On-Prem Agent
Deploy a single container on your network. Get continuous internal monitoring, port discovery, vulnerability detection, and credential testing, without VPNs, jump hosts, or inbound firewall rules.
docker compose up -d from the install snippet you copy out of the portal.What the agent does
Every capability runs entirely inside your network. Findings stream back to the portal over an authenticated, TLS-encrypted channel as they're discovered. The agent is what makes internal network penetration testing and Active Directory security testing possible without a VPN or a jump host.
LAN Asset Discovery
Sweeps your authorised CIDRs using ARP, multicast listeners, NetBIOS, mDNS, SSDP and SNMP probes. Builds a continuous asset inventory with reverse-DNS, OS hints, and open-port fingerprints, same level of coverage as commercial network-discovery scanners, no separate licence. This is the discovery layer behind internal network penetration testing.
Port & Service Detection
SYN-scan rate-limited port discovery against your authorised scope, followed by service / version banner-grabbing on every open port. Identifies HTTP, SMB, SSH, RDP, database, mail, AD, SNMP, IPSEC, MikroTik Winbox and dozens of other service families for downstream targeting.
Vulnerability Scanning
Template-based vulnerability detection covering OWASP Top 10, CVE catalogue (CISA KEV prioritised), and tech-stack-specific checks. Web servers, CMSes, APIs, network devices, and databases all get the same severity-scored treatment.
Credential Testing
Default-credential and weak-password checks against SSH, RDP, SMB, MSSQL, MySQL, PostgreSQL, FTP, VNC, Redis, MongoDB, SNMP, and IPSEC IKE. Results feed directly into post-auth enumeration and lateral-movement mapping.
Windows & AD Enumeration
SMB share enumeration, null-session checks, NetBIOS name queries, and authenticated post-exploitation including SAM / NTDS hash dumps for password-policy auditing. Domain-controller fingerprinting and Kerberoasting hooks for identity-attack-path mapping. See Active Directory security testing for the full identity scope.
Web Application Testing
HTTP server fingerprinting, content-discovery fuzzing, SQL-injection detection, XSS validation, and TLS posture audit on every discovered web endpoint, including intranet apps that an external scanner can't reach.
Exploit Chain Intelligence
Findings carry CVE refs, CVSS scores, KEV flags, and publicly-known exploit availability so your team can triage by real-world exploitability instead of raw severity. Exploitation strategies are dispatched from the platform and execute on the agent for low latency.
SSH-Driven Remediation
Auto-generated, idempotent remediation playbooks dispatch to the agent and apply fixes over your existing SSH infrastructure, no separate config-management rollout required. Rescan-to-confirm closes the loop.
Continuous Monitoring
Drift ledger captures every host, port, and service change between sweeps. New asset alerts, missing-host alerts, and threat-intel-classified inbound traffic events stream to your dashboard, Slack, or webhook of choice in real time.
How it talks to the platform
One outbound TLS connection. No inbound rules. Every action is signed with a per-tenant API key issued at install time.
What the diagram shows
- The agent sits inside your network as a Docker container, RPM, or DEB package. One host can cover multiple subnets.
- All scanning of servers, workstations, and network devices happens locally, on the LAN, so nothing has to be tunnelled to reach an internal target.
- The agent opens one outbound TLS 443 connection to the PentestOps platform and authenticates with a per-tenant API key issued at install time. Restrictive corporate proxies are supported via HTTP CONNECT.
- Nothing connects inbound. The agent has no listening port, so there is no inbound firewall rule to open, no port forward, and no VPN tunnel to maintain.
- Your team reaches findings, reports, and the API from any browser through the platform, never through the agent.
Built for security teams
The agent is itself security-hardened, same scrutiny we apply to the systems it scans. Our Trust Centre covers platform-side encryption, tenant isolation, access control, and data residency.
