Skip to content

Navigation & Screens

The RedCloud interface is a single application shell with a left sidebar (the main menu) and a top header (global controls). The sidebar groups every screen into collapsible sections; the header holds search, language, theme, operation mode, and the tenant switcher. This page is a map of the whole product — use it to find any screen and understand what it’s for.

ScreenWhat it’s for
Security HubA landing hub of curated tiles that launches you into the other sections.
DashboardAt-a-glance posture: KPI cards (identities scanned, Critical/High/Medium/Low counts, attack paths, max risk), a severity donut, risk charts, and an executive summary.

The day-to-day triage area.

ScreenWhat it’s for
IssuesThe canonical findings screen (Wiz-style). Filter by severity, search, accept risk, and manage exemptions.
Issues — New LayoutAn alternative visual layout over the same finding data.
SLA TrackingFinding SLA timers and breach status.
VulnerabilitiesA CVE / vulnerability-centric view.
CIS BenchmarkCIS GCP Foundation compliance scoring.
Risk ScoringPrioritized risk scoring across findings.
Effective AccessWho can effectively reach what, after policy evaluation.
Security ChecklistA manual and automated security checklist.

ASPM (Application Security Posture Management)

Section titled “ASPM (Application Security Posture Management)”

A DefectDojo-style hierarchy for managing application-security work: Products, Engagements, Tests, Risk Acceptance Queue, Finding Rules, False Positive Library, Universal Import (ingest third-party scanner reports), Questionnaires, and Standards & Compliance, plus management surfaces such as Finding Groups, Custom Fields, Webhooks, Retention Policies, Report Builder, MTTR Dashboard, Calendar, Tags, and Bulk Operations.

ScreenWhat it’s for
Asset InventoryCISO-level inventory across all scanned projects/accounts.
Cloud ArchitectureA map of your cloud architecture.
IAM PermissionsIAM permission distribution and analytics.
Cloud Findings HubUnified GCP SCC + AWS Security Hub findings, with Excel/Word export.
ComplianceCompliance-framework dashboard.
Org PoliciesOrganization-policy posture, enforcement status, and drift.
Drift DetectionConfiguration drift over time.
Data Security (DSPM)Data security posture.
ScreenWhat it’s for
FinOps DashboardCloud cost/spend posture, connecting wasted spend to security hygiene.

How findings become attack stories. Key screens: Attack Paths, Attack Chains, Attack Graph (interactive force-directed graph), Kill Chain, Attack Timeline, Attack Feasibility, Exploit Validator, Top Paths, Attack Surface, Network Recon, Web Intelligence, Threat Detection, Threat Intel, MITRE ATT&CK (technique-coverage heatmap), Anomaly Detection, AI Insights, AI Query (ask questions in natural language), Architecture Review, and the Security Knowledge Base.

Active and code-level testing. Includes Code Security, Code Flow Analysis, Dependency Analysis, SBOM Generator, License Scanner, AppSec Pipeline, IaC Scanner, Template Scanner, Secrets Scanner, Web Scanner (DAST), Web Fuzzer, WordPress Scanner, K8s Security, Container Security, VM / OS Scanner, Pen Testing, Web PT Hub, AI Pentest, Red Team Simulation, Attack Simulation, What-If Analysis, Blast Radius Search, LLM Security, and the Security Testing Hub (a central launcher for all of these).

The autonomous and AI-driven operations area: Recon Pipeline, Autonomous Agent, Security Insights, Knowledge Base, Auto Code Fix, Pentest Report, Security Terminal, Rules of Engagement, Censys Intelligence, Visual Pipeline Editor, Tool Permission Matrix, Agent Configuration, Evolutionary Memory, and the Multi-Session Manager.

ScreenWhat it’s for
Report ManagerBuild and export branded reports (see Reports).
Comparison ReportCompare two scans for trend analysis.
Remediation RoadmapPrioritized, AI-assisted remediation plan.
ScreenWhat it’s for
Cloud ResourcesBrowse scanned cloud resources.
Graph Analysis HubCentralized resource/attack/force-graph visualizations.
External ReconOutside-in reconnaissance of your exposed surface.

In-product System Book, Changelog, and a Capabilities view that lists what the platform can do.

Opened from the Administration divider in the sidebar; items can be permission-gated.

GroupKey screens
Platform AdministrationSuper Admin Dashboard
OperationsNew Scan, Demo Scan, Scan History, Mutelist, Red Team, SLA Configuration
Monitoring & LogsLive Logs (Scan Investigation Console), Application Logs, Audit Log, Hebrew Quality
ConnectionsDeployments (connect clouds), Customer Onboarding, Multi-Cloud Security, Connection, Architecture Diagram
User ManagementUsers, Roles & Permissions, Tenants, SSO Settings, IAP Provisioning, API Keys
System SettingsAI Configuration, Model Routing, Email, Storage, Custom Icons, Exemption Policies, License

The New Scan screen is the main launcher — provider selection, connected-account quick-select, scope tabs (Project / Folder / Org / Custom), profile chips, option toggles (Mock, SARIF, Host Security, Web PT, Audit), and a pre-scan permission check. It is documented in detail in CSPM & Findings.

ControlWhat it does
Global searchPress Ctrl/Cmd + K to search pages and findings, with breadcrumb paths.
Operation modeSwitch between Security Assessment and Red Team (Red Team is locked behind a disclaimer). See Core Concepts.
LanguageToggle English / Hebrew; the whole UI re-flows for RTL.
ThemeLight, dark, or follow system.
Tenant switcherSwitch between the tenants you belong to; shows the plan badge and per-tenant branding.
Help buttonAppears on every section header and opens context-sensitive, bilingual help.
AI assistantA floating chat button for the tenant-scoped AI assistant.
  • The exact set of visible screens depends on your role and permissions and your tenant’s license plan — some screens are hidden when a feature isn’t licensed or you lack the permission.
  • Red Team and other offensive screens require accepting a disclaimer and operate only within an authorized scope.