Use cases · Argus Pentest

Security-test every release

Security-test every release with Argus Pentest: a practical, on-prem approach built for Azerbaijani teams.

Authenticated Security Testing for Every Release

Integrate authenticated dynamic security scanning directly into your release cycle with Argus Pentest. As one of the three core engines of the Argus self-hosted AI testing platform, it leverages a shared runtime, model layer, credential store, and cost ledger alongside the QA and AI engines. This unified architecture allows Azerbaijani enterprise teams to identify critical vulnerabilities in web applications and APIs by simulating real user sessions, ensuring that security testing is a consistent part of the deployment pipeline rather than an afterthought. Unlike traditional scanners that stop at the login page, Argus Pentest focuses on the authenticated surface. By utilizing scripted logins and synthesized API specifications, the system operates as a real logged-in user to uncover deep-seated vulnerabilities. Because the solution is entirely self-hosted, all sensitive scan data, credentials, and reports remain within your own infrastructure, eliminating external SaaS dependencies and ensuring total data sovereignty for enterprise environments.

Capabilities

The Argus Pentest Advantage

Complete data sovereignty via self-hosted deployment, keeping credentials and reports on-premise

Deep coverage of authenticated application surfaces through session-aware scanning

Strict security controls using explicit allow-lists to ensure only approved targets are scanned

Reduced configuration overhead by utilizing a shared encrypted credential store

Future-proof architecture with a modular engine that can be upgraded without platform disruption

Actionable intelligence delivered through severity-categorized HTML and JSON reports

Core Capabilities

Authenticated Scanning

Uses scripted logins and encrypted credential stores to obtain session cookies and bearer tokens, allowing the scanner to operate as a logged-in user.

Synthesized API Discovery

Endpoints discovered during login and crawling seed a synthesized API spec, ensuring the scan reaches beyond the login page.

AI-Driven Payloads

Utilizes a model layer specifically for payload generation and finding triage through text-based processing.

Modular Engine Design

Powered by the Deep Eye open-source engine via CLI contract, enabling the engine to be upgraded or replaced without platform disruption.

On-Premise Infrastructure

All scan data, credentials, and reports remain on your own infrastructure with no external SaaS dependency.

How it Works

1Define an explicit allow-list of approved targets to be scanned.
2Execute a scripted login via the shared encrypted credential store to acquire session tokens.
3Crawl the application to synthesize an API specification of the authenticated surface.
4Run dynamic security scans using AI-generated payloads to identify vulnerabilities.
5Review findings categorized by severity in HTML or JSON reports.

Frequently Asked Questions

How does the tool handle authentication to reach deep application layers?

It performs a scripted login using the platform's encrypted credential store to acquire session cookies and bearer tokens, enabling the scanner to operate with the permissions of a real logged-in user.

Where is the sensitive scan data and credential information stored?

The platform is entirely self-hosted, meaning all scan data, reports, and credentials stay on your own internal infrastructure with no external SaaS dependency.

What happens if the scanner fails to authenticate during a run?

Following the platform's 'honest-failure' rule, a failure to authenticate is classified as an environment failure rather than a security finding.

Can I track the specific cost associated with each individual security test?

Currently, per-scan cost accounting is missing, so the engine cannot yet provide a specific cost-per-test metric like the QA engine can.

How is AI utilized within the scanning process?

The AI model is used exclusively for payload generation and the triage of findings through text-in, text-out processing; it does not use vision capabilities.

Secure Your Release Pipeline

Deploy Argus Pentest on your infrastructure and start testing your authenticated surfaces today.

Request a demo