> For the complete documentation index, see [llms.txt](https://docs.akto.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.akto.io/api-protection/concepts/successful-exploits.md).

# Successful Exploits

**Successful Exploits Policy**

Customizable filters that mark detected security threats by Akto's Runtime Threat Protection as successful exploits in the Threat Activity dashboard.

**How to configure**

Go to **API Threat Detection → Threat Activity** in the left sidebar. Click **More Actions → Configure Successful Exploit**.

**Note:** Policies must use category name `SuccessfulExploit`

**Syntax Reference:** For detailed syntax on how to define API selection filters, see [API Selection Filters](https://docs.akto.io/test-editor/concepts/test-yaml-syntax-detailed/api-selection-filters).

<figure><img src="https://2916937215-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRc4KTKGprZI2sPWKoaLe%2Fuploads%2Fgit-blob-ae750dae82b65de74f65e3f03b397fee1c1524b5%2Fconfigure-exploits.png?alt=media" alt=""><figcaption></figcaption></figure>

**Example Successful Exploit Policy**

Marks all threats as successful exploits when the URL contains `test`.

```
id: SuccessfulExploit
filter:
  url:
    contains_all:
      - "test"

info:
  name: "SuccessfulExploit"
  description: "Marks threats as successful exploits"
  details: "Identifies which threat activities were actual successful attacks"
  impact: "Distinguishes real attacks from false positives"
  category:
    name: "SuccessfulExploit"
    displayName: "SuccessfulExploit"
  subCategory: "SuccessfulExploit"
  severity: HIGH
```

<figure><img src="https://2916937215-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRc4KTKGprZI2sPWKoaLe%2Fuploads%2Fgit-blob-14e3b29f66d661a8242ca25cf8d45c63fad2c86d%2Fexploits-policy.png?alt=media" alt=""><figcaption></figcaption></figure>
