Features

A pentest pipeline, not a scanner.

SimpleSec runs the same workflow a senior pentester would — but at machine speed, with every step recorded. The AI planner decides what to do next; deterministic adapters do the work; a judge decides whether to advance, retry, or pause.

01

Recon

Passive subdomain discovery, port scanning, HTTP service enumeration, and content crawling. The planner builds the asset graph before it touches anything intrusive.

subfinder naabu httpx dnsx katana
02

Enumeration

Web vulnerability scanning with nuclei (4,000+ templates), directory and parameter fuzzing, framework detection, SSL/TLS posture, WordPress, and API surface mapping.

nuclei ffuf nikto testssl whatweb wpscan kiterunner arjun
03

Validation

SQL injection confirmation, parameter exploitation, credential verification, and database extraction as proof of impact. Findings are only promoted once they're proven, not just suspected.

sqlmap dalfox postgres_enum postgres_dump_table mssql_exec
04

Internal & AD

Once the WireGuard agent is connected, SimpleSec runs the full authenticated chain on the inside — AD enumeration, ticket roasting, BloodHound path analysis, certificate-template abuse, and proof of execution.

netexec_authed ldap_enum kerberoast bloodhound adcs secretsdump
Active Directory

Real attack chains, not just scans.

Most tools stop at "port 445 is open." SimpleSec authenticates, enumerates the domain, roasts what it can, maps every route to Domain Admin, and then proves the path is real.

01

Enumerate

Null-session SMB/RPC and anonymous LDAP first. Supply a low-privilege domain account — password or NTLM hash — and it re-runs authenticated: shares, sessions, users, groups, and the real password policy.

enum4linux netexec netexec_authed ldap_enum
02

Harvest credentials

Kerberoast SPN accounts and AS-REP roast anything without pre-auth, then crack offline. Recover GPP cpasswords left in SYSVOL, and crawl shares for the credentials people leave in files.

kerberoast asreproast gpp_password smb_spider hashcat
03

Map the routes

BloodHound collection and analysis, reported in plain English: how many distinct routes to Domain Admin exist, and which one an attacker would take first.

bloodhound delegation
04

Prove it

AD CS templates are swept for ESC1–ESC15. With destructive proofs enabled, the ESC1 exploit mints an impersonation certificate. Local-admin rights are validated, and secrets are dumped where the account allows.

adcs adcs_exploit secretsdump winrm_exec
Credentialed testing

Test as the account, not just at the perimeter.

Hand it a low-privilege domain account and it tests from that account's point of view — then tells you how far that account should have been able to get.

Password or NTLM hash

Supply either. The whole authenticated chain runs pass-the-hash if that's what you have, so a dumped hash keeps working without cracking it first.

Least-privilege audit

A first-class report section grading what the account you supplied could actually reach. Over-provisioned, or is least privilege holding? Answer it with evidence.

Lockout safety

Supplied credentials are auth-only and never sprayed. Spraying gets a per-account failure budget derived from the domain's real lockout policy.

Per-scan isolation

Every scan runs in its own network-isolated sandbox. A customer's internal ranges never touch the platform's network, or each other's.

Engagement types

Six personas, each with its own methodology

Pick the engagement type when you create it. It tunes which tools run and in what order — an Internal Network engagement won't fire the AD-specific chain, so choose Internal — Active Directory when that's what you want.

External Web App

HTTP discovery, subdomain enumeration, content fuzzing, and web vulnerability scanning.

External Network

Port discovery, service versions, TLS analysis, and edge-service vulnerabilities.

Internal Network

Mixed internal work — web, SMB shares, databases, file servers, and credential capture.

Internal — Active Directory

The full AD chain: LDAP, roasting, credential spray, BloodHound, and AD CS.

API

Endpoint discovery, parameter mining, injection testing, and auth flows.

Discovery

A fast "what's alive" inventory — hosts, open ports, and HTTP banners.

Reporting

Deliverables your client's auditor will accept

A finding without evidence is a guess. SimpleSec keeps the chain.

AttackForge export

Auto-mapped to AttackForge's vulnerability schema with CVSS:3.1 lookup from NVD, remediation templates, and attack scenarios.

White-labeled PDF reports

Consultant-style narrative plus per-finding evidence and remediation guidance — carrying your client's logo on Pro.

CSV exports

Findings, compromised credentials, and asset inventory as flat CSVs for your own pipelines.

Evidence chain

Every finding ties back to raw tool output, the exact command run, and the parsed record. Defensible under audit.

SCA & SAST ingest

POST your dependency-scanner output (osv-scanner) or Semgrep/CodeQL SARIF results and they fold into the same unified findings model.

CVSS scoring

Findings carry CVSS scores, so severity lines up with whatever your risk register already speaks.

Governance

Built for accountable testing

Pentest tools that don't track who did what get banned by procurement. SimpleSec was built the other way around.

Approval gates

Destructive actions and credential spray require admin approval before they ever leave the orchestrator.

Audit log

Every CRUD operation, approval decision, and config change is timestamped and attributed to a user and IP.

Encrypted at rest

Captured passwords, MFA secrets, and WireGuard private keys stored with Fernet symmetric encryption.

Per-engagement isolation

Auth configs, network profiles, and evidence stores are scoped to the engagement — never bleed across clients.

Under the hood

The AI is the planner, not the pentester.

SimpleSec uses an LLM to decide what to scan next, but every action is sanitized against discovered services and known URLs before execution — no hallucinated tools, no scans against targets that don't exist. A rule-based judge decides whether each step advances, retries, or pauses for review. Resumes cleanly across server restarts. Closes the browser? The test keeps running.

PLANNER
LLM + deterministic fallback
JUDGE
Rule-based, with retries
EXECUTOR
39 tool adapters, sandboxed

Ready to run your first test?

Self-serve signup. Verify your work-email domain and you're testing the same day.