dependency inventory
- Infrastructure files
- Secrets in project artifacts
See Coverage for the public map of those surfaces.
Extensions
Extensions are approved add-ons. Enable them from the Workbench Extensions area. They run inside the same authorization boundary and write into the same evidence trail.

What not to do
- Do not start modules from an
eresus-guard scantutorial - Do not expect local non-MSSP module execution
- Do not treat agent follow-up as a replacement for modules
Agent-assisted work, when enabled, still writes into the same project. It does not replace native modules.
Related
Need a workflow that is not documented here? Email contact@eresussec.com.