It doesn't just scan.It proves.
PentestForge's autonomous AI agent performs independent reconnaissance, validates findings with safe exploit PoCs, chains attack paths, eliminates false positives, and delivers evidence-backed intelligence — not scanner noise.
What the agent actually does
Standard scanners produce vulnerability lists. Deep Pentest AI produces validated exploitation evidence. The agent doesn't trust scanner output — it independently verifies, exploits, and documents real attack paths.
Independent Recon
Performs its own reconnaissance. Doesn't just trust scanner output.
Exploit Validation
7 exploit classes with safe PoCs. Proves impact, not just detection.
Attack Chains
Links findings into multi-step exploitation scenarios. SSRF → cloud → data.
False Positive Elimination
8-level validity classification. Evidence quality rating. Lab detection.
Autonomous 5-phase pipeline
Deep Pentest AI operates independently after initial scan data is received. Each phase builds on the previous, escalating from passive observation to controlled exploitation and intelligence packaging.
Independent Reconnaissance
The agent starts fresh — it doesn't just trust scanner output. It performs its own targeted recon: port scanning and service detection, HTTP fingerprinting, WAF detection, TLS analysis, and subdomain discovery. It sees what the scanner saw, then looks where it didn't.
Finding Triage & Prioritization
Scanner findings are ranked by real exploitability — not just CVSS score. The agent evaluates evidence quality, attack surface exposure, and business impact to decide which vulnerabilities deserve deep validation. Low-confidence findings get dismissed. High-value targets get escalated.
Targeted Exploitation
Seven specialized exploit classes validate real risk. Each uses safe, controlled proof-of-concept payloads that prove impact without causing damage. SQL injection extracts limited data. RCE runs harmless commands. LFI reads system files. SSRF accesses cloud metadata. Every exploit produces structured evidence.
Attack Chain Construction
Individual findings are linked into realistic multi-step attack scenarios. SSRF leads to cloud credentials. SQL injection enables auth bypass. LFI exposes configuration secrets. The agent maps how an attacker would actually chain vulnerabilities to achieve impact.
Evidence & Intelligence Reporting
Every validated finding includes the exact request, response, payload, and impact assessment. False positives are flagged with reasoning. The final report distinguishes confirmed vulnerabilities, suspicious findings, and dismissed noise — with full reproducibility.
7 exploit validation classes
Each exploit class uses safe, controlled proof-of-concept payloads. The goal is to demonstrate impact, not cause damage. Every validated finding includes the exact request, response, and impact assessment.
SQL Injection
criticalSafe data extraction proofs with limited read-only checks that demonstrate database access without modifying data.
Command Injection
criticalRCE validation through harmless command execution (id, whoami, hostname). Confirms code execution capability without destructive payloads.
Path Traversal & LFI
highLocal file inclusion verification reading non-sensitive system files. Proves file read access without exposing secrets.
Authentication Bypass
criticalDefault credentials, broken auth flows, and token manipulation. Proves unauthorized access without modifying accounts.
SSRF & Cloud Metadata
criticalServer-side request forgery validation including cloud metadata endpoint access (AWS, GCP, Azure). Proves internal network reachability.
XSS Exploitation
mediumReflected and stored XSS proof using harmless payloads with controlled callbacks. Verifies script execution without session hijacking.
Exploit Framework Integration
highNon-interactive exploit validation for version-specific vulnerabilities. Controlled proof-of-concept modules with safety constraints.
False positive elimination
Scanner noise doesn't reach your report. Multi-layer filtering, evidence-based classification, and intelligent deduplication ensure every finding is actionable.
Heuristic Classification
Findings sorted into 8 validity levels: confirmed, candidate, needs_validation, informational, likely_false_positive, parser_artifact, out_of_scope, and false_positive. Non-reportable noise eliminated upstream.
Evidence Quality Rating
6-level evidence scoring — exploited, reproducible, strong, basic, weak, none. You know exactly how reliable each result is.
Catch-All Server Detection
Identifies default HTTP servers that return 200 for any path — a major scanner false positive source — and suppresses meaningless findings.
Lab Environment Detection
Flags intentionally vulnerable training applications so they don't inflate your severity counts.
Root-Cause Deduplication
Groups related findings by root cause — not title matching. Merges duplicates from multiple scanners with the strongest available evidence.
Parser Artifact Removal
Eliminates encoding glitches, duplicate entries, and tool-specific noise before findings reach your report.
Intelligence, not just data
The final report is structured for action — confirmed findings with full evidence, attack chains showing real-world risk, and AI-generated remediation guidance.
Confirmed Findings
Vulnerabilities proven with exploit evidence, reproduction steps, and real impact assessment. Every finding is validated, not theoretical.
Attack Chain Narratives
Multi-step exploitation paths showing how vulnerabilities chain together. SSRF → cloud credentials → data access. Not just isolated findings.
Business Impact Context
Severity with exploitability assessment, remediation priority, and business impact. So you focus on what matters, not just CVSS.
AI Analysis & Recommendations
LLM-generated executive summary, remediation roadmap, and compliance mapping. Structured guidance, not generic prose.
What the agent is not
A vulnerability scanner
An autonomous exploitation and validation engine
A list of CVEs
Evidence-backed attack chains with real impact
Passive classification
Active proof-of-concept validation
Generic remediation advice
Context-rich intelligence with business impact
Noisy PDF reports
Structured findings with confidence scores and reproducibility
Theoretical risk
Proven exploitability with request/response evidence
Server auditing from the inside
PAssist runs a local audit agent directly on your infrastructure — no data leaves your network. 28 security modules with 119 checks cover OS hardening, SSH, Docker, Kubernetes, secrets, and more. Findings are grouped, confidence-rated, and can be escalated to Deep Pentest AI for attack chain validation or AI analysis.
Token-activated
Purchase tokens, install the agent, run audits. 1 token per server, 24h / 20 launches, unused tokens valid 30 days.
Data stays local
All checks run on your server. Sensitive values are redacted before transmission. Private keys detected by content, not filename.
Dual CIS scoring
Checks Score (all findings) and CIS Compliance Score (CIS-tagged only). Findings grouped with affected_count for accurate scoring.
AI Analyze
Send internal audit results to AI for intelligent analysis, prioritization, and remediation guidance.
119 checks, 15 modules
OS hardening, SSH & sudo, password policy, patches, firewall, Docker, K8s, cloud, secrets, malware, applications — full coverage.
Smart grouping
Similar findings grouped with affected_count and examples. 36 .env files become one finding, not 36 false positives.
