EcomScan records stores, scans, findings, alerts, incidents, threat intelligence, and agent health in a tenant-isolated API. The views below describe workflows the repository supports today.
The enterprise entitlement set supports a large store limit, fleet overview, shared-threat queries, agent status, and response runbook checklists. Per-client tenancy, white-labeling, and client billing are not implemented.
Scan store files, optional platform databases, installed components, file changes, and supported host evidence. Findings preserve paths, signatures, severity, confidence, and investigation context.
Use generated and operator-authored runbooks as checklists, record notes and resolution, and export incident data. External providers can be configured and tested manually; automatic delivery is not enabled yet.
Query alerts, incidents, findings, IOC data, malware families, audit records, and MITRE identifiers through authenticated API routes. Use provider connection tests before wiring your own operational delivery path.
Start with the free workspace entitlement or review the scanner and API documentation first.