VULNERABILITY MANAGEMENT

Agentless Scanning, Results That Don't Sit in a Silo

Scan the external and internal perimeter with no agents to install. Then verify every finding automatically by running a real exploit against it - non-destructive by default, safe for stability and confidentiality - and reuse the results in the pentest, attack chain, and reporting modules.

0 agents
Nothing installed on the assets you scan
In + out
External perimeter and internal LAN
Reused
Feeds pentest, attack chains, and reporting

What the module does

Agentless, external and internal

Nothing to install on the assets you scan. Distributed scanner nodes cover the external perimeter from outside and the internal perimeter from inside the network, so one platform sees what an outside attacker sees and what an attacker already on the LAN sees.

  • No endpoint agents, no host software to deploy or maintain
  • External perimeter, internal LAN, cloud, and hybrid topologies
  • Distributed scanner nodes, including on-prem and air-gapped
  • Authenticated and unauthenticated scan modes

Automatic exploit verification, safely

The killer feature: every finding can be verified automatically by actually running an exploit against it. Verification is non-destructive by default - no data deletion, no payload that causes a crash, nothing that touches confidential data - and staging and production run as isolated scopes. A human-in-the-loop mode requires analyst approval before active exploitation.

  • Auto-verify all findings with real exploits, not just CVSS matching
  • Non-destructive by default: no crashes, no data loss, no data exfiltration
  • Isolated per-scan scopes; staging and production kept separate
  • Optional human-in-the-loop approval before active exploitation
  • Handles WAF, non-standard ports, and masked banners; every result has a PoC

Triage that holds up

Each vulnerability is a record with a machine status - unconfirmed, potential, detected, verified, exploited - that never silently downgrades. Mark a false positive, an accepted risk, or a won't-fix once, with a permanent audit trail, and it stays out of future results.

  • Per-finding status with full history and delta between scans
  • Built-in false-positive suppression per module
  • Exclusion log: who, when, and why, revocable by any reviewer
  • Verified findings auto-create tickets with reproduction steps

The data is reused everywhere

Scan results are not a dead-end report. They set pentest scope and priorities, feed the attack chain engine as graph nodes, correlate with DevGuard code findings, and carry business-impact and compliance context into reporting.

  • Feeds pentest scope, likely tech, and attack paths
  • Becomes nodes in cross-domain attack chains
  • Correlates with code and supply chain findings
  • Business-impact and compliance mapping for reports

FAQ

Do I need to install agents?

No. Scanning is fully agentless. Distributed scanner nodes assess the external perimeter from outside and the internal perimeter from inside the network - there is no host software to deploy on the assets being scanned.

Does it cover both external and internal scanning?

Yes. The same platform runs external perimeter scans from the internet-facing perspective and internal scans from inside the LAN, cloud, or a hybrid environment, with on-prem and air-gapped scanner options for restricted networks.

How is this different from a plain vulnerability scanner?

A plain scanner produces a list ranked by CVSS. Pentesterra can automatically verify each finding by running a real exploit against it, keeps a stable triage status per finding, and then reuses the results in the pentest, attack chain, and reporting modules instead of leaving them in a silo.

Is automatic exploit verification safe to run on production?

Yes. Verification is non-destructive by default - no data deletion, no denial-of-service payloads, and nothing that reads or exfiltrates confidential data. Each scan has an explicitly defined scope, staging and production are isolated, and a human-in-the-loop mode can require analyst approval before any active exploitation step.

Where do the scan results go?

Into every other module. They set penetration testing scope, become nodes in attack chains, correlate with DevGuard code and supply chain findings, and feed compliance and business-impact reporting.

Take Control of Your Attack Surface.

Start with the free tier or talk to us about your environment - network, web, cloud, or on-prem.