Glossary · Argus Pentest

What is an attack surface?

What is an attack surface? A clear explanation for Azerbaijani business — and how Argus Pentest applies it.

Comprehensive Attack Surface Analysis

An attack surface represents the total sum of all potential entry points where an unauthorized user could attempt to penetrate or extract sensitive data from an environment. In the context of enterprise web applications and APIs, this encompasses every accessible endpoint, login portal, and interface. If these surfaces are not properly secured, they become primary vectors for exploitation, making it critical to identify and harden every possible point of interaction. Argus addresses this challenge through authenticated dynamic security scanning, specifically designed for enterprise-grade web applications and their associated APIs. As one of the three core engines of the Argus self-hosted AI testing platform, it shares a unified runtime, model layer, credential store, and cost ledger with the QA and AI engines. By focusing on the authenticated surface, Argus ensures that security testing extends beyond the perimeter, uncovering vulnerabilities that are only visible to logged-in users.

Capabilities

Advantages of Authenticated Scanning

Uncovers hidden vulnerabilities by penetrating the login page to analyze the authenticated surface

Mimics real-world user behavior through scripted logins and session token acquisition

Guarantees total data sovereignty by keeping all scan data and credentials on self-hosted infrastructure

Eliminates accidental targeting by restricting scans to an explicit, deliberately managed allow-list

Provides actionable intelligence via severity-based reporting in both HTML and JSON formats

Ensures platform longevity through a modular design that allows the scanning engine to be upgraded via CLI contract

Argus Pentest Capabilities

Authenticated Scanning

Utilizes a scripted login through an encrypted credential store to obtain session cookies and bearer tokens, allowing the scanner to operate as a real user.

Dynamic API Discovery

Endpoints discovered during login and crawling seed a synthesized API spec, ensuring the scan reaches the authenticated surface.

Self-Hosted Architecture

All scan data, credentials, and reports remain on your own infrastructure with no external SaaS dependency.

AI-Driven Payloads

Integrates a model specifically for payload generation and finding triage using a text-in, text-out approach.

Modular Engine Design

Driven by an open-source engine via CLI contract, allowing the scanner to be upgraded or replaced without affecting the platform.

The Argus Pentest Process

1Define an explicit allow-list of approved targets to be scanned.
2Execute a scripted login using the encrypted credential store to acquire session tokens.
3Crawl the application to discover endpoints and synthesize an API specification.
4Generate and deploy security payloads using the integrated AI model.
5Analyze results and generate findings reports in HTML and JSON formats.

Frequently Asked Questions

How does Argus handle target selection and safety?

To prevent unauthorized scanning, Argus operates strictly against an explicit allow-list of approved targets. A target must be added deliberately to this list before any scan can be initiated.

What happens if the scanner fails to authenticate?

Argus applies an 'honest-failure' rule: if the scanner cannot authenticate, it is recorded as an environment failure rather than a security finding, ensuring reports remain accurate.

How is AI utilized within the scanning process?

The AI model is used exclusively for payload generation and the triage of findings. It operates on a text-in, text-out basis and does not utilize vision capabilities.

Where is the sensitive scan data stored?

Because Argus is a self-hosted platform, all scan data, credentials, and reports remain entirely on your own infrastructure, removing any dependency on external SaaS providers.

Can the scanning engine be updated or changed?

Yes. The scanner uses an open-source engine driven through a CLI contract, meaning the engine can be upgraded or replaced without needing to modify the core platform.

Secure Your Authenticated Surface

Discover the vulnerabilities that hide behind your login page with Argus Pentest's authenticated dynamic scanning.

Request a demo