Glossary · Argus Pentest

What are scope and authorization in a penetration test?

What are scope and authorization in a penetration test? A clear explanation for Azerbaijani business — and how Argus Pentest applies it.

Enterprise Authenticated Dynamic Security Scanning

Argus Pentest provides authenticated dynamic security scanning designed specifically for enterprise web applications and their associated APIs. As one of the three core engines of the Argus self-hosted AI testing platform, it leverages a shared runtime, model layer, credential store, and cost ledger alongside the QA and AI engines. This integration ensures that security testing is not an isolated process but a coordinated effort that utilizes the same infrastructure and identity management as other quality and AI assurance workflows. Unlike traditional scanners that often stop at the login page, Argus Pentest focuses on the authenticated surface. By utilizing a scripted login process through an encrypted credential store, the scanner obtains the necessary session cookies and bearer tokens to operate as a legitimate logged-in user. This approach allows the system to discover endpoints during the login and crawl phases, which then seed a synthesized API specification, ensuring that the security assessment reaches the deep internal logic of the application where critical vulnerabilities often reside.

Capabilities

Key Advantages of Authenticated Scanning

Deep Surface Coverage: Reaches authenticated areas of the application and APIs that unauthenticated scanners cannot access.

Complete Data Sovereignty: Self-hosted architecture ensures all scan data, credentials, and reports remain on your own infrastructure without SaaS dependencies.

Reduced False Positives: Employs an AI model for precise payload generation and finding triage using a text-in, text-out approach.

Strict Target Control: Prevents accidental disruption by running scans exclusively against an explicit allow-list of approved targets.

Modular Flexibility: Utilizes the open-source Deep Eye engine via a CLI contract, allowing for seamless upgrades or replacement of the scanner.

Accurate Failure Attribution: Distinguishes between security vulnerabilities and environment failures, such as authentication errors.

Core Capabilities of Argus Pentest

Explicit Allow-Lists

Scans run only against a deliberately added list of approved targets, ensuring no unauthorized systems are touched.

Authenticated Scanning

Uses a scripted login via an encrypted credential store to operate as a real logged-in user, reaching the authenticated surface.

Self-Hosted Infrastructure

All scan data, credentials, and reports remain on your own infrastructure to eliminate external SaaS dependencies.

Synthesized API Specs

Endpoints discovered during login and crawling seed the API specification, allowing the scan to move beyond the login page.

Modular Engine Architecture

Driven by the Deep Eye open-source engine via CLI, allowing the scanner to be upgraded or replaced without affecting the platform.

The Argus Pentest Workflow

1Define the scope by adding approved targets to the explicit allow-list.
2Provide credentials through the encrypted credential store for authenticated access.
3Execute a scripted login to obtain session cookies and bearer tokens.
4Crawl the application to synthesize an API specification of the authenticated surface.
5Generate payloads and perform triage using the integrated AI model.
6Review findings via severity-based HTML and JSON reports.

Frequently Asked Questions

How does Argus Pentest handle credentials and session management?

It utilizes an encrypted credential store shared with the QA engine to perform scripted logins, which yields the session cookies and bearer tokens required to operate as a real user.

What happens if the scanner is unable to authenticate to the target?

Following the same honest-failure rule as the QA engine, a failure to authenticate is categorized as an environment failure rather than a security finding.

How is AI integrated into the scanning process?

The AI model is used exclusively for payload generation and finding triage. It operates strictly on a text-in, text-out basis and does not utilize vision capabilities.

Where is the scan data stored and who has access to it?

Because the platform is entirely self-hosted, all scan data, credentials, and reports stay on your own infrastructure, removing any external SaaS dependency.

Can the scanning engine be customized or updated?

Yes. The platform uses the Deep Eye open-source engine driven through a CLI contract, meaning the scanner can be upgraded or replaced without modifying the core platform.

Secure Your Enterprise Applications

Implement authenticated dynamic security scanning with Argus Pentest to identify vulnerabilities within your defined scope.

Request a demo