See XHack in Action
Explore every tool in the XHack security platform, from real-time threat detection to AI-powered vulnerability scanning and adversarial AI testing.
Access is granted after identity verification. These are real offensive-security tools, so we confirm who is holding them first, before any payment. How verification works
39
Screenshots10
Product Areas100%
Real UINothing below is reachable until your identity is verified. XHack hands out real offensive capability: an agent that runs with root privileges, live vulnerability scanning, exploit generation. We confirm who is holding it before we hand it over. Verification happens before payment: you are never charged while your application is reviewed, and if we cannot approve you there is nothing to refund. Most decisions land within one business day, and approval is what unlocks plan selection, workspace creation, and every feature on this page.

Individual — Identity
Upload both sides of a government ID or passport. The form advances to the reverse on its own once the front lands, and the checklist tracks what is still outstanding.
Individual — Credentials
Researcher accounts are approved on expertise, so at least one certification or diploma is required: OSCP, CEH, CISSP, or a security-related degree. A public verification link speeds up review considerably.
Individual — LinkedIn
Optional. A public profile gives the reviewer a second, independent sighting of you, but the decision rests on your documents.
Individual — Review & submit
Everything outstanding is listed above the submit button, with required items separated from optional ones. Submission is refused until the required list is clear.
Company — Identity
The owner setting the organisation up proves their own identity first, exactly as an individual would.
Company — Business documents
Certificate of incorporation, tax/VAT registration, and proof of address. None of these block submission, since a reviewer requests what they need, but including them up front usually turns a two-day review into a same-day one.
Company — Business information
Registered legal name, company number, and country of incorporation. These do gate submission: they are what a reviewer uses to find the company on a public register.
Company — Review & submit
Once approved, the organisation itself is verified, and colleagues you invite inherit that verification instead of each submitting their own documents.Dashboard
A single overview of your entire security posture. See active alerts, recent incidents, scan results, and team activity at a glance.

Dashboard Overview
Real-time summary of security events, alerts, incidents, and team activity across your organisation.Ingest security logs from Cloudflare, Wazuh, and custom sources. Detect threats with custom rules, stack alerts intelligently, correlate attack chains, and manage incidents with SLA tracking.

SOC Overview
High-level view of your security operations, event counts, severity breakdown, active alerts, and detection status.
Security Events
Real-time stream of normalised security events from all connected sources with severity filtering and search.
Alerts
Alerts generated by detection rules. Stacked alerts group repeated attacks from the same source into a single expandable view.
Stacked Alert — Expanded
Expand a stacked alert to see every individual event, with normalised data cards and raw payload for each.
Incidents
Confirmed security incidents with severity, assignee, SLA status, and linked alerts. Full lifecycle tracking.
Incident Detail
Complete incident timeline showing all linked events, alerts, AI analysis, status changes, and team notes.
Attack Chains
Multi-stage attacks automatically correlated using MITRE ATT&CK kill chain stages with dual-severity scoring.
Attack Chain Detail
Drill into an attack chain to see the kill chain progression, contributing events, and severity assessment.
Detection Rules
18 operators, nested AND/OR groups, threshold rules, and framework-aware false positive suppression. AI can generate rules from natural language.
Log Sources
Connect Cloudflare, Wazuh, custom webhooks, and the XHack log wrapper. Monitor connection health and ingestion rates.
Threat Intelligence
IOC enrichment, threat feeds, and IP/domain reputation lookups integrated directly into your event analysis.
SOC Agents
Deploy and manage lightweight agents in your infrastructure for direct log forwarding.
Agent Configuration
Configure agent connection settings, log types, and forwarding rules per deployment.
Webhooks
Outbound webhooks for real-time alert and incident notifications to Slack, Teams, PagerDuty, or custom endpoints.
Suppressions
Suppress known false positives by IP, rule, or pattern without disabling detection rules entirely.
SOC Reports
Generate professional security assessment reports with severity breakdown, timeline, and remediation guidance.
SOC Settings
Configure correlation windows, SLA thresholds, notification preferences, and data retention policies.Register your assets, run AI-driven vulnerability scans, watch results come in live, and generate actionable reports with mitigation plans.

VA Dashboard
Overview of registered assets, recent scans, and vulnerability statistics across your infrastructure.
Live Scan Progress
Watch vulnerabilities appear in real time as the scan runs. No need to wait for the final report.
Scan Findings
All discovered vulnerabilities with severity, location, and recommended fixes, ready for triage.
Vulnerability Detail
Full technical breakdown including exploit scenario, impact assessment, and AI-generated remediation guidance.Connect your GitHub repositories and let GitGuard scan every pull request for security vulnerabilities before code reaches your main branch.

GitGuard Dashboard
Connected repositories, scan history, and finding statistics across your organisation.
Repository Detail
Per-repository scan history with findings breakdown and latest PR scan results.
PR Scan Results
AI-analysed code changes with security findings, severity classification, and remediation suggestions.Test your AI systems against 350+ attack payloads across the OWASP LLM Top 10. Detect prompt injection, data leaks, jailbreaks, and safety failures.

AI Probe Dashboard
Overview of all scans with security scores, grades, and severity breakdown per scan.
Scan Findings
Tabbed view of vulnerable, safe, and other findings with severity chips, scores, and AI judge reasoning.
Escalate — Interactive Bypass Testing
Continue probing a vulnerability in an interactive chat. AI generates bypass payloads based on conversation context.AI Chat
Chat with the XHack AI for security analysis, threat assessment, vulnerability research, and general cybersecurity guidance.

AI Chat
Interactive AI assistant for security research, threat analysis, and vulnerability investigation.Make the AI yours. Bring your own provider key, choose the exact model behind every chat and agent run, load reusable skill packs that sharpen it for a specific job, and read text straight out of screenshots and PDFs. The XHack engine stays the same (instructions, guardrails, tool routing); you decide what powers it.

AI Models — Bring Your Own Key
Connect your own OpenAI, Claude, Gemini, GLM, Mistral, xAI, or OpenRouter key and pick the model that runs your chats and agent, while still using XHack’s engine, guardrails, and tools.
AI Skills
Import and activate reusable skill packs for offensive AD, cloud, web, recon and more, each focusing the AI on a specific discipline. Toggle them on and off within a token budget.
Image Reading (OCR)
Point a vision model at a screenshot or PDF and pull the text straight out, feed a scanned report, a captured request, or a whiteboard photo into the AI without retyping a thing.Assets
Register and manage your organisation's digital assets in one verified inventory: domains, subdomains, IPs, APIs, and web applications.

Asset Management
Registered assets with verification status, scan history, and quick-launch options.Notifications
Real-time in-app notifications for security events, scan completions, incident updates, and team activity.

Notification Centre
Centralised notifications with severity indicators, direct links to relevant pages, and bulk management.Settings & Administration
Manage your organisation, team members, roles and permissions, API keys, and integrations, all from a centralised settings panel with fine-grained access control.

Organisation Settings
Configure your organisation profile, branding, domain, and general workspace preferences.
Team Members
Invite and manage team members with role assignment, MFA enforcement, and access control.
Roles & Permissions
Define custom roles with granular permissions. Control who can view, manage, or configure each platform feature.
API Keys
Generate and manage API keys for programmatic access. Track usage, set expiry dates, and revoke instantly.
Integrations
Connect third-party tools and services: GitHub, Cloudflare, Wazuh, Slack, and custom webhooks.Ready to Secure Your Organisation?
Get a personalised walkthrough of the platform with your team. No commitment, no credit card required.