5 min
Time to deploy
One docker compose up -d from the install snippet you copy out of the portal.
0
Inbound firewall rules
Outbound-only WebSocket to the platform. Nothing to whitelist on your perimeter.
3
Install formats
Ships as a Docker container, RPM, or DEB package. One host can cover multiple subnets.
24/7
Continuous monitoring
Asset inventory, drift detection, and unauthorised-change alerts run on a schedule.

What the agent does

Every capability runs entirely inside your network. Findings stream back to the portal over an authenticated, TLS-encrypted channel as they're discovered. The agent is what makes internal network penetration testing and Active Directory security testing possible without a VPN or a jump host.

LAN Asset Discovery

Sweeps your authorised CIDRs using ARP, multicast listeners, NetBIOS, mDNS, SSDP and SNMP probes. Builds a continuous asset inventory with reverse-DNS, OS hints, and open-port fingerprints, same level of coverage as commercial network-discovery scanners, no separate licence. This is the discovery layer behind internal network penetration testing.

Port & Service Detection

SYN-scan rate-limited port discovery against your authorised scope, followed by service / version banner-grabbing on every open port. Identifies HTTP, SMB, SSH, RDP, database, mail, AD, SNMP, IPSEC, MikroTik Winbox and dozens of other service families for downstream targeting.

Vulnerability Scanning

Template-based vulnerability detection covering OWASP Top 10, CVE catalogue (CISA KEV prioritised), and tech-stack-specific checks. Web servers, CMSes, APIs, network devices, and databases all get the same severity-scored treatment.

Credential Testing

Default-credential and weak-password checks against SSH, RDP, SMB, MSSQL, MySQL, PostgreSQL, FTP, VNC, Redis, MongoDB, SNMP, and IPSEC IKE. Results feed directly into post-auth enumeration and lateral-movement mapping.

Windows & AD Enumeration

SMB share enumeration, null-session checks, NetBIOS name queries, and authenticated post-exploitation including SAM / NTDS hash dumps for password-policy auditing. Domain-controller fingerprinting and Kerberoasting hooks for identity-attack-path mapping. See Active Directory security testing for the full identity scope.

Web Application Testing

HTTP server fingerprinting, content-discovery fuzzing, SQL-injection detection, XSS validation, and TLS posture audit on every discovered web endpoint, including intranet apps that an external scanner can't reach.

Exploit Chain Intelligence

Findings carry CVE refs, CVSS scores, KEV flags, and publicly-known exploit availability so your team can triage by real-world exploitability instead of raw severity. Exploitation strategies are dispatched from the platform and execute on the agent for low latency.

SSH-Driven Remediation

Auto-generated, idempotent remediation playbooks dispatch to the agent and apply fixes over your existing SSH infrastructure, no separate config-management rollout required. Rescan-to-confirm closes the loop.

Continuous Monitoring

Drift ledger captures every host, port, and service change between sweeps. New asset alerts, missing-host alerts, and threat-intel-classified inbound traffic events stream to your dashboard, Slack, or webhook of choice in real time.

How it talks to the platform

One outbound TLS connection. No inbound rules. Every action is signed with a per-tenant API key issued at install time.

Your network PentestOps agent Docker, RPM or DEB Scans run on the LAN Servers Workstations Network devices Perimeter firewall Outbound TLS 443 Agent opens the connection No inbound rule The agent has no listening port PentestOps platform Portal, API, AI analysis and reporting Findings, reports, API Your team Any browser, no VPN

What the diagram shows

  • The agent sits inside your network as a Docker container, RPM, or DEB package. One host can cover multiple subnets.
  • All scanning of servers, workstations, and network devices happens locally, on the LAN, so nothing has to be tunnelled to reach an internal target.
  • The agent opens one outbound TLS 443 connection to the PentestOps platform and authenticates with a per-tenant API key issued at install time. Restrictive corporate proxies are supported via HTTP CONNECT.
  • Nothing connects inbound. The agent has no listening port, so there is no inbound firewall rule to open, no port forward, and no VPN tunnel to maintain.
  • Your team reaches findings, reports, and the API from any browser through the platform, never through the agent.

