Platform Tour

See XHack in Action

Explore every tool in the XHack security platform, from real-time threat detection to AI-powered vulnerability scanning and adversarial AI testing.

Access is granted after identity verification. These are real offensive-security tools, so we confirm who is holding them first, before any payment. How verification works

Request a Demo

39

Screenshots

10

Product Areas

100%

Real UI
Identity Verification
Dashboard
SOC Dashboard
Vulnerability Assessment
GitGuard
AI Probe
AI Chat
AI Models & Skills
Assets
Notifications
Settings & Administration
Identity Verification
How access is granted
Learn more

Nothing below is reachable until your identity is verified. XHack hands out real offensive capability: an agent that runs with root privileges, live vulnerability scanning, exploit generation. We confirm who is holding it before we hand it over. Verification happens before payment: you are never charged while your application is reviewed, and if we cannot approve you there is nothing to refund. Most decisions land within one business day, and approval is what unlocks plan selection, workspace creation, and every feature on this page.

Individual — Identity
Click to enlarge
Individual — Identity
Upload both sides of a government ID or passport. The form advances to the reverse on its own once the front lands, and the checklist tracks what is still outstanding.
Individual — Credentials
Click to enlarge
Individual — Credentials
Researcher accounts are approved on expertise, so at least one certification or diploma is required: OSCP, CEH, CISSP, or a security-related degree. A public verification link speeds up review considerably.
Individual — LinkedIn
Click to enlarge
Individual — LinkedIn
Optional. A public profile gives the reviewer a second, independent sighting of you, but the decision rests on your documents.
Individual — Review & submit
Click to enlarge
Individual — Review & submit
Everything outstanding is listed above the submit button, with required items separated from optional ones. Submission is refused until the required list is clear.
Company — Identity
Click to enlarge
Company — Identity
The owner setting the organisation up proves their own identity first, exactly as an individual would.
Company — Business documents
Click to enlarge
Company — Business documents
Certificate of incorporation, tax/VAT registration, and proof of address. None of these block submission, since a reviewer requests what they need, but including them up front usually turns a two-day review into a same-day one.
Company — Business information
Click to enlarge
Company — Business information
Registered legal name, company number, and country of incorporation. These do gate submission: they are what a reviewer uses to find the company on a public register.
Company — Review & submit
Click to enlarge
Company — Review & submit
Once approved, the organisation itself is verified, and colleagues you invite inherit that verification instead of each submitting their own documents.
Dashboard
Your security command centre

A single overview of your entire security posture. See active alerts, recent incidents, scan results, and team activity at a glance.

Dashboard Overview
Click to enlarge
Dashboard Overview
Real-time summary of security events, alerts, incidents, and team activity across your organisation.
SOC Dashboard
Security operations centre
Learn more

Ingest security logs from Cloudflare, Wazuh, and custom sources. Detect threats with custom rules, stack alerts intelligently, correlate attack chains, and manage incidents with SLA tracking.

SOC Overview
Click to enlarge
SOC Overview
High-level view of your security operations, event counts, severity breakdown, active alerts, and detection status.
Security Events
Click to enlarge
Security Events
Real-time stream of normalised security events from all connected sources with severity filtering and search.
Alerts
Click to enlarge
Alerts
Alerts generated by detection rules. Stacked alerts group repeated attacks from the same source into a single expandable view.
Stacked Alert — Expanded
Click to enlarge
Stacked Alert — Expanded
Expand a stacked alert to see every individual event, with normalised data cards and raw payload for each.
Incidents
Click to enlarge
Incidents
Confirmed security incidents with severity, assignee, SLA status, and linked alerts. Full lifecycle tracking.
Incident Detail
Click to enlarge
Incident Detail
Complete incident timeline showing all linked events, alerts, AI analysis, status changes, and team notes.
Attack Chains
Click to enlarge
Attack Chains
Multi-stage attacks automatically correlated using MITRE ATT&CK kill chain stages with dual-severity scoring.
Attack Chain Detail
Click to enlarge
Attack Chain Detail
Drill into an attack chain to see the kill chain progression, contributing events, and severity assessment.
Detection Rules
Click to enlarge
Detection Rules
18 operators, nested AND/OR groups, threshold rules, and framework-aware false positive suppression. AI can generate rules from natural language.
Log Sources
Click to enlarge
Log Sources
Connect Cloudflare, Wazuh, custom webhooks, and the XHack log wrapper. Monitor connection health and ingestion rates.
Threat Intelligence
Click to enlarge
Threat Intelligence
IOC enrichment, threat feeds, and IP/domain reputation lookups integrated directly into your event analysis.
SOC Agents
Click to enlarge
SOC Agents
Deploy and manage lightweight agents in your infrastructure for direct log forwarding.
Agent Configuration
Click to enlarge
Agent Configuration
Configure agent connection settings, log types, and forwarding rules per deployment.
Webhooks
Click to enlarge
Webhooks
Outbound webhooks for real-time alert and incident notifications to Slack, Teams, PagerDuty, or custom endpoints.
Suppressions
Click to enlarge
Suppressions
Suppress known false positives by IP, rule, or pattern without disabling detection rules entirely.
SOC Reports
Click to enlarge
SOC Reports
Generate professional security assessment reports with severity breakdown, timeline, and remediation guidance.
SOC Settings
Click to enlarge
SOC Settings
Configure correlation windows, SLA thresholds, notification preferences, and data retention policies.
Vulnerability Assessment
Scan, analyse, and act
Learn more

Register your assets, run AI-driven vulnerability scans, watch results come in live, and generate actionable reports with mitigation plans.

