Hand the platform a scope of CIDRs, IPs, ASNs, or domains and pick a depth. A lead orchestrator agent runs a phased external pentest by spawning phase subagents that drive recon, discovery, assessment, and proof-of-concept tools over SSH on a hardened Kali worker. Every host, service, finding, and command lands on a live timeline you can audit phase by phase.
No VPN to a jump box, no operator wiring up tooling from scratch. You define the scope, the orchestrator picks up a Kali worker, and the engagement runs end to end on a methodology you can read.
Two views from a sample Assessment-depth engagement: what the operator recorded in each methodology phase, and the external attack surface it built up while walking the playbook.
Each bar shows how many timeline events the operator wrote during a phase, split by outcome. Skipped checkpoints stay visible so you can see where the operator stood down and why.
A live graph of what the operator found. The scope expands into live hosts, hosts expose services, and the red edge is the single non-destructive proof of exploitation against a confirmed weakness.
The scope textarea accepts four token types. ASNs and domains are expanded on the Kali worker during recon, so the platform carries no whois or DNS dependency of its own.
Same scope, same worker, different aggressiveness. The depth you pick is the depth the operator executes, and the phase set is gated to it so there is no scope creep.
The recon, scanning, and exploitation tooling runs on the Kali worker, the same shared pool that drives DAST. Here is the toolkit the operator reaches for.
Define a scope of CIDRs, IPs, ASNs, or domains, pick a depth, and let an AI operator run the engagement over a hardened Kali worker.
Choose which categories you are happy to allow. You can change your mind at any time using the Cookie settings link in the footer.