Authenticated vs unauthenticated scanning
Authenticated vs unauthenticated scanning: a balanced comparison for Azerbaijani business, grounded in how Argus Pentest works.
Authenticated vs. Unauthenticated Scanning
Choosing between authenticated and unauthenticated scanning determines the depth and accuracy of a security probe. While unauthenticated scans are limited to identifying external vulnerabilities visible to any visitor, authenticated scanning allows a tool to operate as a legitimate logged-in user. This capability is essential for testing the internal authenticated surface of enterprise web applications and their APIs, where the most critical business logic and sensitive data typically reside. As one of the three core engines of Argus—a self-hosted AI testing platform—this security engine shares its runtime, model layer, credential store, and cost ledger with the QA and AI engines. By leveraging a scripted login process, the scanner bypasses the limitation of stopping at the login page, ensuring that the security analysis reaches the deep functional layers of the application to identify vulnerabilities that would otherwise remain hidden from external scanners.
Advantages of the Authenticated Approach
Deep Surface Access: Penetrates beyond the login page to test the internal authenticated surface of web applications and APIs.
Logic-Level Testing: Enables the identification of vulnerabilities within internal application logic and authenticated API endpoints.
Secure Session Management: Utilizes an encrypted credential store to securely manage session cookies and bearer tokens.
Complete Data Sovereignty: Operates on self-hosted infrastructure, ensuring scan data, credentials, and reports never leave your environment.
Reduced Noise: Minimizes false positives by treating authentication failures as environment issues rather than security findings.
Flexible Engine Architecture: Uses an open-source engine via a CLI contract, allowing for seamless upgrades or replacement without platform disruption.
Core Capabilities of Argus Pentest
Deep Eye Integration
Powered by the Deep Eye open-source engine driven through a CLI contract, ensuring the scanner can be upgraded or replaced without touching the platform.
Synthesized API Specs
Endpoints discovered during the login and crawl process seed a synthesized API specification to ensure comprehensive coverage of the authenticated surface.
AI-Driven Payloads
The model layer is utilized specifically for payload generation and finding triage using a strict text-in, text-out approach without vision.
Strict Target Control
Security is maintained through an explicit allow-list; targets must be deliberately added before any scanning can be executed.
Detailed Reporting
Findings are categorized by severity and delivered via comprehensive HTML and JSON reports for technical and management review.
The Authenticated Scanning Process
Frequently Asked Questions
What happens if the scanner cannot authenticate?
Following the same honest-failure rule as the QA engine, a scanner that cannot authenticate is classified as an environment failure, not a security finding.
Where is the scan data stored and how is it protected?
The platform is entirely self-hosted. All scan data, credentials, and reports remain on your own infrastructure, eliminating external SaaS dependencies.
Does the AI use vision to analyze the application interface?
No. The AI model is used exclusively for text-based payload generation and finding triage; it operates on a text-in, text-out basis.
Can I track the exact cost per individual security test?
Currently, per-scan cost accounting is missing, meaning the engine cannot yet provide the specific cost-per-test metrics available in the QA engine.
How does the scanner ensure it doesn't hit unauthorized targets?
The scanner only operates against an explicit allow-list of approved targets; a target must be added deliberately before it can be scanned.
Secure Your Internal Surface
Move beyond the login page with authenticated scanning tailored for enterprise infrastructure. Contact Allmaz to learn more about Argus.
Request a demo