VA Dashboard
Click to enlarge
VA Dashboard
Overview of registered assets, recent scans, and vulnerability statistics across your infrastructure.
Live Scan Progress
Click to enlarge
Live Scan Progress
Watch vulnerabilities appear in real time as the scan runs. No need to wait for the final report.
Scan Findings
Click to enlarge
Scan Findings
All discovered vulnerabilities with severity, location, and recommended fixes, ready for triage.
Vulnerability Detail
Click to enlarge
Vulnerability Detail
Full technical breakdown including exploit scenario, impact assessment, and AI-generated remediation guidance.
GitGuard
AI-powered PR protection
Learn more

Connect your GitHub repositories and let GitGuard scan every pull request for security vulnerabilities before code reaches your main branch.

GitGuard Dashboard
Click to enlarge
GitGuard Dashboard
Connected repositories, scan history, and finding statistics across your organisation.
Repository Detail
Click to enlarge
Repository Detail
Per-repository scan history with findings breakdown and latest PR scan results.
PR Scan Results
Click to enlarge
PR Scan Results
AI-analysed code changes with security findings, severity classification, and remediation suggestions.
AI Probe
Adversarial AI testing
Learn more

Test your AI systems against 350+ attack payloads across the OWASP LLM Top 10. Detect prompt injection, data leaks, jailbreaks, and safety failures.

AI Probe Dashboard
Click to enlarge
AI Probe Dashboard
Overview of all scans with security scores, grades, and severity breakdown per scan.
Scan Findings
Click to enlarge
Scan Findings
Tabbed view of vulnerable, safe, and other findings with severity chips, scores, and AI judge reasoning.
Escalate — Interactive Bypass Testing
Click to enlarge
Escalate — Interactive Bypass Testing
Continue probing a vulnerability in an interactive chat. AI generates bypass payloads based on conversation context.
AI Chat
Your security AI assistant

Chat with the XHack AI for security analysis, threat assessment, vulnerability research, and general cybersecurity guidance.

AI Chat
Click to enlarge
AI Chat
Interactive AI assistant for security research, threat analysis, and vulnerability investigation.
AI Models & Skills
Tune the AI to your work
Learn more

Make the AI yours. Bring your own provider key, choose the exact model behind every chat and agent run, load reusable skill packs that sharpen it for a specific job, and read text straight out of screenshots and PDFs. The XHack engine stays the same (instructions, guardrails, tool routing); you decide what powers it.

AI Models — Bring Your Own Key
Click to enlarge
AI Models — Bring Your Own Key
Connect your own OpenAI, Claude, Gemini, GLM, Mistral, xAI, or OpenRouter key and pick the model that runs your chats and agent, while still using XHack’s engine, guardrails, and tools.
AI Skills
Click to enlarge
AI Skills
Import and activate reusable skill packs for offensive AD, cloud, web, recon and more, each focusing the AI on a specific discipline. Toggle them on and off within a token budget.
Image Reading (OCR)
Click to enlarge
Image Reading (OCR)
Point a vision model at a screenshot or PDF and pull the text straight out, feed a scanned report, a captured request, or a whiteboard photo into the AI without retyping a thing.
Assets
Asset inventory

Register and manage your organisation's digital assets in one verified inventory: domains, subdomains, IPs, APIs, and web applications.

Asset Management
Click to enlarge
Asset Management
Registered assets with verification status, scan history, and quick-launch options.
Notifications
Stay informed

Real-time in-app notifications for security events, scan completions, incident updates, and team activity.

Notification Centre
Click to enlarge
Notification Centre
Centralised notifications with severity indicators, direct links to relevant pages, and bulk management.
Settings & Administration
Full control

Manage your organisation, team members, roles and permissions, API keys, and integrations, all from a centralised settings panel with fine-grained access control.

Organisation Settings
Click to enlarge
Organisation Settings
Configure your organisation profile, branding, domain, and general workspace preferences.
Team Members
Click to enlarge
Team Members
Invite and manage team members with role assignment, MFA enforcement, and access control.
Roles & Permissions
Click to enlarge
Roles & Permissions
Define custom roles with granular permissions. Control who can view, manage, or configure each platform feature.
API Keys
Click to enlarge
API Keys
Generate and manage API keys for programmatic access. Track usage, set expiry dates, and revoke instantly.
Integrations
Click to enlarge
Integrations
Connect third-party tools and services: GitHub, Cloudflare, Wazuh, Slack, and custom webhooks.

Ready to Secure Your Organisation?

Get a personalised walkthrough of the platform with your team. No commitment, no credit card required.