01
Engagement management
Targets, ports, PTES checklists, credential vaults, loot, timelines and time logging — the whole engagement in one place, exported as a portable .pcbundle.
- Seven-phase PTES
- Credential vault
- .pcbundle export/import
02
Findings & evidence
CVSS v3.1 scoring, evidence uploads, CVE/CWE lookups, confidence and false-positive flags, and a 2,400+ template library with cross-engagement dedupe.
- 2,400+ templates
- Nessus & Burp import
- CVE / CWE lookups
03
Attack paths & tooling
Cytoscape graphs of hosts, users, creds and services with technique-labelled edges, alongside a 55-tool hub that auto-discovers binaries and streams live output.
- Path-to-goal highlighting
- 55 tools, 10 categories
- Live output streaming
04
Scanning & automation
A passive web scanner graded A–F, auto-scan rules that match ports and services, finding triggers, false-positive suppression and scheduled recurring scans.
- TLS · headers · CORS
- Auto-scan rules
- Scheduled scans
05
Reporting & sharing
DOCX and PDF with custom branding, executive summaries, technical sections and per-engagement redaction — plus token-based, read-only client portals.
- DOCX & PDF
- Per-engagement redaction
- Client portals
06
Team, API & the rest
Role-based access, TOTP MFA and audit logging; a REST API and Slack/Discord/Teams webhooks; playbooks, exam mode, notes, a hash identifier and a Base64 codec.
- RBAC & TOTP MFA
- REST API & webhooks
- Exam mode