Use cases · Argus Pentest

Produce security-testing evidence for an audit

Produce security-testing evidence for an audit with Argus Pentest: a practical, on-prem approach built for Azerbaijani teams.

Enterprise-Grade Authenticated Security Scanning

Argus Pentest delivers a self-hosted, authenticated dynamic security scanning solution specifically engineered for enterprise web applications and their associated APIs. As one of the three core engines of the Argus AI testing platform, it leverages a shared runtime, model layer, credential store, and cost ledger alongside the QA and AI engines. This integration allows organizations to generate comprehensive security-testing evidence for audits while ensuring that all sensitive scan data, credentials, and reports remain strictly within their own private infrastructure, eliminating external SaaS dependencies. Unlike traditional scanners that often stop at the login page, Argus Pentest differentiates itself through deep authenticated scanning. By utilizing a scripted login process via an encrypted credential store, the system obtains the necessary session cookies and bearer tokens to operate as a real logged-in user. This capability, combined with the synthesis of API specifications from discovered endpoints, ensures that the scanner reaches the actual authenticated surface of the application, providing a rigorous and honest assessment of the security posture.

Capabilities

Key Advantages for Audit Compliance

Complete data sovereignty through a self-hosted deployment that keeps credentials and reports on-premises

Deep surface coverage by operating as a legitimate user to test protected application areas

High-signal reporting that treats authentication failures as environment issues rather than security findings

Strict security controls via an explicit allow-list, ensuring scans only run against approved targets

Future-proof architecture using a CLI-driven open-source engine that can be upgraded or replaced independently

Audit-ready documentation provided through standardized severity-based reports in HTML and JSON formats

Core Technical Capabilities

Authenticated Scanning

Utilizes a scripted login through an encrypted credential store to obtain session cookies and bearer tokens, ensuring the scanner operates as a legitimate user.

Synthesized API Mapping

Endpoints discovered during login and crawling seed a synthesized API specification, enabling the scan to reach protected surfaces beyond the login page.

AI-Driven Payload Generation

Integrates a model layer specifically for payload generation and finding triage, utilizing a text-in, text-out approach.

On-Premises Infrastructure

Eliminates external SaaS dependencies, ensuring that scan data, credentials, and reports remain on your own infrastructure.

Modular Engine Design

Driven by an open-source engine via a CLI contract, allowing the scanning component to be upgraded or replaced independently.

The Security Testing Workflow

1Define an explicit allow-list of approved targets to be scanned.
2Execute a scripted login using the platform's encrypted credential store.
3Crawl the application to synthesize an API specification for authenticated endpoints.
4Run dynamic security scans using AI-generated payloads for triage.
5Generate severity-based findings in HTML and JSON formats for audit documentation.

Frequently Asked Questions

How does the scanner handle authentication differently than standard tools?

It uses a scripted login process to retrieve session cookies and bearer tokens. This allows the scanner to operate as a real logged-in user, reaching the authenticated surface of the application rather than being blocked by the login page.

Where is the sensitive scan data and credential information stored?

All scan data, credentials, and reports are stored on your own self-hosted infrastructure. There is no external SaaS dependency, ensuring full data sovereignty.

How are the AI models utilized during the scanning process?

The model layer is used exclusively for payload generation and finding triage. It operates on a 'text in, text out' basis and does not utilize vision capabilities.

What happens if the scanner fails to authenticate during a run?

Following the 'honest-failure' rule, a failure to authenticate is categorized as an environment failure rather than a security finding, reducing noise in your audit reports.

Can the scanning engine be updated without affecting the rest of the platform?

Yes. Because the scanner (Deep Eye) is an open-source engine driven through a CLI contract, it can be upgraded or replaced without requiring changes to the broader Argus platform.

Ready to secure your audit process?

Contact Allmaz to implement Argus Pentest on your infrastructure.

Request a demo