Skip to main content

How to Use the SpartanX Custom Agent

Query your vulnerability data in plain English. Use web search, agentic re-validation, research mode, and import third-party scanner reports like Nessus — all in one AI chat.

Written by SpartanX CS

The SpartanX Custom Agent transforms static vulnerability data into an interactive experience. Instead of reviewing fixed reports, you can query your security data in plain language, drill into specific collections, and even import results from third-party scanners for deeper analysis.

Overview of the Interface

The Custom Agent is accessible from the left-hand navigation under "Start Custom Agent." The interface resembles a conversational AI prompt box — similar to ChatGPT or Gemini — but with one critical difference: it is directly connected to your organization's vulnerability data inside SpartanX.

The panel includes pre-built prompt categories to help you get started quickly:

  • Risk Management — e.g., "Show me the overall risk score for all assets and prioritize the top ten."

  • Deep Research — investigate specific attack paths or novel exploits

  • Security Posture — assess your current defensive standing

  • Collections, Assets, and Vulnerabilities — scoped queries for specific areas

These are starter prompts. You can edit or replace them with any question relevant to your environment.


Configuring Search Options

Three toggles control how the Custom Agent processes your queries:

  • Web Search — enables the agent to query public vulnerability databases alongside your internal data. Disable this to restrict responses to SpartanX platform data only.

  • Agentic Mode — useful in virtualized or containerized environments. In this mode, the agent can re-execute proof of concept tests to verify whether a vulnerability is genuinely exploitable.

  • Research Mode — enables deeper reasoning for complex topics. This mode consumes more tokens but produces more thorough analysis.


    Contextualizing Queries to a Collection

    By default, the Custom Agent queries all vulnerability data across your organization. If you need to scope a query to a specific environment — for example, your PCI cardholder environment or your cloud infrastructure — you can select the relevant collection before asking your question.


    Once a collection is selected, all responses are scoped to that collection. This is especially useful for:

    • Compliance reporting (PCI DSS, HIPAA, SOC 2)

    • Environment-specific investigations (firewalls, APIs, internal networks)

    • Focused risk analysis without noise from unrelated assets


Working with Imported Scan Data

The plus icon in the Custom Agent interface opens the import functionality. This allows you to upload output from third-party scanning tools — such as Tenable Nessus, Acunetix, or Qualys — and interact with those results conversationally.

When importing, you:

  • Select an existing import or upload a new file

  • Specify the scanner tool (e.g., Nessus XML)

  • Set a severity threshold to filter results (critical, high, or informational for all)

  • Optionally store the import in a new collection

Once the playbook runs and ingests the data, you can ask questions like: "Are the critical vulnerabilities in this Nessus report actually exploitable?" — turning a static PDF into an interactive security conversation.


What's Next

The Custom Agent is most powerful when your data is well-organized. The next section covers Collections — how to create them and how they structure your assets and vulnerability data for maximum clarity and control.

Did this answer your question?