Overview
The Exposure page shows what anyone on the internet can learn about your organization: your domains, subdomains and IP addresses, vulnerabilities on your internet-facing hosts, and accounts on your domain that appear in breach data. It also shows risks found through integrations you have connected, such as risky Microsoft 365 app grants, exposed cloud resources and at-risk user accounts.
The Exposure page has six tabs: Overview, OAuth apps, Cloud, Identity, Hosts, and Attack surface. Each one is described in About the Exposure tabs, below.
Exposure and Cloud security
Some cloud data appears on both pages in Hearth. Exposure shows what is reachable from the internet. Cloud security shows misconfigurations and over-permissioned IAM identities across your connected cloud accounts.
Both pages read the same cloud issues, so snoozing, hiding or accepting a cloud issue on one page applies on the other. Google Cloud checks cover IAM only, so Google Cloud issues appear only on the Cloud security page, not the Cloud tab of the Exposure page.
This table shows which entities are covered on the Exposure tabs, and whether those items also appear on the Cloud security page:
| What you're looking for | Exposure | Cloud security |
|---|---|---|
| Cloud resources exposed to the internet (AWS and Azure) | Cloud tab | Yes |
| Other cloud misconfigurations and over-permissioned IAM identities | Linked from the Cloud tab and from Overview issue cards | Yes |
| At-risk identity-provider accounts | Identity tab | No |
| Microsoft 365 OAuth app grants | OAuth apps tab | No |
| Domains, hosts, vulnerabilities and breach data | Overview, Hosts and Attack surface tabs | No |
MSP parent workspaces also have a cohort exposure view that rolls up exposure across managed workspaces. See Cohort views for MSPs.
How discovery works
Discovery is passive: Hearth does not probe your servers or network, and it never changes anything in your environment. It looks up your domain in public internet records and in commercial internet-intelligence and breach databases, then adds what your connected integrations report.
Hearth runs discovery automatically as follows:
- When your workspace is first set up
- Once a week
- When you connect an integration (that integration's checks only)
You can also run it yourself at any time. See Running discovery and changing the domain, below.
Each run works through these five phases:
- Mapping attack surface
- Scanning exposed services
- Checking breach exposure
- Analyzing connected sources
- Scoring & finalizing
A run usually takes a few minutes; larger domains take longer. Each run covers up to 100 hosts and 100 IP addresses. Results reflect what those sources last observed. After you fix something, discovery may keep reporting it until the sources catch up.
Hearth checks for risky services and vulnerabilities only on hosts it attributes to your organization directly. Hosts on CDNs, SaaS platforms and hosting providers such as AWS, Azure, Google Cloud and DigitalOcean are counted but not checked. To see cloud resources exposed to the internet, connect your cloud accounts and use the Cloud tab.
About the Exposure tabs
Overview
The Overview tab opens on the Latest Snapshot card, which summarizes the most recent run across every tab. If a discovery run is in progress, a separate Discovery card shows the status as either pending or running. The card also shows how the latest run started, who started it and when. Each issue card has the option to create an action plan.
The overview includes these details:
| Section | Details |
|---|---|
| Domain snapshot |
Includes your grade pill, the business domain Hearth scans for your workspace, an option to change the domain, and the run-state pill. The grade is one of The run states are as follows:
|
| Top Priorities | This section lists the issues to act on first, from every tab. Select the All tab to see every issue, or Focus to return to the priorities. |
| Domain, Email & Tenant Config | This section lists configuration issues with your domain, email and tenant setup. |
| Posture Coverage | This section shows which sources were checked, could not be checked or are not configured. |
| What Changed | This section compares the run with the previous one: counts of subdomains, public IPs, exposed services and breached accounts, plus new and resolved vulnerabilities. |
| Run History | This section lists the last 20 runs. |
OAuth apps
The OAuth apps tab needs the Microsoft 365 integration. It lists third-party apps with Microsoft Graph access to your Microsoft 365 tenant, grouped into Flagged, Needs review and Approved. Apps with risky access display a sensitive permissions pill. Select an app's name to see how it was consented (tenant-wide by an admin, or by a user), its permissions, and an option to investigate with Hestia.
Approve apps you expect or flag the apps you do not expect in your environment. Approved apps drop off the Overview issues, but an approved app that gains a new sensitive permission returns for review. Flagged apps rise into your list of top priorities.
Cloud
The Cloud tab lists cloud resources exposed to the internet, from your connected AWS and Azure accounts. For example:
- An AWS S3 bucket that is public or lacks Block Public Access
- An AWS security group that allows all ports from any address
- An Azure storage account that allows anonymous access
- An Azure network security group rule that allows SSH or RDP from the internet
It shows the same issues as the Cloud security page, limited to internet-facing resources. A link at the top of the tab (N more cloud posture issues in Cloud security →) opens the rest. Google Cloud checks cover IAM only, so Google Cloud issues appear on Cloud security, not here.
Identity
The Identity tab lists at-risk user accounts from Microsoft 365, where Microsoft Entra rates a user as risky or confirms a compromise, and from Okta, where an account is locked out. It needs the Microsoft 365 or Okta integration. Google Workspace checks appear under Domain, Email & Tenant Config on the Overview tab instead.
Hosts
The Hosts tab lists problems on your internet-facing IP addresses and subdomains, grouped by host. Discovery finds these; no integration is needed.