Network posture
- Outbound-only TLS 443 to the platform, no inbound listeners
- Server-authenticated TLS with per-tenant API key
- Operates entirely inside your network, never proxies third-party traffic
- Survives restrictive corporate proxies (HTTP CONNECT supported)
Data & identity
- Discovered credentials never leave the agent in plaintext, redacted before findings ship
- Scope-of-work signed and version-controlled in the platform; agent refuses out-of-scope targets
- SSH keys for remediation stay on your hosts, agent uses them, never exfiltrates
- Full audit trail of every dispatched scan, exploit, and remediation
Operations
- Auto-update with operator-controlled change windows, or freeze indefinitely
- Health checks, structured JSON logs, Prometheus-compatible metrics
- Single-binary install, no agent server, no orchestrator hub to manage
- Zero state to back up, if the host dies, deploy a fresh agent and reconnect
Compliance
- Every scan / exploit / remediation tied to a signed Rules of Engagement
- Findings auto-mapped to 8 reporting frameworks (OWASP Top 10, PCI-DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks. These are the frameworks findings map to in reports, not a certification claim
- 365-day audit-log retention; assessment findings kept per plan (Starter 1 year, Professional 3 years, Enterprise and MSP 7 years), with exported reports and legal records retained beyond that
- Built for tenants under regulatory scope, not "ship it and pray"
vs. the alternatives
Honest comparison against the three categories buyers usually evaluate alongside us. Capabilities below reflect each vendor's public documentation as of mid-2026; check current vendor docs if you're making a procurement decision today.
| Capability | PentestOps Agent | Cloud agent scanners (Qualys VMDR, Tenable Nessus Agent, Rapid7 InsightVM) | EASM platforms (CyCognito, Tenable EASM, Mandiant Advantage) | PTaaS (Cobalt, Synack, HackerOne Pentest) |
|---|---|---|---|---|
| Coverage | ||||
| Internal LAN scanning (no VPN) | ✓ Native | ✓ Native | × External only | ~ Manual VPN to tester |
| External-attack-surface monitoring | ✓ Continuous | ~ Add-on tier | ✓ Native | × Point-in-time |
| Web application testing | ✓ Built-in | ~ Separate product | × Surface only | ✓ Manual depth |
| Exploitation (not just detection) | ✓ Strategy engine | × Detect only | × Detect only | ✓ Manual |
| Auto-remediation playbooks | ✓ One-click apply | × Ticket export | × Ticket export | × Recommendation only |
| Deployment | ||||
| Inbound firewall rules required | ✓ None | ✓ None | ✓ N/A (cloud-only) | ~ Tester-dependent |
| Time to first scan | ✓ ~5 minutes | ~ Hours-to-days | ✓ ~1 hour (DNS-driven) | × Days-to-weeks (contracting) |
| Self-update mechanism | ✓ Operator-controlled | ✓ Vendor-controlled | N/A | N/A |
| Operating model | ||||
| Continuous (vs. point-in-time) | ✓ Continuous | ✓ Continuous | ✓ Continuous | × Quarterly / ad-hoc |
| Findings stream live to dashboard | ✓ WebSocket | ~ Polling | ~ Polling | × End-of-engagement report |
| AI-driven finding triage | ✓ Native | ~ Add-on | ~ Add-on | × Human-only |
| Compliance mapping (SOC 2 / PCI / etc.) | ✓ 8 frameworks built-in | ✓ Selected frameworks | ~ Limited | ~ Manual narrative |
| Commercial | ||||
| Pricing model | ✓ Per asset, predictable | Per IP / per asset | Per domain / surface | Per engagement |
| Per-tool licence fees | ✓ None | × Add-ons priced separately | ✓ None | N/A |
| Multi-tenant MSP support | ✓ Built-in | ~ Enterprise tier | ~ Enterprise tier | × Single-engagement |
What the agent is NOT
Honest scope, so you're not surprised after install.
Not a backdoor
It only does what you dispatch from the portal, signed, scoped, audit-logged. No remote-shell-on-demand for our staff.
