Use Explorer (Northstar)
The Explorer provides a comprehensive view of your organization's application layer to better understand your security posture. It helps you compare risks across applications and all their related entities.
Developers and AppSec teams can use the Explorer to better understand the applications they manage and their associated risk.
SOC Analysts can use the Explorer to better understand their organization's attack surface and risks.
Entities in Explorer are applications, servers, called APIs, databases or datastores and open-source libraries. Explorer also surfaces AI usage as an attribute on application entities when Contrast agents detect calls to AI and machine learning libraries or external AI services.
Explorer application actions
From the details panels for application entities, you can:
Explore incidents and issues related to the selected applications.
Configure policies for Assess rules, ADR (Protect) rules, and exclusions.
Before you begin
The entities that you see in Explorer depend on the permissions you have to view specific resources, as defined in your access control settings.
View Explorer entities
In the left navigation, select Explorer > Contrast Graph.
The initial display shows a visual representation of the complete application layer for an environment in your organization.
Application entities display the Contrast score to help you quickly see which areas in your application are most at risk.

Use your mouse, trackpad, or other navigation device to zoom in on or move the view.
Select Prod, QA, or Dev to focus the view on entities in that environment. Explorer defaults to the highest-priority environment that has Contrast data. For example, if applications are running in production, defaults to Prod. If there is no production data, Explorer defaults to QA or Dev, depending on which has data.
Select Include static-only to include entities Contrast has only observed through static analysis, without runtime data.
To focus the view on a specific entity and its connections, enter a full or partial entity name in the search bar.
You can also enter the full or partial name for a CVE.
The search results include the searched-for entity and any entities connected to it. The results also reflect filter settings.
Select an Application entity to open the Application details page that contains the following tabs:
Overview: Contrast score, a Profile panel (language, routing framework, last seen), Criticality, Routes exercised, incidents, and issues by severity.
Libraries summary: Library issues by severity, CVE by status, and a CVE Shield exposure trend chart for the application's libraries. Library entities represent either a root open-source library or a transitive dependency.
Note
Viewing library data is different than viewing other entities. View library data in Explorer describes how to navigate library entities.
Library details: A sortable, paginated table of every library, version, and CVE affecting the application, with per-environment issue status.
Policy: Assess rules, Protect rules, and Exclusions rule tables you can manage, with per-environment mode toggles.
Dependencies: Dependency tree for the selected library cluster, matching the Dependencies tab available from a library cluster node.
From the Application details page, you can select the Download button to generate a CycloneDX version of the report that includes the component name and version, origin or source (open-source or proprietary), license information, supply chain relationships (dependencies), and vulnerabilities.
Select an entity see more details:
Entity
Details
Servers
Type: The type of server associated with one or more applications.
Agent language: The language of the agent used for applications associated with the server.
Agent version: The version of the agent used for applications associated with the server.
Called API
Domain: The domain name for an API.
Database
Server address: The address for the server.
System: The type of database, for example, MySQL.
Server port: The number of the port the database is using to communicate with the server.
Libraries
Library entities represent either a root open-source library or a transitive dependency.
Root library entities show the number of dependencies. You can expand these entities to view all dependencies or just the next level of entities in the dependency chain.

Entities for transitive dependencies show the name of the library. In some cases, you can expand these entities to view another level of dependencies.

The details panel for a transitive dependency entity can include:
Name: The name of the library.
Version: The library version.
Language: The library language.
Licenses: The name of the license that applies to the library. For example, Apache-2.0.
Released: The date the library was released.
Ancestors (if applicable): The libraries that uses the transitive dependency indirectly.
For example, If Library 1 calls Library 2, Library 1 is the ancestor of Library 2.
Issues (if applicable): A link to the issues that Contrast created.
Selecting a link opens the Issues view.
Direct CVEs (if applicable): CVEs that indicates a software flaw exists that lets an attacker take direct action, unauthorized access, or control of software.
Descendant CVEs (if applicable):
A descendant CVE is a vulnerability in a child process (descendant) of another process.
CVE link: A link to the NIST description of the CVE
Library: The name of the transitive dependency
Path: The path to the affected dependencies
Score: The CCVSS (Common Vulnerability Scoring System) score
Refine the Explorer view
To refine the view, select the Filter icon () to open the filter panel and select one or more filters and filter options. The available filters are:
Type: Type of entity: application, server, API, database, library, or repository
Language: Languages for the applications you want to view
Open issue severity: Issue severity
Open incident severity: Incident severity
Application: Application name
AI: Whether the application uses AI/ML functionality, as detected by the agents. Select Uses AI to show only applications with detected AI/ML activity. Select Does not use AI to show only applications where no AI/ML activity has been detected.
Repositories: Filter by connected source code repository. This is a searchable, multi-select list.
Lifecycle: Filter by whether an entity is Active or Archived. Defaults to Active only selected, so archived entities don't clutter the graph unless you ask for them.