- Exposed risky services, such as RDP, SMB, SSH, FTP, Telnet, databases, VNC, and admin or VPN panels
- Known vulnerabilities (CVEs)
- Possible origin-IP leaks, where a server behind a CDN appears to be directly reachable
- Subdomains at risk of takeover
Triaging items on the Cloud, Identity and Hosts tabs
Each resource, account, or vulnerability has options to snooze, hide, or investigate with Hestia. Hiding lasts until the item changes. You can re-open a triaged item to undo the decision.
The additional actions menu (...) includes these options:
- Accept risk (90d) and False positive, which ask for a short note
- Prioritize, which pins the item to Top priorities
- Custom snooze…, which asks for a date
Attack surface
The Attack surface tab lists every domain, subdomain and IP address discovery found, grouped into Unconfirmed, Confirmed ours, Not ours, and Ignored.
- Select "Ours" or "Not ours" on each unconfirmed item. Marking a host "Not ours" removes its vulnerabilities from the Overview issues; they stay on Hosts, dimmed.
- Promote confirmed items to facts, which adds it to what Hestia knows about your workspace.
- Select an item to see its related accounts and issues, or to investigate with Hestia.
Running discovery and changing the domain
To run a new discovery, do the following:
- Navigate to Exposure.
- On the Overview tab, click Run discovery now if it has never run, or in the Latest snapshot card, click Re-run.
- Keep the page open until the results appear, then review the Latest snapshot card.
You need the Analyst role or higher. If you open the page while a run is in progress, a Discovery card shows the current phase and the elapsed time.
Scan a different domain
Hearth scans one business domain per workspace. By default it uses the website domain from your Blumira account or, for a workspace created through sign-up, the domain of the sign-up email address. You can point discovery at another domain your organization owns, for example to test it.
To change the domain:
- On the Overview tab, next to the domain, click Change.
- In the Domain box, type a domain your organization owns.
Note: Free email domains, such as gmail.com, cannot be scanned. - Click Save & re-scan.
The new domain replaces the old one, including for the weekly runs. To go back to the domain Hearth detected, select Change, then Reset to automatic, which also re-scans.
Runs of the old domain stay in Run History. After a change, What Changed compares the new domain's run with the old domain's.
Reset run history
The Reset option, next to Re-run, deletes the current snapshot and all run history so the next run starts fresh. It can not be undone. It does not change the scanned domain, triage decisions, asset confirmations or action plans. Share links stop working until the next run.
Action plans
To track the fix for an issue, create an action plan. Hearth builds the plan from a playbook and opens it; if the issue already has a plan, Hearth opens that one. Issue types without a vetted playbook get a plan marked "General checklist — tailor it to your environment."
Hearth never changes your systems: you carry out the steps and mark each one done. Later runs update the plan for you as follows:
- When a complete run no longer finds the issue, Hearth marks the plan resolved. For exposed services and vulnerabilities, this waits until a run has re-checked that IP address.
- If the plan is resolved, or has an action proposed, and a later run still finds the issue, Hearth moves it back to investigating.
Breach exposure
When accounts on your domain appear in known breach or leak data, the Overview tab shows a "Breach exposure" issue. Its list of affected accounts shows each account with the breach name, date, and type, including the following details:
- Password exposed: This label means that the breach included a password for this account.
- Rotated since or reset predates breach: These indicate whether the password changed after the breach. Shown when Microsoft 365 or Okta is connected.
The list shows up to 15 accounts, then the number of others. Accounts on other domains appear under "Related — other domains." You can mark an entry as "ours" to add the domain's accounts to your affected accounts list, or "not ours" to drop them from the list.
Reports and sharing
To print or save the latest snapshot as a PDF, do the following:
- On the Latest snapshot card, click Open full report →.
- Click Print / Save as PDF.
- In the confirmation window, select your destination, and then click [Print | Save].
- (Optional) To create a shareable link, click Share report, then copy the link.
Anyone with the sharing link can view a redacted summary for 30 days: your grade, domain, counts and issue categories, without IP addresses, vulnerabilities, subdomains or account names. The link always shows the latest snapshot.
Roles and permissions
Every role except Billing can view the Exposure page. Running discovery and acting on issues need the Analyst role; changing the domain and sharing reports need Administrator- or Owner-level permissions.
Reference: For more information about Hearth access, see User roles and permissions.
Troubleshooting common issues
| Issue | What to do |
The run state shows partial
|
A source failed or reached a usage limit, so results may be incomplete. Try to re-run it later. |
| A permission error appears after you try to run discovery | Your role can view Exposure but cannot run discovery. Ask an Administrator or Owner to update your role or permissions. |
| Share report or attempting to change domain gives a permission error | Changing the domain and creating share links need the Administrator or Owner role. |
| Hearth asks you to confirm the domain to scan | No business domain is on file, so Hearth suggests the domain of your email address. An Administrator or Owner can confirm it, then change the domain to the correct one if necessary. |
| An issue you fixed still appears | Discovery reads third-party data, which can lag behind your changes. Check again after the next weekly run. |
| A cloud misconfiguration doesn't appear | The Cloud tab shows only AWS and Azure resources exposed to the internet. For every misconfiguration and over-permissioned IAM identity, use Cloud security. |
| An Exposure tab is empty | OAuth apps needs Microsoft 365, Cloud needs AWS or Azure, and Identity needs Microsoft 365 or Okta. Hearth checks an integration as soon as you connect it. Hosts and Attack surface fill after the first discovery run. |