What is penetration testing?
What is penetration testing? A clear explanation for Azerbaijani business — and how Argus Pentest applies it.
Enterprise Authenticated Security Scanning
Argus Pentest provides authenticated dynamic security scanning specifically designed for enterprise web applications and their associated APIs. As one of the three core engines of the Argus self-hosted AI testing platform, it leverages a shared runtime, model layer, credential store, and cost ledger alongside the QA and AI engines. This integration ensures that security testing is not a siloed process but a coordinated effort within a unified infrastructure, allowing for a comprehensive evaluation of the application's security posture. The primary differentiator of this solution is its ability to perform authenticated scanning. By utilizing a scripted login process through an encrypted credential store, the scanner obtains session cookies and bearer tokens, enabling it to operate as a legitimate logged-in user. This approach allows the scanner to move beyond the login page and reach the authenticated surface of the application, ensuring that protected endpoints and internal logic are thoroughly vetted for vulnerabilities.
Advantages of Authenticated Testing
Deep Surface Coverage: Penetrates beyond the login screen to identify vulnerabilities within the authenticated areas of the application.
Realistic User Simulation: Operates as a real logged-in user by utilizing valid session cookies and bearer tokens.
Comprehensive API Security: Discovers and tests protected API endpoints through a synthesized API specification generated during the crawl.
Total Data Sovereignty: Maintains a self-hosted architecture where all scan data, credentials, and reports remain on your own infrastructure.
Flexible Engine Lifecycle: Utilizes the Deep Eye open-source engine via a CLI contract, allowing for seamless upgrades or replacement.
Actionable Intelligence: Delivers detailed findings categorized by severity through standardized HTML and JSON reporting.
Core Capabilities of Argus Pentest
Authenticated Scanning
Utilizes a scripted login through an encrypted credential store to obtain session cookies and bearer tokens.
Synthesized API Discovery
Endpoints discovered during login and crawling seed a synthesized API spec to ensure deep coverage.
AI-Driven Payloads
Uses a model layer specifically for payload generation and finding triage through text-based processing.
Strict Target Control
Scans are executed only against an explicit allow-list of approved targets to prevent unauthorized scanning.
Modular Engine Architecture
Powered by the Deep Eye open-source engine, allowing for upgrades or replacement via its CLI contract.
The Pentest Workflow
Frequently Asked Questions
Where is the scan data stored?
The platform is entirely self-hosted, ensuring that all scan data, credentials, and reports stay on your own infrastructure with no external SaaS dependency.
What happens if the scanner cannot authenticate?
Following the same honest-failure rule as the QA engine, a failure to authenticate is classified as an environment failure rather than a security finding.
How does the AI contribute to the testing process?
The AI model is used exclusively for payload generation and finding triage. It operates on a strict text-in, text-out basis and does not utilize vision.
How are targets managed to prevent unauthorized scanning?
The system uses a strict allow-list; a target must be deliberately added to this list before the scanner is permitted to run against it.
Can the scanning engine be updated or replaced?
Yes, because the scanner is based on the Deep Eye open-source engine and interacts via a CLI contract, it can be upgraded or replaced without modifying the rest of the platform.
Secure Your Enterprise Applications
Integrate authenticated dynamic security scanning into your workflow with Argus Pentest.
Request a demo