← All capabilities
Deep Pentest AI

It doesn't just scan.It proves.

PentestForge's autonomous AI agent performs independent reconnaissance, validates findings with safe exploit PoCs, chains attack paths, eliminates false positives, and delivers evidence-backed intelligence — not scanner noise.

What the agent actually does

Standard scanners produce vulnerability lists. Deep Pentest AI produces validated exploitation evidence. The agent doesn't trust scanner output — it independently verifies, exploits, and documents real attack paths.

Independent Recon

Performs its own reconnaissance. Doesn't just trust scanner output.

Exploit Validation

7 exploit classes with safe PoCs. Proves impact, not just detection.

Attack Chains

Links findings into multi-step exploitation scenarios. SSRF → cloud → data.

False Positive Elimination

8-level validity classification. Evidence quality rating. Lab detection.

Autonomous 5-phase pipeline

Deep Pentest AI operates independently after initial scan data is received. Each phase builds on the previous, escalating from passive observation to controlled exploitation and intelligence packaging.

Phase 1

Independent Reconnaissance

The agent starts fresh — it doesn't just trust scanner output. It performs its own targeted recon: port scanning and service detection, HTTP fingerprinting, WAF detection, TLS analysis, and subdomain discovery. It sees what the scanner saw, then looks where it didn't.

port scanningHTTP fingerprintingWAF detectionTLS analysissubdomain discovery
Phase 2

Finding Triage & Prioritization

Scanner findings are ranked by real exploitability — not just CVSS score. The agent evaluates evidence quality, attack surface exposure, and business impact to decide which vulnerabilities deserve deep validation. Low-confidence findings get dismissed. High-value targets get escalated.

vulnerability scanningweb assessmentXSS detectioninjection testing
Phase 3

Targeted Exploitation

Seven specialized exploit classes validate real risk. Each uses safe, controlled proof-of-concept payloads that prove impact without causing damage. SQL injection extracts limited data. RCE runs harmless commands. LFI reads system files. SSRF accesses cloud metadata. Every exploit produces structured evidence.

SQL injectioncommand injectionexploit frameworknetwork testingcredential cracking
Phase 4

Attack Chain Construction

Individual findings are linked into realistic multi-step attack scenarios. SSRF leads to cloud credentials. SQL injection enables auth bypass. LFI exposes configuration secrets. The agent maps how an attacker would actually chain vulnerabilities to achieve impact.

custom analysisattack graph
Phase 5

Evidence & Intelligence Reporting

Every validated finding includes the exact request, response, payload, and impact assessment. False positives are flagged with reasoning. The final report distinguishes confirmed vulnerabilities, suspicious findings, and dismissed noise — with full reproducibility.

MarkdownHTMLJSONPDF

7 exploit validation classes

Each exploit class uses safe, controlled proof-of-concept payloads. The goal is to demonstrate impact, not cause damage. Every validated finding includes the exact request, response, and impact assessment.

SQL Injection

critical

Safe data extraction proofs with limited read-only checks that demonstrate database access without modifying data.

Command Injection

critical

RCE validation through harmless command execution (id, whoami, hostname). Confirms code execution capability without destructive payloads.

Path Traversal & LFI

high

Local file inclusion verification reading non-sensitive system files. Proves file read access without exposing secrets.

Authentication Bypass

critical

Default credentials, broken auth flows, and token manipulation. Proves unauthorized access without modifying accounts.

SSRF & Cloud Metadata

critical

Server-side request forgery validation including cloud metadata endpoint access (AWS, GCP, Azure). Proves internal network reachability.

XSS Exploitation

medium

Reflected and stored XSS proof using harmless payloads with controlled callbacks. Verifies script execution without session hijacking.

Exploit Framework Integration

high

Non-interactive exploit validation for version-specific vulnerabilities. Controlled proof-of-concept modules with safety constraints.

False positive elimination

Scanner noise doesn't reach your report. Multi-layer filtering, evidence-based classification, and intelligent deduplication ensure every finding is actionable.

Heuristic Classification

Findings sorted into 8 validity levels: confirmed, candidate, needs_validation, informational, likely_false_positive, parser_artifact, out_of_scope, and false_positive. Non-reportable noise eliminated upstream.

Evidence Quality Rating

6-level evidence scoring — exploited, reproducible, strong, basic, weak, none. You know exactly how reliable each result is.

Catch-All Server Detection

Identifies default HTTP servers that return 200 for any path — a major scanner false positive source — and suppresses meaningless findings.

Lab Environment Detection

Flags intentionally vulnerable training applications so they don't inflate your severity counts.

Root-Cause Deduplication

Groups related findings by root cause — not title matching. Merges duplicates from multiple scanners with the strongest available evidence.

Parser Artifact Removal

Eliminates encoding glitches, duplicate entries, and tool-specific noise before findings reach your report.

Intelligence, not just data

The final report is structured for action — confirmed findings with full evidence, attack chains showing real-world risk, and AI-generated remediation guidance.

Confirmed Findings

Vulnerabilities proven with exploit evidence, reproduction steps, and real impact assessment. Every finding is validated, not theoretical.

Attack Chain Narratives

Multi-step exploitation paths showing how vulnerabilities chain together. SSRF → cloud credentials → data access. Not just isolated findings.

Business Impact Context

Severity with exploitability assessment, remediation priority, and business impact. So you focus on what matters, not just CVSS.

AI Analysis & Recommendations

LLM-generated executive summary, remediation roadmap, and compliance mapping. Structured guidance, not generic prose.

What the agent is not

A vulnerability scanner

An autonomous exploitation and validation engine

A list of CVEs

Evidence-backed attack chains with real impact

Passive classification

Active proof-of-concept validation

Generic remediation advice

Context-rich intelligence with business impact

Noisy PDF reports

Structured findings with confidence scores and reproducibility

Theoretical risk

Proven exploitability with request/response evidence

Internal Audit Agent

Server auditing from the inside

PAssist runs a local audit agent directly on your infrastructure — no data leaves your network. 28 security modules with 119 checks cover OS hardening, SSH, Docker, Kubernetes, secrets, and more. Findings are grouped, confidence-rated, and can be escalated to Deep Pentest AI for attack chain validation or AI analysis.

Token-activated

Purchase tokens, install the agent, run audits. 1 token per server, 24h / 20 launches, unused tokens valid 30 days.

Data stays local

All checks run on your server. Sensitive values are redacted before transmission. Private keys detected by content, not filename.

Dual CIS scoring

Checks Score (all findings) and CIS Compliance Score (CIS-tagged only). Findings grouped with affected_count for accurate scoring.

AI Analyze

Send internal audit results to AI for intelligent analysis, prioritization, and remediation guidance.

119 checks, 15 modules

OS hardening, SSH & sudo, password policy, patches, firewall, Docker, K8s, cloud, secrets, malware, applications — full coverage.

Smart grouping

Similar findings grouped with affected_count and examples. 36 .env files become one finding, not 36 false positives.

Ready for real validation?

Stop trusting scanner output. Start proving real attack paths.