- Home
- Getting Started
- Account & Settings
- Roles & Add-On Access
- Settings
- Agentic
- White Label
- Agents & Engines
- Engines
-
Agents
- Overview
- Core Agents
- Core Agents
- Matrix Agent
- Audit Agent
- Industry Agents
- Patent Agent
- Add-On Modules
-
Manufacturing
- Manufacturing
- Overview
- Work Orders
- Production Scheduling
- Shop Floor Monitor
- OEE Dashboard
- Production Counters
- Plant & Process Setup
- Work Centers
- Bill of Materials
- Manufactured Products
- Work Instructions
- Quality Operations
- Overview
- Inspection Plans
- Quality Checklist
- Non-Conformance (NCR)
- SPC Charts
- Traceability (4M)
- Maintenance Operations
- Overview
- Asset Registry
- Preventive Maintenance
- Work Orders
- Spare Parts
- Reliability Dashboard
- Inventory Operations
- Overview
- Material Staging
- WIP Tracking
- Kanban Replenishment
- Material Consumption
- Assets
- Asset Health
- Legal
- Construction
- Government
- Education
- Energy
- Agriculture
- Healthcare
- RevOps
- Ecommerce Operations
- Financial Audit & Fintech Ops
- Insurance
- Hospitality
- Real Estate
- Patent & R&D Operations
- Automotive & Fleet Management Ops
- Customs & Global Trade
- Enterprise & Technical
-
Enterprise Operations
- Enterprise Operations
- Overview
- Enterprise Operations Guide
- Compliance & Docs
- Overview
- Approval Workflow
- Expiry Reminders
- Document Control
- Audit Trail
- Compliance Radar
- Contracts & Warranty
- Overview
- Active Contracts
- Warranty Check
- Service Billing
- Field Service
- Overview
- Dispatch Board
- Job Management
- Van Inventory
- Performance Dashboard
- Service Desk
- Overview
- Service Requests
- SLA Monitor
- Knowledge Base
- Procurement & Vendor
- Purchase Orders
- Vendor Portal
- RFQ Management
- QHSE
- Overview
- Incident Reporting
- Permit to Work
- Safety Inspections
-
Security & Compliance
- Threat & Monitoring
- Overview
- Security Hub
- Security Audit
- IAM Visualizer
- Dependency Scanner
- Secret Scanner
- Secret Vault
- Traffic Monitor
- Audit Trail
- Threat Simulator
- Compliance Radar (MatrixAgent)
- Identity & Compliance
- Overview
- PPTX Auditor
- PDF Auditor
-
Engineering & Infrastructure
- DevOps & Infrastructure
- Overview
- Cron Builder
- CI/CD Pipeline
- Containers
- Log Streamer
- Secrets Management
- Health Monitor
- Infrastructure as Code
- Developer Tools
- Overview
- Nerve Center
- Git Diff Viewer
- Regex Tester
- JSON Transformer
- Workflow Optimizer
- Execution Replay
- Workflow Editor
- Dev Hub Terminal
- Security Hub
- Graph View
- Terminal Editor
- API Playground
- DSL Compiler
- Database Tools
- Overview
- Database Manager
- ORM Mapper
- SQL Formatter
- Schema Visualizer
- Visual Query Builder
- Seed Data Generator
- Custom Collections
- QA & Test
- Overview
- Flake Tracker
- Artifact Vault
- Web Test Module
- Test Plan & Runner
-
Data & Intelligence
- AIOps & Intelligence
- Overview
- Agents
- Agent Architect
- Model Center
- Prompt Lab
- Knowledge Base
- Agent Persona Editor
- Tool / Function Registry
- Observability & Logs
- DataOps & Analytics
- Overview
- Data Inspector
- AI Predictive Models
- Core Modules
- Ads & Social Media
- AI Assistants
- API & Integration
- App Groups
- Appointment Booking
-
Automation
- Automation
- Overview
- Workflow Editor
- Monitoring
- Execution Heatmap
- Workflow Pulse
- Trigger Control
- Task Scheduler
- Integration Hub
- Rule Engine
- Pipeline Designer
- Workflow Editor
- Overview
- Triggers
- Manual Input
- Data Sources
- Ecommerce
- Document Management
- Logic & Transform
- AI Agents
- Knowledge / AI
- Validation & Security
- Integrations
- Outputs
- Document Generation
- Image Generation
- Video Generation
- Coming Soon
- Call Center
- Collaboration
- Community
- Creative Studio
- CRM
- Fleet & Logistics
-
Finance
- Hub
- Finance Hub
- Accounting Hub
- Treasury & Banking Hub
- Commercial Accounts Hub
- Invoicing & Billing Hub
- Reporting & Analytics Hub
- Grid View
- Overview
- Accounting AI Assistant
- Treasury
- Invoice Manager
- Expense Management
- Financial Accounts
- Payroll
- Accounts Receivable
- Accounts Payable
- Bank Reconciliation
- Budget & Forecasting
- Expenses & Budget
- Profit & Loss
- Tax & Compliance
- Galleries & Curation
- Google Display Ads
- Human Resources
- Legal & Support
- Logistics
- Map Explorer
- Marketing
- My Workspace
- Plans & Pricing
- Point of Sale
- Product Management
- Purchase
- Sales
- Semantic Search
- Strategy & Fundraising
- Warehouse
- Website
- Productivity
- Project Management
- Documents
- Learning (LMS)
-
Creator Tools
- Overview
- Brand Identity Creator
- Template Creator
- Image Creator
- Overview
- Getting Started
- Image Generation
- Remix
- Upscale
- Magic Replace
- Remove Background
- Reframe
- Describe
- Magic Tags
- Magic Fill
- Style Transfer
- Style Preset
- Social Media Images
- Prompting Guide
- Video Creator
- Overview
- Getting Started with Video
- Text to Video
- Image to Video
- AI Video Transition
- Video Effects
- Scene Builder
- Short Film Creator
- Audio Creator
- Overview
- AI Audio
- Text to Speech
- Voice Cloning
- Music Generation
- Sound Effects
- Writer Tools
- App Factory
- Research
- Utilities
Threat Simulator
Safe, simulated OWASP Top 10 attack scenarios that validate your detection coverage — no real payloads leave your environment.
