Triage scanner findings
Triage scanner findings with Argus Pentest: a practical, on-prem approach built for Azerbaijani teams.
Precision Authenticated Security Scanning
Argus Pentest is a self-hosted AI testing platform engineered for authenticated dynamic security scanning of enterprise web applications and their associated APIs. As one of the three core engines of the Argus ecosystem, it integrates seamlessly with a shared runtime, model layer, credential store, and cost ledger, allowing it to operate in tandem with QA and AI engines. By prioritizing authenticated access, the platform ensures that security assessments penetrate deep into the application's logic rather than being halted at the login screen. The system distinguishes itself by utilizing a scripted login process via an encrypted credential store to acquire session cookies and bearer tokens, enabling the scanner to operate with the permissions of a real logged-in user. This approach, combined with a synthesized API specification derived from discovery and crawling, allows the scanner to map and test the authenticated surface area. All operations are conducted within a self-hosted environment, ensuring that sensitive scan data, credentials, and reports remain entirely on your own infrastructure without external SaaS dependencies.
Strategic Advantages of Argus Pentest
Complete data sovereignty through a self-hosted architecture that eliminates external SaaS dependencies
Deep visibility into protected application surfaces via authenticated session and token management
High-signal reporting by categorizing authentication failures as environment issues rather than security findings
Future-proof modularity using the Deep Eye open-source engine, allowing upgrades via CLI contract without platform disruption
Enterprise-grade security for sensitive access keys through a shared, encrypted credential store
Actionable intelligence delivered through structured severity-based reports in both HTML and JSON formats
Core Capabilities
Authenticated Scanning
Uses a scripted login through an encrypted credential store to obtain session cookies and bearer tokens, operating as a real logged-in user.
Synthesized API Mapping
Endpoints discovered during login and crawling seed a synthesized API specification to ensure the scan reaches protected areas.
AI-Driven Triage
Utilizes a text-based model specifically for payload generation and the triage of findings.
Strict Target Control
Scans are executed only against an explicit allow-list of approved targets to prevent unauthorized scanning.
Modular Engine Design
Driven by the Deep Eye open-source engine via CLI contract, allowing the engine to be replaced or upgraded without affecting the platform.
The Triage Workflow
Frequently Asked Questions
Where is the scan data and credential information stored?
The platform is entirely self-hosted. All scan data, reports, and credentials remain on your own internal infrastructure, ensuring there is no external SaaS dependency.
How does the platform handle authentication failures during a scan?
Following the same honest-failure rule as the QA engine, a scanner that cannot authenticate is treated as an environment failure rather than a security finding.
What role does AI play in the scanning process?
The AI model is used exclusively for text-based operations, specifically for payload generation and the triage of findings; it does not utilize vision capabilities.
Can the scanning engine be updated or replaced?
Yes. Because the platform is driven by the Deep Eye open-source engine through a CLI contract, the engine can be upgraded or replaced without needing to modify the broader platform.
Is it possible to track the cost per individual security test?
Currently, per-scan cost accounting is missing, meaning the engine cannot yet provide the specific cost-per-test metrics available in the QA engine.
Secure Your Enterprise Applications
Deploy Argus Pentest on your own infrastructure to start triaging authenticated security findings today.
Request a demo