Penetration Testing

Penetration Testing

Automated, repeatable penetration testing powered by 11 industry-standard open-source tools. Create projects, define targets, run assessments, and generate compliance-ready reports.

1Overview

The Penetration Testing module is an add-on to the Vulnios platform. It enables automated security assessments against web applications, APIs, networks, and infrastructure using battle-tested open-source tools.

Unlike static scanning, PT runs active probes — port scans, injection attempts, fuzzing, directory brute-forcing, and TLS analysis — giving you a real attacker's view of your attack surface.

PT is an add-on product available alongside core platform plans. Start with a 30-day free trial (PT Starter at $99/mo after trial), or subscribe directly to PT Pro, PT Pro+, or PT Enterprise.

2Tools & Engines

All 11 tools run in hardened Docker containers with zero data persistence:

NmapPort scanning & service detection
NiktoWeb server vulnerability scanning
SQLMapAutomated SQL injection testing
OWASP ZAPWeb application security scanner
NucleiTemplate-based vulnerability scanner
AmassAttack surface discovery & enumeration
GobusterDirectory & DNS brute-forcing
WfuzzWeb fuzzer for parameter testing
SSLScanTLS/SSL configuration analysis
DirbWeb content & path scanner
WhatWebWeb technology fingerprinting

3Projects & Targets

Projects group related targets and runs. Think of each project as one application, client, or environment.

  • Create projects with name, description, and optional tags.
  • Add targets: hostnames, IP addresses, URL ranges, or CIDR blocks.
  • Targets are validated before addition to prevent unauthorized scanning.
  • Import targets from CSV for bulk operations.
  • Per-target authentication support for authenticated scanning.

4Runs & Scheduling

Runs are individual pen test executions against your project's targets.

  • On-demand runs from the dashboard with one click.
  • Configure which tools to run or use the default "all tools" profile.
  • Real-time progress monitoring with per-tool status.
  • Concurrent run limits based on your PT plan tier.
  • Scheduled runs with cron support (PT Pro+ and above).

5Findings & Reports

Each run produces structured findings with full evidence:

  • Severity ratings (Critical → Info) with CVSS scores.
  • Tool attribution — which engine found each issue.
  • Evidence: HTTP request/response, screenshots, and command output.
  • Remediation recommendations with fix priority.
  • Export to HTML, JSON, PDF, CSV (format depends on plan tier).
  • Compliance mapping: PCI-DSS, OWASP Top 10, ISO 27001.
  • AI-powered narrative reports (PT Pro+ and above).

6Plans & Quotas

PT Plan Comparison

FeatureStarterProPro+Enterprise
Price$99/mo$199/mo$399/mo$999/mo
Projects31025Unlimited
Targets525100Unlimited
Runs/mo1050200Unlimited
Concurrent13510
Trial30 days
API Access
AI Reports
SSO