Glossary · Argus Pentest

What is penetration testing?

What is penetration testing? A clear explanation for Azerbaijani business — and how Argus Pentest applies it.

Enterprise Authenticated Security Scanning

Argus Pentest provides authenticated dynamic security scanning specifically designed for enterprise web applications and their associated APIs. As one of the three core engines of the Argus self-hosted AI testing platform, it leverages a shared runtime, model layer, credential store, and cost ledger alongside the QA and AI engines. This integration ensures that security testing is not a siloed process but a coordinated effort within a unified infrastructure, allowing for a comprehensive evaluation of the application's security posture. The primary differentiator of this solution is its ability to perform authenticated scanning. By utilizing a scripted login process through an encrypted credential store, the scanner obtains session cookies and bearer tokens, enabling it to operate as a legitimate logged-in user. This approach allows the scanner to move beyond the login page and reach the authenticated surface of the application, ensuring that protected endpoints and internal logic are thoroughly vetted for vulnerabilities.

Capabilities

Advantages of Authenticated Testing

Deep Surface Coverage: Penetrates beyond the login screen to identify vulnerabilities within the authenticated areas of the application.

Realistic User Simulation: Operates as a real logged-in user by utilizing valid session cookies and bearer tokens.

Comprehensive API Security: Discovers and tests protected API endpoints through a synthesized API specification generated during the crawl.

Total Data Sovereignty: Maintains a self-hosted architecture where all scan data, credentials, and reports remain on your own infrastructure.

Flexible Engine Lifecycle: Utilizes the Deep Eye open-source engine via a CLI contract, allowing for seamless upgrades or replacement.

Actionable Intelligence: Delivers detailed findings categorized by severity through standardized HTML and JSON reporting.

Core Capabilities of Argus Pentest

Authenticated Scanning

Utilizes a scripted login through an encrypted credential store to obtain session cookies and bearer tokens.

Synthesized API Discovery

Endpoints discovered during login and crawling seed a synthesized API spec to ensure deep coverage.

AI-Driven Payloads

Uses a model layer specifically for payload generation and finding triage through text-based processing.

Strict Target Control

Scans are executed only against an explicit allow-list of approved targets to prevent unauthorized scanning.

Modular Engine Architecture

Powered by the Deep Eye open-source engine, allowing for upgrades or replacement via its CLI contract.

The Pentest Workflow

1Define an explicit allow-list of approved targets for scanning.
2Execute a scripted login using the encrypted credential store to acquire session tokens.
3Crawl the application to synthesize an API specification of the authenticated surface.
4Generate and deploy security payloads using the AI model layer.
5Triage findings and generate reports categorized by severity in HTML and JSON.

Frequently Asked Questions

Where is the scan data stored?

The platform is entirely self-hosted, ensuring that all scan data, credentials, and reports stay on your own infrastructure with no external SaaS dependency.

What happens if the scanner cannot authenticate?

Following the same honest-failure rule as the QA engine, a failure to authenticate is classified as an environment failure rather than a security finding.

How does the AI contribute to the testing process?

The AI model is used exclusively for payload generation and finding triage. It operates on a strict text-in, text-out basis and does not utilize vision.

How are targets managed to prevent unauthorized scanning?

The system uses a strict allow-list; a target must be deliberately added to this list before the scanner is permitted to run against it.

Can the scanning engine be updated or replaced?

Yes, because the scanner is based on the Deep Eye open-source engine and interacts via a CLI contract, it can be upgraded or replaced without modifying the rest of the platform.

Secure Your Enterprise Applications

Integrate authenticated dynamic security scanning into your workflow with Argus Pentest.

Request a demo