Skip to main content
New: Vulkro Cloud for Salesforce, a hosted workspace for your team. Available by invitation: register your interestView docs

Desktop console

vulkro serve starts a local web app on 127.0.0.1:8723 and opens your browser. Your work (projects, scans, triage, settings) is saved to SQLite on disk, so it survives Ctrl-C.

Launch​

vulkro serve # build UI + run release server, opens browser
vulkro serve --port 9000 # bind to a different port
vulkro serve --no-browser # don't auto-open

Where state lives​

OSPath
macOS~/Library/Application Support/Vulkro/vulkro-desktop.db
Linux~/.local/share/Vulkro/vulkro-desktop.db
Windows%APPDATA%\Vulkro\vulkro-desktop.db

Schema: SQLite, projects -> scans -> findings -> triage notes.

Tabs​

TabWhat it shows
EndpointsFilterable, sortable table of every detected endpoint with auth status, framework, source location.
FindingsMaster list. Group by severity, OWASP category, file, or owner.
PrivacyPII / PHI fields per endpoint, mapped to GDPR / HIPAA controls.
Access controlIDOR / BOLA / function-level findings, grouped by route.
CSRFCSRF-related findings + missing token middleware.
InjectionSQLi / XSS / SSTI / command injection grouped together.
IaCFindings on Terraform, Helm, k8s manifests, Dockerfile, docker-compose.
DependenciesCVE matches, KEV/EPSS decoration, reachability tags.
SecretsHardcoded secrets (current tree).
Git historySecrets ever committed (last 500 commits / 2 yrs).
ContainersOutput from vulkro container runs.
LicensesPackage-licence inventory + flagged copyleft / unknown licences.
OpenAPIScore against the inferred spec; gaps and inconsistencies.
CompliancePass/fail per control across the nine frameworks.
TrendsRisk-score, finding-count, MTTR, risk-debt over saved scans.
HotspotsSortable heatmap of churn x risk per module.
ContributorsTop contributors, bus factor per module, ownership coverage.
Compare scansPer-finding delta between two scans of the same project.
Code qualityComplexity, duplicates, dead code, coverage.
CVE DatabasePer-ecosystem CVE record counts; Quick Sync, Apply Bundle.

Triage workflow​

Mark any finding as one of:

  • triaged - looked at, not yet decided.
  • accepted-risk - known issue, deliberately won't fix.
  • false-positive - not a real bug.
  • wont-fix - real but de-prioritised.

Triage state carries across scans (matched by a stable finding_key), so a suppression you set doesn't come back next scan. Bulk-triage from the FilterBar, or export to vulkro-suppress.yaml to keep triage in source control.

Re-scan​

Click Re-scan to trigger POST /api/scan on the embedded server. Handy while iterating: change code, hit Re-scan, and see the deltas without leaving the browser.

Quick Sync (CVE Database tab)​

Click Quick Sync to run the same path as vulkro update (CDN fetch, signature verify, atomic apply). Useful when CI dropped the bundle and you want fresh CVE data without leaving the browser.

  • vulkro serve
  • See also: Baselines explained - when the UI's baseline-scan flag applies vs the CLI's .vulkro-baseline.json file, and how the Export-for-CI button bridges the two.

Vulkro is a product of Reveriext.

reveriext.com

Visit Reveriext