> ## Documentation Index
> Fetch the complete documentation index at: https://docs.borghq.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Runs

> Monitor and manage Mjolnir pentest runs

The Runs page shows all your Mjolnir pentest assessments, past and present. Open it from **Security testing > Full pentests > Pentest history** in the sidebar.

## Starting a run

Click **Run Assessment** in the top-right corner to launch a new Mjolnir run. A confirmation dialog opens warning that the run can't be paused once started.

<Warning>
  A run cannot be paused once started. You can abort it, but the assessment then has to be restarted from the beginning.
</Warning>

Only one run can be active at a time. If a run is already in progress, the Run Assessment button is disabled.

If you haven't configured Mjolnir yet, the Run Assessment button is disabled with a tooltip pointing you to the [setup wizard](/mjolnir/setup/connect-github).

## Run statuses

Each run has a status indicating where it is in its lifecycle:

| Status        | Meaning                                     |
| ------------- | ------------------------------------------- |
| **Queued**    | The run is waiting to be picked up          |
| **Running**   | The assessment is actively in progress      |
| **Completed** | The run finished successfully               |
| **Failed**    | The run encountered an error and stopped    |
| **Timed out** | The run exceeded its time limit and stopped |
| **Cancelled** | The run was manually cancelled              |

Active runs display a **LIVE** badge in the run list.

## Run list

Each run card in the list shows:

* **Target domain**: the primary URL being assessed
* **Repository**: the source code repository used
* **Started**: when the run began
* **Duration**: how long it ran (or a live timer if still active)
* **Findings**: the number of findings discovered (once complete)

Click any run to view its details. If a report has been generated, a **Download Report** button is available to export the PDF.

## Run detail

The detail view has tabs for following the run and reviewing its output.

### Overview

The overview shows the **phase stepper**, a visual timeline of where the assessment is in its pipeline:

1. **Analyse** — initial code analysis
2. **Map** — crawling your application and cross-referencing with source code
3. **Plan** — generating test cases from the attack surface
4. **Attack** — running test cases against your targets
5. **Report** — compiling confirmed findings into a report

Below the phase stepper is a **live event feed** that streams events as they happen during an active run. Events include reconnaissance discoveries, test case execution, and finding confirmations.

### Attack surface

The Attack surface tab shows what Mjolnir discovered about your application and how much of it was tested. It populates live during a run — the technology stack appears first, during the initial code-analysis phase; endpoints then appear as reconnaissance finds them, and their coverage updates as the attack phase progresses — and stays available after the run completes.

**Endpoints** lists every route Mjolnir found, with its method, path, whether authentication is required, known parameters, observed response codes, and a coverage pill:

| Coverage     | Meaning                                                                                                                        |
| ------------ | ------------------------------------------------------------------------------------------------------------------------------ |
| **Tested**   | Mjolnir exercised the endpoint (whether or not it turned up a vulnerability)                                                   |
| **Blocked**  | Mjolnir was prevented from completing a test — for example by a WAF, an authentication wall, or the endpoint being unreachable |
| **Untested** | No test targeted this endpoint                                                                                                 |

Use the filter buttons above the table to narrow it to a single coverage state.

Alongside the table, two panels give context for the assessment:

* **Technology stack** — the languages, frameworks, databases, and any high-risk dependencies detected in your code, plus the attack categories Mjolnir prioritised as a result.
* **Defences observed** — the security controls Mjolnir saw while testing, such as WAF behaviour, Content-Security-Policy and CORS settings, security headers, and cookie flags. If no controls were observed, this panel says so.

Until Mjolnir has learned anything about your application, the tab shows a "Mapping your attack surface…" placeholder; the technology stack is usually the first thing to appear.

### Findings

Once a run produces findings, they appear in this tab with the same filtering and detail panel as the main [Findings](/platform/findings) page. You can filter by status, view full finding details, update statuses, and export results.

During an active run, this tab shows live finding cards as vulnerabilities are discovered in real time.

## Aborting a run

While a run is in the **Running** state, click the **Abort** button in the run detail header. The run is cancelled and its underlying job terminated. You can start a new run afterwards.

## Run summary

When a run completes, a summary bar shows:

* **Duration**: total time taken
* **Total findings**: the number of vulnerabilities discovered
* **Severity breakdown**: counts for Critical, High, Medium, and Low

## Downloading reports

If a report was generated for a completed run, click **Download Report** in the run detail header to export a PDF containing all findings, reproduction steps, and remediation guidance.

<Card title="Mjolnir overview" icon="bolt" href="/mjolnir/overview">
  Learn how Mjolnir works and what it tests for
</Card>
