Workbench

Workbench is the product. Sign in at https://workbench.eresussec.com.

This marketing site is not in the auth path. Reconnect keeps the screen you were on: Dashboard, Findings, HTTP Records, Admin.

The left navigation is the map. It is grouped the same way the work is grouped.

Overview

Dashboard is the current project. It shows risk posture (Critical / High / Medium / all recorded findings), immediate actions when something is waiting, latest findings, a live assessment pipeline when a scan is running, and recent OAST callbacks. Last successful assessment and active status sit in the header. Start assessment launches New Scan for that project.

Workbench dashboard with risk posture, immediate actions, and latest findings
Workbench dashboard with risk posture, immediate actions, and latest findings

Projects is the portfolio. Create or select the project that owns the target before you scan. Scans, findings, HTTP records, and scope do not float across projects.

Workbench projects list with project ownership and launch actions
Workbench projects list with project ownership and launch actions

Assess

New Scan is authorized web and API DAST. You confirm the project, the target, profile, modules, and authentication before the run starts. A discovered link is an observation, not an automatic scope change.

New Scan setup for an authorized web target
New Scan setup for an authorized web target

SAST Scan is source analysis on a pinned snapshot: credential-free HTTPS repository, connected repository, or upload. It is not a live-target setup screen.

Source analysis setup with repository URL and upload
Source analysis setup with repository URL and upload

Active Scan is the run in progress. Processed-record count and status live here. Pause or stop from Workbench if the target becomes unstable.

Scan History is every finished or stopped run in the project: status, duration, findings, re-run, SARIF export when your plan includes it.

Scan history with status, duration, and export actions
Scan history with status, duration, and export actions

Ingest accepts URL, URL list, cURL, captured HTTP, OpenAPI, or Postman. Whatever you paste lands in the same project and the same evidence pipeline.

Ingest panel for URL, cURL, OpenAPI, and Postman inputs
Ingest panel for URL, cURL, OpenAPI, and Postman inputs

Investigate

Findings is the triage list. Filter by severity, status, module, and project. Open a row for module, status, and linked HTTP or OAST evidence. Do not export a finding you have not opened.

Findings inventory filtered by severity, module, and status
Findings inventory filtered by severity, module, and status

HTTP Records is the request and response trail for the same project. Use it to see what was sent, what came back, and which identity was in use. Sensitive values may be redacted; the sequence still has to be reviewable.

HTTP records with captured request and response
HTTP records with captured request and response

OAST is out-of-band callbacks on that trail. A callback without a reviewed finding is not a conclusion.

OAST callback list for the current project
OAST callback list for the current project

Plugins (Modules) is coverage you enable on the project. It is not a CLI catalog.

Modules selected for a scoped assessment
Modules selected for a scoped assessment

Extensions is the extension inventory for the workspace, managed in Workbench, not from a customer plugin store.

Extensions inventory in Workbench
Extensions inventory in Workbench

Report

Reports, Trends, OWASP, Framework Map, and SOC2 Evidence use the same project evidence. They are operator views. They are not a certification, and they are not a substitute for opening a finding.

Administration

MSSP is portfolio operations for the MSSP tier.

Users & RBAC is people and roles.

Authentication is OIDC/SAML for Enterprise.

CI/CD Tokens are provisioned callers. This marketing site does not list an API host.

SLA tracks open findings against the policy you saved.

Workbench users and administration
Workbench users and administration

Web Analysis Engine lives under Settings → Components: install, update, repair, rollback. It is a separately signed component, not embedded Chromium.

Web Analysis Engine in Settings → Components
Web Analysis Engine in Settings → Components

Configuration is workspace settings that belong in Workbench, not in a local scanner config file.

Need a workflow that is not documented here? Email contact@eresussec.com.