Built for security teams

The agent is itself security-hardened, same scrutiny we apply to the systems it scans. Our Trust Centre covers platform-side encryption, tenant isolation, access control, and data residency.

Network posture

  • Outbound-only TLS 443 to the platform, no inbound listeners
  • Server-authenticated TLS with per-tenant API key
  • Operates entirely inside your network, never proxies third-party traffic
  • Survives restrictive corporate proxies (HTTP CONNECT supported)

Data & identity

  • Discovered credentials never leave the agent in plaintext, redacted before findings ship
  • Scope-of-work signed and version-controlled in the platform; agent refuses out-of-scope targets
  • SSH keys for remediation stay on your hosts, agent uses them, never exfiltrates
  • Full audit trail of every dispatched scan, exploit, and remediation

Operations

  • Auto-update with operator-controlled change windows, or freeze indefinitely
  • Health checks, structured JSON logs, Prometheus-compatible metrics
  • Single-binary install, no agent server, no orchestrator hub to manage
  • Zero state to back up, if the host dies, deploy a fresh agent and reconnect

Compliance

  • Every scan / exploit / remediation tied to a signed Rules of Engagement
  • Findings auto-mapped to 8 reporting frameworks (OWASP Top 10, PCI-DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks. These are the frameworks findings map to in reports, not a certification claim
  • 365-day audit-log retention; assessment findings kept per plan (Starter 1 year, Professional 3 years, Enterprise and MSP 7 years), with exported reports and legal records retained beyond that
  • Built for tenants under regulatory scope, not "ship it and pray"

vs. the alternatives

Honest comparison against the three categories buyers usually evaluate alongside us. Capabilities below reflect each vendor's public documentation as of mid-2026; check current vendor docs if you're making a procurement decision today.

Capability PentestOps Agent Cloud agent scanners (Qualys VMDR, Tenable Nessus Agent, Rapid7 InsightVM) EASM platforms (CyCognito, Tenable EASM, Mandiant Advantage) PTaaS (Cobalt, Synack, HackerOne Pentest)
Coverage
Internal LAN scanning (no VPN) Native Native × External only ~ Manual VPN to tester
External-attack-surface monitoring Continuous ~ Add-on tier Native × Point-in-time
Web application testing Built-in ~ Separate product × Surface only Manual depth
Exploitation (not just detection) Strategy engine × Detect only × Detect only Manual
Auto-remediation playbooks One-click apply × Ticket export × Ticket export × Recommendation only
Deployment
Inbound firewall rules required None None N/A (cloud-only) ~ Tester-dependent
Time to first scan ~5 minutes ~ Hours-to-days ~1 hour (DNS-driven) × Days-to-weeks (contracting)
Self-update mechanism Operator-controlled Vendor-controlled N/A N/A
Operating model
Continuous (vs. point-in-time) Continuous Continuous Continuous × Quarterly / ad-hoc
Findings stream live to dashboard WebSocket ~ Polling ~ Polling × End-of-engagement report
AI-driven finding triage Native ~ Add-on ~ Add-on × Human-only
Compliance mapping (SOC 2 / PCI / etc.) 8 frameworks built-in Selected frameworks ~ Limited ~ Manual narrative
Commercial
Pricing model Per asset, predictable Per IP / per asset Per domain / surface Per engagement
Per-tool licence fees None × Add-ons priced separately None N/A
Multi-tenant MSP support Built-in ~ Enterprise tier ~ Enterprise tier × Single-engagement

What the agent is NOT

Honest scope, so you're not surprised after install.

Not a backdoor

It only does what you dispatch from the portal, signed, scoped, audit-logged. No remote-shell-on-demand for our staff.

