Skip to main content
The Runs page shows all your Mjolnir pentest assessments, past and present. Open it from Security testing > Full pentests > Pentest history in the sidebar.

Starting a run

Click Run Assessment in the top-right corner to launch a new Mjolnir run. A confirmation dialog opens warning that the run can’t be paused once started.
A run cannot be paused once started. You can abort it, but the assessment then has to be restarted from the beginning.
Only one run can be active at a time. If a run is already in progress, the Run Assessment button is disabled. If you haven’t configured Mjolnir yet, the Run Assessment button is disabled with a tooltip pointing you to the setup wizard.

Run statuses

Each run has a status indicating where it is in its lifecycle: Active runs display a LIVE badge in the run list.

Run list

Each run card in the list shows:
  • Target domain: the primary URL being assessed
  • Repository: the source code repository used
  • Started: when the run began
  • Duration: how long it ran (or a live timer if still active)
  • Findings: the number of findings discovered (once complete)
Click any run to view its details. If a report has been generated, a Download Report button is available to export the PDF.

Run detail

The detail view has tabs for following the run and reviewing its output.

Overview

The overview shows the phase stepper, a visual timeline of where the assessment is in its pipeline:
  1. Analyse — initial code analysis
  2. Map — crawling your application and cross-referencing with source code
  3. Plan — generating test cases from the attack surface
  4. Attack — running test cases against your targets
  5. Report — compiling confirmed findings into a report
Below the phase stepper is a live event feed that streams events as they happen during an active run. Events include reconnaissance discoveries, test case execution, and finding confirmations.

Attack surface

The Attack surface tab shows what Mjolnir discovered about your application and how much of it was tested. It populates live during a run — the technology stack appears first, during the initial code-analysis phase; endpoints then appear as reconnaissance finds them, and their coverage updates as the attack phase progresses — and stays available after the run completes. Endpoints lists every route Mjolnir found, with its method, path, whether authentication is required, known parameters, observed response codes, and a coverage pill: Use the filter buttons above the table to narrow it to a single coverage state. Alongside the table, two panels give context for the assessment:
  • Technology stack — the languages, frameworks, databases, and any high-risk dependencies detected in your code, plus the attack categories Mjolnir prioritised as a result.
  • Defences observed — the security controls Mjolnir saw while testing, such as WAF behaviour, Content-Security-Policy and CORS settings, security headers, and cookie flags. If no controls were observed, this panel says so.
Until Mjolnir has learned anything about your application, the tab shows a “Mapping your attack surface…” placeholder; the technology stack is usually the first thing to appear.

Findings

Once a run produces findings, they appear in this tab with the same filtering and detail panel as the main Findings page. You can filter by status, view full finding details, update statuses, and export results. During an active run, this tab shows live finding cards as vulnerabilities are discovered in real time.

Aborting a run

While a run is in the Running state, click the Abort button in the run detail header. The run is cancelled and its underlying job terminated. You can start a new run afterwards.

Run summary

When a run completes, a summary bar shows:
  • Duration: total time taken
  • Total findings: the number of vulnerabilities discovered
  • Severity breakdown: counts for Critical, High, Medium, and Low

Downloading reports

If a report was generated for a completed run, click Download Report in the run detail header to export a PDF containing all findings, reproduction steps, and remediation guidance.

Mjolnir overview

Learn how Mjolnir works and what it tests for