Not always-on traffic monitoring
It scans on a schedule and on demand. It's not an IDS/IPS; if you want a SIEM, keep your SIEM, the agent integrates as a data source.
Not a replacement for human pentesters
It runs the repetitive, high-volume work (port sweep, vuln scan, default creds, web fuzzing) so your humans focus on the creative testing automation handles poorly. We co-exist with your retainer.
Not a VPN
Outbound WebSocket only, we never route your application traffic, never relay your users, never become a chokepoint for your business operations.
Not yet-another-thing-to-monitor
The agent reports its own health back to the portal. If it stops checking in, you get an alert, you don't have to add it to your monitoring stack manually.
Not running unsigned code
The agent image is built from versioned, audited Dockerfiles. SBOM available on request for procurement / compliance review.
Frequently Asked Questions
How long does the agent take to deploy, and how does it ship?
About 5 minutes. You copy the install snippet out of the portal and run it on one host inside the network you want tested. The agent ships as a Docker container, an RPM or a DEB package, so it fits whatever build process you already use. There is no agent server, orchestrator hub or database to stand up alongside it, and there is no state to back up: if the host dies, deploy a fresh agent and it reconnects.
Do I need to open inbound firewall rules or run a VPN?
No. The agent makes a single outbound, server-authenticated TLS 443 connection to the platform and listens on nothing, so 0 inbound firewall rules are required and there is no VPN, jump host or tester credential to manage. It survives restrictive corporate proxies via HTTP CONNECT and reconnects automatically after a link drop. Scans execute natively on the LAN instead of tunnelling every packet out to a remote scanner, so internal testing is not constrained by the capacity of a VPN or WAN link.
Can one agent cover multiple subnets?
Yes. One host can cover multiple subnets, provided it can route to them and those ranges are inside your authorised scope. Most organisations start with a single agent and add more only where routing, segmentation or a separate site makes it necessary, for example a DMZ that cannot reach the core network. Multi-site and MSP fleets are managed centrally from the portal, including force-update across every deployed agent.
How does the agent update, and can I control when?
Updates are operator-controlled. You choose the change window in which the agent may update itself, or freeze it indefinitely and roll updates on your own schedule. Images are built from versioned, audited Dockerfiles rather than pulled from an unsigned source, and an SBOM is available on request for procurement or compliance review. The agent reports its own health back to the portal, so if it stops checking in you get an alert instead of silent gaps in coverage.
What does the agent do with credentials it discovers?
Discovered credentials are redacted before findings ship, so they never leave the agent in plaintext. SSH keys used for remediation stay on your hosts; the agent uses them in place and never exfiltrates them. Every dispatched scan, exploitation attempt and remediation playbook is tied to a signed Rules of Engagement record and written to a full audit trail, and the agent refuses targets outside the approved scope.
What is the agent not?
It is not a backdoor: it only performs work you dispatch from the portal, signed, scoped and audit-logged. It is not always-on traffic monitoring, so it does not replace an IDS, IPS or SIEM, though it integrates as a data source. It is not a VPN and never routes your application traffic. And it is not a replacement for human pentesters: it runs the repetitive, high-volume testing so your specialists can spend their time on the creative work that automation handles poorly.
Do I need the agent for external, cloud or Kubernetes testing?
No. External network, web application, API and email assessments run from the platform without an agent, cloud posture auditing uses read-only credentials you issue, and Kubernetes auditing is agentless via a read-only kubeconfig. The agent exists for the work that can only be done from inside: LAN asset discovery, internal port and service detection, credential testing, Windows and Active Directory enumeration, intranet web applications, and continuous drift monitoring.
Ready to see your network from the inside?
Start a free trial, the install snippet is in your portal within 5 minutes of sign-up. No charge for 7 days, a card is required to start your trial and is only charged after the trial ends, unless you cancel first.
Start Free Trial