Not always-on traffic monitoring

It scans on a schedule and on demand. It's not an IDS/IPS; if you want a SIEM, keep your SIEM, the agent integrates as a data source.

Not a replacement for human pentesters

It runs the repetitive, high-volume work (port sweep, vuln scan, default creds, web fuzzing) so your humans focus on the creative testing automation handles poorly. We co-exist with your retainer.

Not a VPN

Outbound WebSocket only, we never route your application traffic, never relay your users, never become a chokepoint for your business operations.

Not yet-another-thing-to-monitor

The agent reports its own health back to the portal. If it stops checking in, you get an alert, you don't have to add it to your monitoring stack manually.

Not running unsigned code

The agent image is built from versioned, audited Dockerfiles. SBOM available on request for procurement / compliance review.

Frequently Asked Questions

How long does the agent take to deploy, and how does it ship?

About 5 minutes. You copy the install snippet out of the portal and run it on one host inside the network you want tested. The agent ships as a Docker container, an RPM or a DEB package, so it fits whatever build process you already use. There is no agent server, orchestrator hub or database to stand up alongside it, and there is no state to back up: if the host dies, deploy a fresh agent and it reconnects.

Do I need to open inbound firewall rules or run a VPN?

No. The agent makes a single outbound, server-authenticated TLS 443 connection to the platform and listens on nothing, so 0 inbound firewall rules are required and there is no VPN, jump host or tester credential to manage. It survives restrictive corporate proxies via HTTP CONNECT and reconnects automatically after a link drop. Scans execute natively on the LAN instead of tunnelling every packet out to a remote scanner, so internal testing is not constrained by the capacity of a VPN or WAN link.

Can one agent cover multiple subnets?

Yes. One host can cover multiple subnets, provided it can route to them and those ranges are inside your authorised scope. Most organisations start with a single agent and add more only where routing, segmentation or a separate site makes it necessary, for example a DMZ that cannot reach the core network. Multi-site and MSP fleets are managed centrally from the portal, including force-update across every deployed agent.

How does the agent update, and can I control when?

Updates are operator-controlled. You choose the change window in which the agent may update itself, or freeze it indefinitely and roll updates on your own schedule. Images are built from versioned, audited Dockerfiles rather than pulled from an unsigned source, and an SBOM is available on request for procurement or compliance review. The agent reports its own health back to the portal, so if it stops checking in you get an alert instead of silent gaps in coverage.

What does the agent do with credentials it discovers?

Discovered credentials are redacted before findings ship, so they never leave the agent in plaintext. SSH keys used for remediation stay on your hosts; the agent uses them in place and never exfiltrates them. Every dispatched scan, exploitation attempt and remediation playbook is tied to a signed Rules of Engagement record and written to a full audit trail, and the agent refuses targets outside the approved scope.

What is the agent not?

It is not a backdoor: it only performs work you dispatch from the portal, signed, scoped and audit-logged. It is not always-on traffic monitoring, so it does not replace an IDS, IPS or SIEM, though it integrates as a data source. It is not a VPN and never routes your application traffic. And it is not a replacement for human pentesters: it runs the repetitive, high-volume testing so your specialists can spend their time on the creative work that automation handles poorly.

Do I need the agent for external, cloud or Kubernetes testing?

No. External network, web application, API and email assessments run from the platform without an agent, cloud posture auditing uses read-only credentials you issue, and Kubernetes auditing is agentless via a read-only kubeconfig. The agent exists for the work that can only be done from inside: LAN asset discovery, internal port and service detection, credential testing, Windows and Active Directory enumeration, intranet web applications, and continuous drift monitoring.

Ready to see your network from the inside?

Start a free trial, the install snippet is in your portal within 5 minutes of sign-up. No charge for 7 days, a card is required to start your trial and is only charged after the trial ends, unless you cancel first.

Start Free Trial