Targeted Attack Validation bridges the gap between third-party scanner output and confirmed exploitability. Instead of discovering new vulnerabilities from scratch, SpartanX takes your imported findings and validates them — telling you which are real, which are exploitable, and which are false positives.
What Targeted Attack Validation Does
A standard full-scope engagement discovers vulnerabilities across your attack surface. Targeted Attack Validation is different: it works from existing vulnerability data, typically imported from scanners like Nessus, Qualys, or Acunetix.
For each imported finding, SpartanX will:
Attempt to exploit the vulnerability to confirm it is genuinely present and exploitable
Identify false positives — findings that appear in the report but cannot be reproduced
Assess exploitability difficulty and provide evidence
This is especially useful for organizations with high-volume scanner output who need to prioritize remediation based on actual risk rather than scanner-reported severity.
Launching from the Engagements Menu
Navigate to Engagements and select "Targeted Attack Validation." The wizard will prompt you to:
Select a collection — choose the collection created from your import (e.g., "Hopi" or "Q2 Nessus Scan")
Choose assets — pick the specific domains or IP addresses you want to validate
Optionally narrow to specific vulnerabilities — if you only want to validate a subset of findings, select them individually
For example, if an import contains 14 vulnerabilities across a single domain, you can choose to validate all 14, or focus on the 3 most critical ones.
Configuring and Launching
After scoping the validation, configure guardrails as you would for any other engagement. Then give it a name and launch. The process is identical to standard engagements from this point.
Targeted Attack Validation can target:
External assets — publicly reachable IPs, domains, and API endpoints
Internal assets — RFC 1918 addresses reached via a NodeX Connector
What's Next
With your engagement types covered, the next section introduces the Knowledge functionality — a way to set organization-specific rules and context that govern how SpartanX behaves during any engagement.




