Skip to main content

Getting started

This is the shortest path from a new account to useful results. Five steps, and the first two matter more than they look: almost everything the CyberOptix CTEM Platform does is scoped to an organization and unlocked by a verified domain.

When you first sign in you will see the Welcome Guide, which links to each of these steps. This page explains what each one does and how to tell it worked.

Screenshot pending

SCREENSHOT: the Welcome Guide on first sign-in, showing the onboarding steps.

1. Create an organization​

An organization is the top-level container. Assets, findings, integrations, users, and permissions all belong to one, and nothing is shared between them unless you explicitly make it so.

If you are a service provider, you will have one per client. If you are a single business, you will usually have exactly one.

Open Organizations, click Add, and fill in:

Screenshot pending

SCREENSHOT: the Add Organization form with its fields.

FieldNotes
NameThe organization or client name
NicknameA short alias, used where space is tight
Primary domainThe domain you will verify in step 2
EnabledOff means the organization exists but is dormant
OngoingOn for continuous monitoring, off for a point-in-time engagement

Then switch into it using the organization selector in the top navigation. Until you do, most screens have nothing to show you - they are scoped to an organization and you have not chosen one.

2. Verify your domain​

Domain verification proves you own a domain before the platform will search for exposed credentials and leaked data relating to it. That gate exists so nobody can point breach-data monitoring at a domain they do not control.

Until a domain is verified, identity exposure and dark web monitoring do not run for it.

Open Administration → Public DNS. Each domain shows a verification code that looks like this:

Screenshot pending

SCREENSHOT: the Public DNS page showing a verification code and the two copy icons.

cyberoptix-verification=8rAzUDvLEh142LLZ

That single string is two values, and this is where people go wrong: the part before the = is the record name, and the part after it is the record value.

FieldValue
TypeTXT
Namecyberoptix-verification.your-domain.com
Value8rAzUDvLEh142LLZ
TTL300, or your provider's default
Do not paste the whole string as the value

Verification matches the TXT value against the code exactly. A record whose value is cyberoptix-verification=8rAzUDvLEh142LLZ will never match, because the expected value is just 8rAzUDvLEh142LLZ.

The two copy icons next to the code exist for this reason: one copies the record name, the other copies the value. Use them rather than copying the displayed text.

The platform re-checks periodically, so nothing further is needed once the record is live. DNS propagation can take up to 48 hours, though it is usually minutes. The domain shows as Verified when the record is found.

If it stays unverified, query the record yourself - this is the same lookup the platform performs:

dig +short TXT cyberoptix-verification.your-domain.com

If that returns nothing, the record has not propagated or was created at the wrong name. If it returns the code wrapped in extra text, the value contains more than it should.

3. Define what to scan​

Verification enables external monitoring, which needs nothing from you. Scanning your internal estate needs scope.

Scope is built from zones: a zone holds subnets and URLs, and has a scanner group assigned to it. See Zones, subnets, URLs, and tags for the detail, and Deployment if you need a scanner in the first place.

You can skip this step initially. External attack surface discovery begins as soon as a domain is verified, so there will be results to look at either way.

4. Review your attack surface​

Discovery starts automatically once a domain is verified. Within the hour you should see hosts, services, web applications, and certificates appear under Attack Surface.

This is the answer to "what do we actually have exposed", and it is frequently the first surprise: hosts nobody remembered, services that should not be public, certificates about to expire.

5. Check identity exposure​

Identity Exposure → Breach Records shows credentials and personal data for your verified domains that have appeared in known breaches.

Unlike the attack surface, this describes exposure that already happened. Treat anything recent as actionable now - a valid credential in a breach corpus does not become less valid because the breach is old.

6. Work your first finding​

Open Findings, sort by severity, and take one.

A finding tells you what was found, where, how severe it is, and what to do about it. Working one end to end - reading it, assigning it, fixing it, confirming it closes - is the fastest way to understand how the platform expects you to operate.

Findings, severity, and risk explains how severity is decided, which is worth reading before you sort by it and start at the top.

Where to go next​

If you want toGo to
Understand the model underneath all of thisConcepts
Scan internal networksDeployment
Connect cloud accounts or source controlIntegrations
Add your teamUsers
Collect logs and run detectionsSecurity Operations