External attack surface
Enumerate a public domain: subdomains, DNS records, open ports, and the version fingerprint of every exposed service.
target: acme.example.comDescribe the objective and the target. PentAGI plans the engagement, drives a real terminal, browser, editor, and search inside a sandboxed Kali environment, and reports every finding with the evidence behind it.
Start with a sentence. PentAGI handles reconnaissance, exploitation attempts, privilege escalation, and reporting, then hands back a report that links every finding to the command that produced it.
Give the agent an objective, a target, and any rules of engagement. PentAGI plans the path itself: reconnaissance, exploitation attempts, privilege escalation, and reporting.
Every step runs inside a sandboxed container with a real terminal, a headless browser, a code editor, and web search, so the agent can act on what it discovers.
Commands, outputs, and observations are stored in PostgreSQL and indexed in a knowledge graph, so the final report cites the exact step that produced each finding.
Only test systems you are authorised to test. Every engagement requires an explicit target list, runs in an isolated sandbox, and keeps a complete command and output history for audit.
The same agent handles reconnaissance, web application testing, privilege escalation paths, and regression testing. Each pattern starts from a plain-language objective.
Enumerate a public domain: subdomains, DNS records, open ports, and the version fingerprint of every exposed service.
target: acme.example.comDrive a headless browser and a proxy through the app, capture every request, and follow the parameters that look injectable.
scope: staging web appCollect credentials from the environment, then map the shortest path from a low-privilege foothold to domain admin.
goal: privilege escalationRe-run the same engagement after every release and diff the findings against the previous run.
cadence: every deployCorrelate banner versions with CVEs and public exploit write-ups before attempting anything against the target.
source: CVE + vendor docsProduce realistic adversary activity and check whether your detections and alerts actually fire.
goal: validate detectionsPentAGI combines an isolated execution sandbox, a professional toolchain, and persistent memory so long engagements stay coherent and auditable.
The agent runs inside an isolated Docker environment with its own network and filesystem, so testing never touches your host.
PentAGI detects the next step from the previous result and performs it, instead of waiting for you to drive every command.
A headless browser fetches live pages, follows redirects, and reads documentation the moment the agent needs it.
Semantic memory powered by Graphiti and Neo4j keeps entities, credentials, hosts, and findings connected across the run.
Every command, output, and decision is persisted in PostgreSQL, so any terminal step can be replayed and audited later.
Over 200 penetration testing tools ship in the optimized Docker images, from nmap and ffuf to Metasploit and hydra.
Run the whole platform on your own infrastructure and keep engagement data inside your perimeter.
A sleek, intuitive console shows the live plan, current task, terminal stream, and accumulated findings side by side.
Control and monitor agents while they work: token usage, tool calls, latency, and cost per engagement.
Tool state and agent configuration are tracked in a Git project, so runs are reproducible.
Drive engagements from your own tooling through the REST and GraphQL APIs.
The agent looks up CVEs, exploits, and vendor documentation through Google, Tavily, and Traversaal.
From objective to report, the agent keeps a plan you can follow and intervene in at any point.
Describe the penetration testing objective, the target, and any constraints the agent must respect.
PentAGI decomposes the objective, picks a strategy, and builds a plan before touching the target.
The agent executes the plan in a sandboxed Kali environment, adapting as each result comes back.
Watch the plan, terminal stream, and findings update live, and intervene whenever you want.
Get a structured report that links every finding to the evidence that produced it.
Example objective: Assess the external perimeter of acme.example.com. Enumerate subdomains and exposed services, prioritise anything internet-facing with an outdated component, and attempt to demonstrate impact without disrupting production.
Bring your own key or run entirely locally. PentAGI supports the major model providers plus any OpenAI-compatible endpoint through LiteLLM.
GPT-5+ reasoning models for complex security analysis.
Claude 4+ series with exceptional reasoning capabilities.
Multimodal models with advanced thinking.
Enterprise-grade foundation models.
Local inference for zero-cost private testing.
Any OpenAI-compatible endpoint.
Fast inference for cost-effective operations.
Newest models through one unified API.
Reasoning models for complex problem solving.
Models with strong multilingual capabilities.
Long-context models up to 200k tokens.
Open-source models with strong reasoning.
PentAGI ships with a complete observability stack so you can analyse what the agent did, why it did it, and what it cost.
Visualize metrics and logs from every engagement.
Log aggregation for agent and tool output.
Column-oriented analytics database for run history.
Distributed tracing across agent steps.
Vendor-neutral instrumentation for the whole stack.
High-performance time series metrics.
Security teams use PentAGI for the work that is repetitive, time-boxed, or needs to run on every release.
Run repeatable internal engagements and keep the human operator on the decisions that matter.
Generate realistic adversary activity to validate detections and alerts end to end.
Reconnaissance, asset discovery, and repetitive probing handled by the agent while you focus on exploitation logic.
Drive web application assessments with browser automation, proxies, and evidence capture.
Produce auditable evidence trails for each test through the persisted command history.
Automate the tedious parts of a lab environment and study how an autonomous agent reasons.
Start monthly, or save 17% when you pay annually. Every plan unlocks the same PentAGI workflow - describe an objective and the agent plans, executes, and reports the engagement inside a sandboxed environment - so you only choose how much testing capacity you need.
Included
Included
Included
Answers about how the agent runs engagements, which models are supported, and how credits are consumed.
PentAGI is a fully autonomous AI agent for complicated penetration testing tasks. It plans an engagement, executes it with a terminal, browser, editor, and search inside a sandboxed environment, and produces a structured report.
Sign in with Google, pick a plan, describe the objective and target in the console, and start the engagement. Nothing needs to be installed to try the hosted workspace.
No. Every command runs inside an isolated Docker sandbox with its own network and filesystem, and all output is stored for the run.
More than 12 providers are supported, including OpenAI, Anthropic, Google Gemini, AWS Bedrock, Ollama, DeepInfra, OpenRouter, DeepSeek, GLM, Kimi, and Qwen, plus any OpenAI-compatible endpoint or a LiteLLM proxy.
Commands and outputs are persisted in PostgreSQL, and semantic memory is kept in a knowledge graph powered by Graphiti and Neo4j, so findings stay connected across a long engagement.
Yes. The console streams the plan, the active task, the terminal output, and new findings in real time, and monitoring integrations such as Langfuse, Grafana, and Jaeger are supported.
No. The hosted workspace provisions an isolated environment per engagement. Self-hosting on your own infrastructure is also supported if engagement data must stay in your perimeter.
Each engagement consumes credits based on the depth of the run, the number of tools invoked, and the reasoning model selected. The console shows an estimate before you start.
No. pentagi.homes is an independent third-party workspace and is not affiliated with, endorsed by, sponsored by, or operated by VXControl L.L.C-FZ or any of its affiliates.
Start using PentAGI today and experience AI-driven penetration testing on your own targets.