Help Center · GLAIM
Home Risk & decision Vulnerability Management Risk Management CTEM Decision Intelligence Compliance Operations Reporting Red Team Recon Artificial Intelligence Who it's for Security teams Service providers Security Integrations Pricing Español
Help center

GLAIM guides, written against the real product.

How every part of the platform works, explained directly.

Getting started

Log in and activate your account

To sign in to GLAIM, enter your email and password on the login screen and click "Log in". If you don't remember your password, use the "Forgot your password?" link to receive reset instructions. The "Remember me" checkbox keeps your session active for two days on that device.

If it's your first time logging in and an administrator required you to change your initial password, you'll see a dialog you can't close until you set a new one.

If your organization has two-factor authentication (MFA) enabled, after your first login you'll be taken automatically to the setup screen. The steps are:

  1. A QR code is shown on screen. The code also appears as text below it, in case you'd rather enter it manually into any TOTP-compatible authenticator app.
  2. Scan the code, or enter it manually, in your authenticator app.
  3. Type the 6-digit code your app shows into the "Verification code" field.
  4. Click "Enable MFA".
  5. The system gives you a set of one-time recovery codes, shown only at that moment. You can copy them or download them as a text file. Keep them somewhere safe: they're the only way back in if you lose access to your authenticator app.
  6. Click "I've saved my codes, continue" to finish setup.

From then on, every login will ask for the 6-digit code from your authenticator app in addition to your password. If your account uses your organization's single sign-on (SSO), this MFA step doesn't apply: verification is handled by your company's identity provider.

MFA status can be checked from your user profile, though it's informational only there: activation happens exclusively through the setup screen described above.

Create your first pentest

From the pentest list, click "New" to open the creation form. It's organized in three steps.

Step 1: General. If your organization has pentest templates configured, you can select one or more at the start so several fields fill in automatically (associated reports, checklist, compliance norms, among others). Then fill in: name, identifying code (there's a button to suggest one automatically), initial status, client (required, with search), associated service, tags, work types, work description and access credentials if applicable.

Step 2: Assignment. Here you define who works on the pentest: project owner, reviewer, assigned teams and users (with a dedication percentage per person), CVSS version to use, report template(s), methodology checklist, applicable compliance norms, scope (included assets) and relevant client contacts.

Step 3: Dates. Start date, end date, start and end of the planning/reporting phase, and the report delivery deadline. These five fields are required.

After finishing the last step, click "Create" to set up the pentest.

Invite your team

From the users section, click "Create user" to open the sign-up form. There are three ways to give a new person access:

  • Invite by email: the user gets a link to set their own password.
  • Generate a temporary setup link: a one-time URL is generated, valid for 24 hours, which you send through whichever channel you prefer.
  • Manual assignment: you set an initial password yourself and share it securely.

Besides the email, the form asks for: first and last name, job title, interface language, role or roles (from those your organization has enabled) and, if the assigned role requires client scope, the corresponding client. You can also mark the account as active or inactive.

To organize several people into a working group, use the teams section. There, "Create team" opens a form with a name, description and a member list you select right in that same step: there's no separate flow to add people to an existing team, just edit it and change the member list.

Pentests and findings

Managing a pentest's lifecycle

Every pentest goes through a series of statuses that reflect what stage of work it's in:

  • Scheduled: set up, not yet started.
  • Preparation: the phase before technical work begins.
  • On hold: paused. Applied automatically if the pentest is left with no assigned users.
  • Execution: active testing phase.
  • Reporting: technical work is done and the report is being prepared.
  • Remediation: waiting for the client to fix the findings.
  • Completed: closed.
  • Cancelled.

The status is changed from the pentest's edit form. Not every user can change it: only those assigned as that pentest's owner. The status change history stays visible, read-only, inside the pentest's own page.

To see several pentests at once over time, there's a separate calendar view with different display modes (timeline, by team, by workload, heatmap and by service) and different time scales, from weekly to yearly.

Recording and prioritizing findings

To record a finding manually, go into the pentest's page and click "Create finding". The form includes: name, type (vulnerability, observation, attack path or positive note), status, severity, description, recommendation, affected asset(s), CWE, CVE, MITRE tactics and techniques, vulnerability types and tags. You can also calculate the CVSS score (versions 3.1 and 4.0) right from the form, with a built-in calculator, instead of typing the score by hand.

If you already work with your own vulnerability catalog, you can start from an existing template instead of writing the finding from scratch.

Available severities are: Critical, High, Medium, Low and Informational.

