External & Internal Scanning
24+ external recon modules and 18+ internal modules running through a
reverse SOCKS5 tunnel from your on-prem agent. Stealth and custom
profiles for noise-sensitive environments.
- Fast port discovery + deep service enumeration
- Service version + WAF detection
- SSL/TLS, DNS, subdomain, email-security audit
- Stealth, balanced, and aggressive profiles
Vulnerability Detection
Automated vulnerability scanning with CVE correlation and
CVSS scoring for accurate risk assessment.
- CVE database integration
- CVSS v3.1 scoring
- False positive reduction
- Exploit availability check
Web & API Testing
OWASP Top 10 + API Top 10 coverage with template based
detection, custom checks, and live findings streamed to
the dashboard as they are discovered.
- SQLi, XSS, SSRF, IDOR, auth bypass
- REST + GraphQL API security
- M365 / Azure AD audit
- Real-time WebSocket finding stream
Asset Inventory & AI Discovery
Continuous asset inventory with AI-powered classification,
bulk CSV/XLSX import, agent-based LAN discovery, and 7-day
re-verification lifecycle. Drift ledger captures every change.
- AI asset classification + criticality
- Multi method LAN discovery via on prem agent
- Cloud sync (AWS, Azure, GCP, M365)
- Drift detection + change ledger
Cloud Security (CSPM)
800+ automated security checks across AWS, Azure, and GCP.
Credential-based API auditing with continuous misconfiguration detection.
- AWS: 572 checks across 83 services
- Azure: 165 checks across 20 services
- GCP: 100 checks across 13 services
- ECR/ACR/GCR container image CVE scanning
- CIS Benchmarks for AWS / Azure / GCP (Prowler) and Kubernetes node + control-plane (kube-bench)
- 8 compliance reporting frameworks (OWASP, PCI-DSS, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001), plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes
Infrastructure Assessment
Deep infrastructure security testing across Active Directory,
container, and Kubernetes environments. Kubernetes auditing is
fully agentless: onboard a cluster by pasting a kubeconfig, with
no permanent agent or DaemonSet to install.
- Active Directory enumeration + privilege escalation paths
- Agentless Kubernetes via kubeconfig: GKE (incl. Autopilot), EKS (incl. Fargate), AKS, OpenShift, k3s, on-prem
- API posture audit (kubeaudit): RBAC, securityContext, privileged pods, capabilities, network policy, image provenance
- Node + control-plane CIS Kubernetes Benchmark via a short-lived, auto-cleaned in-cluster job (kube-bench)
- On fully-managed clusters (Autopilot, Fargate), node CIS routes through the cloud configuration audit while API posture still runs
- Docker / container image security scanning
Compliance Reporting
Generate compliance-ready reports for major frameworks with
detailed evidence and remediation guidance.
- OWASP Top 10 mapping
- PCI-DSS v4.0 mapping
- NIST 800-53 controls
- SOC2, HIPAA, GDPR
- ISO 27001, SMB1001
Analytics & Trending
Track security posture over time with scan comparisons and
remediation velocity metrics.
- Scan-over-scan comparison
- Trend & SLA analysis
- Executive dashboards
- Custom metrics & alerts
Continuous Monitoring (EASM)
Agentless External Attack Surface Management with HMAC-signed
log shipping, change and drift alerting, and continuous re-checks
of your perimeter between scheduled scans.
- Drift & asset-change alerts + email + webhook
- Customer log shipper (HMAC-signed ingest)
- 24/7 monitoring of public assets
- Slack-compatible incident webhooks
Auto Exploitation Framework
Safe, auditable proof of exploit on confirmed findings.
The strategy engine auto picks the best technique per
finding; chained pipelines turn one weak credential into
a full pivot.
- Credential brute force, VPN, network device, container
- Phased exploit chains with evidence carry over
- Per tenant Rules of Engagement gates
- Full evidence trail + audit log
AI Guided Remediation
Per finding AI remediation with clear explanation,
validated fix steps, and one click playbook deployment
via the on prem agent for SSH managed targets.
- Context aware risk + business impact scoring
- Auto generated patch ready playbooks
- SSH key discovery + safe execution
- Roll back on validation failure
MSP & Multi-Tenancy
Run an MSP practice on isolated per-tenant Kubernetes namespaces
with custom domains, custom SSL, Okta SSO, GitOps provisioning,
and per-tenant pricing tiers.
- Per-tenant namespace + DB isolation
- Custom & auto-managed SSL (ACME)
- Tenant SSO (Okta) for Pro & Enterprise
- Fleet orchestrator + force-update agents
Platform Security
ISO/IEC 27001:2022 certified and built to SOC 2-aligned
controls, with encrypted secrets injection, encryption at
rest, RBAC, MFA, and a full audit trail of every scan,
exploit, and config change.
- Encrypted secrets vault with dynamic injection
- JWT + session bound auth, MFA
- Per IP login rate limiting
- 365-day audit-log retention
Ready to secure your infrastructure?
Start a 7-day trial on any tier and run your first assessment against assets you own.
A card is required to start your trial and is only charged after it ends, unless you
cancel first.
Want the deeper background first? Read
our methodology,
see how PentestOps compares,
or browse the Knowledge Centre.