Overview
Threat Simulator runs the OWASP Top 10 attack categories against your application as safe, simulated scenarios and reports whether each one was Detected or Missed by your current monitoring stack. Every request carries a recognisable marker so your own detection tooling (like Traffic Monitor and Audit Trail) can distinguish simulator traffic from real attacks.
Simulated, not real
Threat Simulator does not send real exploit payloads to external systems. It generates the request patterns an attack would produce and checks whether your stack correctly flags them — no real damage, no real data exfiltration.
Quick Start
- Open Threat Simulator from the Security sidebar.
- Click Run Full OWASP Suite to run all ten scenario categories, or select a single row and click Run to run just that scenario.
- Watch each scenario move from Not run to Running… to Detected or Missed.
- Click any scenario row to see its description and result detail in the right-hand panel.
- Check the stat strip at the top for overall Detection Coverage, and how many scenarios were detected vs. missed.
OWASP Top 10 Coverage
| # | Category | Simulated scenario |
|---|---|---|
| A01 | Broken Access Control | IDOR probing, privilege escalation via path manipulation, CORS misconfiguration test |
| A02 | Cryptographic Failures | Weak cipher negotiation, unencrypted cookie detection, TLS downgrade attempt |
| A03 | Injection | SQL injection payloads (time-based, error-based), NoSQL operator injection, command injection |
| A04 | Insecure Design | Business logic bypass patterns, mass assignment probing, rate-limit absence test |
| A05 | Security Misconfiguration | Default credentials, exposed admin panels, verbose error messages, directory listing |
| A06 | Vulnerable Components | Known-CVE endpoint probing, outdated version fingerprinting via response headers |
| A07 | Authentication Failures | Brute-force simulation, credential stuffing patterns, JWT algorithm confusion |
| A08 | Software Integrity Failures | Unsigned update endpoint detection, subresource integrity check |
| A09 | Logging Failures | Checks whether attack attempts appear in Audit Trail and Traffic Monitor logs |
| A10 | SSRF | Internal metadata endpoint probing patterns, DNS rebinding indicators |
Features
Run All or One
Run the full OWASP Top 10 suite in sequence, or trigger a single scenario from its row for a fast spot-check.
Detection Coverage
The stat strip shows overall detection coverage as a percentage, plus counts of detected, missed, and not-yet-run scenarios.
Safe by Design
Every simulated request carries an X-TotalApp-Sim: true header so your own monitoring and logging tools can distinguish it from real attack traffic.
AI Assistant
Every screen in Security Hub now ships with an embedded AI Assistant, opened from the vertical AI Assistant tab on the right edge of the screen. The assistant reads the data currently on screen — the OWASP Top 10 scenario list, including which categories were Detected and which were Missed — and answers questions, triages findings, or drafts a remediation plan directly in the chat panel.
Coverage Summary
Get a plain-language summary of your current detection coverage — how many scenarios were caught vs. missed, and the resulting percentage.
Missed-Scenario Explanation
Understand why a specific scenario was missed and what kind of attack pattern slipped through undetected.
Next Steps
Get concrete recommendations — a WAF rule, a tighter rate limit, added input validation — to close a specific detection gap.
Save as Report & Add Knowledge
Any assistant reply can be saved as a report (available later from My Reports) via the Save as Report button under the last message. Click Add Knowledge in the input dock to attach files or notes from your Knowledge library so the assistant's answers can reference them.
FAQ
X-TotalApp-Sim: true marker so you can filter them out of production metrics — but running against a staging environment first is recommended, since some WAF rules may still trigger rate-limit responses that affect real traffic.