Skip to main content
Mallory
Findings: Fix What Matters First

Findings: Fix What Matters First

Matt BuckOctober 8, 20264 min read

An alert fires, or an analyst forwards a threat advisory by email. Before anyone can decide whether it matters, someone has to pivot across consoles, pull the evidence, check the asset, and find current intelligence on what's involved. A week later there's often still no priority, no owner, and no record of what happened.

Findings hand that work to Mallory Agents. The agent investigates across your environment and files a finding if the risk is real: one issue on one asset or entity, with the evidence behind it, and the steps to remediate it. Findings help you create a prioritized queue your team can triage, route, and track until they're resolved. Findings are available today on the Team plan and above.

Findings show you which risks matter, and why.

What makes a finding a finding

A scanner reports a condition. A finding reports a condition a Mallory Agent has already investigated. Before an analyst looks at it, the agent has triaged the issue, gathered the evidence, and checked it against current threat intelligence, so the finding says how serious it is for your organization and why.

The agent works from everything Mallory sees: its own attack surface analysis, the sensors and integrations you connect, and intelligence such as a dark web sighting or a partner breach. That covers exploitable vulnerabilities, exposed misconfigurations, and intel issues alike. Whatever the source, the agent does the investigation and writes the finding.

You decide what the agent looks into, through Chat or the Agents you run, and where each finding goes, by routing it to the team that owns the risk.

A familiar shape, with more inside

A finding is tied to the asset or control where the issue exists. Examples include a security group that allows all inbound traffic from 0.0.0.0/0, a GCP firewall rule that exposes SSH to the internet, an externally trusted IAM role with administrator permissions, or an actively exploited vulnerability verified in your environment.

Every finding has a severity from INFO through CRITICAL, a summary, and remediation specific to the issue. For that firewall rule, the remediation is to restrict the source range to your corporate or VPN ranges, or to move access behind Cloud IAP. The finding also holds the evidence the agent collected, a link back to the investigation that produced it, and the intel entities it resolved to, including current threat intelligence from Mallory.

An analyst who picks it up next week can see what was found, how it was found, and what to do about it without tracking down whoever ran the investigation.

A Mallory finding detail page, with severity and status at the top and the evidence and intelligence behind them underneath.
Severity and status sit at the top, with the evidence and intelligence behind them underneath.

Generate findings from Chat or an Agent Template

Findings come out of investigations, assessments, and intelligence that needs to reach someone who can act on it. After you run an investigation with a Mallory Agent in Chat, ask it to package the result:

"Generate a finding from this investigation."

To skip the manual step, use an Agent Template. Each time you run the template, the agent investigates and files findings on its own, so they show up in the queue without anyone asking. Findings from a template carry the same evidence and context as findings requested in Chat.

Work the queue from the top

Open Findings in the navigation and your team starts from a queue that's already been investigated. You can filter by status, severity, type, or asset, or run a full-text search across every finding, so it's quick to see what's open now and what your team has already handled. When a batch of findings turns out to be the same story, close or dismiss them together from the list.

The Findings catalog defines what Mallory looks for. Mallory maintains a shared catalog, and your team can add its own types for conditions specific to your environment. Custom types use the same evidence, ticketing, and resolution workflow as the built-in ones.

The Mallory Findings queue, with filters for status, severity, type, and asset and a search across every finding.
Filter by status, severity, type, or asset, and search across every finding.

Every finding records how it was resolved

A finding is open, fixed, or dismissed. Dismissing one records the reason: false positive, accepted risk, not applicable, duplicate, fixed externally, or other. A quarter later, that record shows what your team decided and why, which is usually the part nobody can reconstruct.

Route it into the tools you already run

When the remediation belongs to another team, link the finding to a ticket in Jira, Linear, GitHub, or ServiceNow. You can point to a ticket your team already opened, or hand the finding to the agent, which files the ticket in your tracker and links it back to the finding. Either way, the finding's context goes with the ticket.

Findings are also available through the API and Mallory's remote MCP server, so Claude, Cursor, or any other MCP client can reach findings from wherever the remediation gets written. The agent in your editor can file what it turns up, raise a severity once someone confirms an exposure is real, close a batch that turned out to be one story, and attach the Jira ticket you just opened.

Start from a queue that's already investigated

Connect a cloud account, run an investigation, and see what Mallory files.

Try Mallory for Free

Start Free Trial