To prioritize, besides severity, the form calculates a risk level from two values you enter: impact and likelihood, each on a 1-to-5 scale. The system multiplies both values and classifies the result as low, medium, high or critical. This calculated risk helps you tell apart, within the same severity, which findings deserve attention first. The findings list can be sorted manually by any of its columns.

Importing scanner results

Instead of recording every finding by hand, you can import scanner results. From the pentest's page (or from the client's page, choosing which pentest the findings go to first), click "Import findings".

Supported formats: CSV or Excel files with your own data structure, or exports from the most common vulnerability scanners. Maximum file size is 20 MB.

The process has four steps:

  1. If you're coming from the client's page, you first select the destination pentest.
  2. You select the file to import. If you're using CSV or Excel with your own format, you can first download a template with the expected columns.
  3. The system shows a preview with the rows that will import successfully, the ones with errors, the ones that are duplicates, and any columns it didn't recognize.
  4. You confirm the import and the findings are created, with a summary of how many were created and how many were skipped.

Importing Nmap results works differently and is used to register assets (hosts and ports), not findings. That option is available separately, inside the pentest's asset management.

Attack Chains: chaining findings

Attack Chains lets you join several independent findings into a sequence that represents how a real attack could be chained together, useful for explaining to a client the combined impact of several weaknesses that, individually, might look minor.

From the "Attack Chain" tab of the pentest's page, click the button to create a new chain. Each chain has a name, an objective and an overall outcome, and is made up of steps you add one at a time. Each step includes: a title, an attack phase (with suggestions based on MITRE tactics), the actor executing that step, a free-text narrative, the related findings you want to link, the corresponding MITRE tactic and technique, mitigation and detection measures, and the step's outcome (success, partial, blocked or detected).

You can also generate a suggested chain automatically from findings already recorded, and edit it by hand afterwards.

The chain can be viewed three ways: as an interactive diagram, as a timeline, or as a narrative story with one card per step. You can decide whether the chain is included in the pentest's final report or not.

Requires GLAIM Pro or higher
Reports

Generating a report from a template

Reports are generated from the "Reports" tab inside the pentest's page, not from the general template catalog (that section is only for creating and maintaining available templates).

To generate a pentest's first report, select a template from the dropdown (only published templates appear) and click "Create report". If the pentest already has a report generated from that same template and you want to create an additional one, the button changes to "Generate report".

Generating a report asks you for a title of its own for that document. This title is what the client will see in their portal, and is deliberately independent from the template's internal name, so no internal information leaks into the final report.

If your organization doesn't have any published template yet, you'll see a notice saying so, with a shortcut to the templates section to create one.

Once the report is generated, sections marked as optional in the template aren't chosen at this step: they're turned on or off afterwards, inside the document's own editor, where each optional section shows a checkbox to include it in the final export or not.

Exporting to Word, HTML or PDF

With the report open inside the pentest's page, click the "Download" button to open the export options menu. Three formats are available: PDF, Word and HTML.

If the report is published, the "Share with third parties" option also appears. Instead of downloading a file, this option generates a link to a PDF version of the report, with an expiry date, and copies it directly to your clipboard so you can send it through whichever channel you prefer.

Reports in draft status can't be downloaded from the client portal: in that state, the client can only preview them in HTML format, with a watermark indicating it's a draft.

Versioning and renaming reports

Renaming: next to the report title there's a pencil icon. Clicking it opens the same dialog used when creating the report, where you can change the title the client sees.

Saving a version: the "Save version" button records the content's current state as a version, without changing the active version number.

Generating a new version: the "Generate new version" button creates a new version from the report's current content, keeping everything already written as a starting point (unlike generating a report from scratch off a template). The system keeps the two versions prior to the current one. Generating a new version also lets you change the report's title.

Version history: the history icon opens a panel with every version of the report, showing version number, date, author and notes for each one. From there you can restore any earlier version. The system asks for confirmation first, since restoring an earlier version replaces the current sections' content.

Compliance and risk

Coming soon. Planned articles so far:

  • Compliance norms
  • Threat Landscape
Integrations

Coming soon. Planned articles so far:

  • Setting up a connector
Client portal

Coming soon. Planned articles so far:

  • What your client sees in the portal
  • Work requests
Administration

Coming soon. Planned articles so far:

  • Users and roles
  • Teams and isolation (MSSP)
  • API Keys
Automation and AI

Coming soon. Planned articles so far:

  • Pentesting AI
  • MCP server for AI agents

Can't find what you're looking for?

Write to us at hello@glaim.io and we'll answer directly.