A pentest pipeline, not a scanner.
SimpleSec runs the same workflow a senior pentester would — but at machine speed, with every step recorded. The AI planner decides what to do next; deterministic adapters do the work; a judge decides whether to advance, retry, or pause.
Recon
Passive subdomain discovery, port scanning, HTTP service enumeration, and content crawling. The planner builds the asset graph before it touches anything intrusive.
Enumeration
Web vulnerability scanning with nuclei (4,000+ templates), directory and parameter fuzzing, framework detection, SSL/TLS posture, WordPress, and API surface mapping.
Validation
SQL injection confirmation, parameter exploitation, credential verification, and database extraction as proof of impact. Findings are only promoted once they're proven, not just suspected.
Internal & AD
Once the WireGuard agent is connected, SimpleSec runs the full authenticated chain on the inside — AD enumeration, ticket roasting, BloodHound path analysis, certificate-template abuse, and proof of execution.
Real attack chains, not just scans.
Most tools stop at "port 445 is open." SimpleSec authenticates, enumerates the domain, roasts what it can, maps every route to Domain Admin, and then proves the path is real.
Enumerate
Null-session SMB/RPC and anonymous LDAP first. Supply a low-privilege domain account — password or NTLM hash — and it re-runs authenticated: shares, sessions, users, groups, and the real password policy.
Harvest credentials
Kerberoast SPN accounts and AS-REP roast anything without pre-auth, then crack offline. Recover GPP cpasswords left in SYSVOL, and crawl shares for the credentials people leave in files.
Map the routes
BloodHound collection and analysis, reported in plain English: how many distinct routes to Domain Admin exist, and which one an attacker would take first.
Prove it
AD CS templates are swept for ESC1–ESC15. With destructive proofs enabled, the ESC1 exploit mints an impersonation certificate. Local-admin rights are validated, and secrets are dumped where the account allows.
Test as the account, not just at the perimeter.
Hand it a low-privilege domain account and it tests from that account's point of view — then tells you how far that account should have been able to get.
Password or NTLM hash
Supply either. The whole authenticated chain runs pass-the-hash if that's what you have, so a dumped hash keeps working without cracking it first.
Least-privilege audit
A first-class report section grading what the account you supplied could actually reach. Over-provisioned, or is least privilege holding? Answer it with evidence.
Lockout safety
Supplied credentials are auth-only and never sprayed. Spraying gets a per-account failure budget derived from the domain's real lockout policy.
Per-scan isolation
Every scan runs in its own network-isolated sandbox. A customer's internal ranges never touch the platform's network, or each other's.
Six personas, each with its own methodology
Pick the engagement type when you create it. It tunes which tools run and in what order — an Internal Network engagement won't fire the AD-specific chain, so choose Internal — Active Directory when that's what you want.
External Web App
HTTP discovery, subdomain enumeration, content fuzzing, and web vulnerability scanning.
External Network
Port discovery, service versions, TLS analysis, and edge-service vulnerabilities.
Internal Network
Mixed internal work — web, SMB shares, databases, file servers, and credential capture.
Internal — Active Directory
The full AD chain: LDAP, roasting, credential spray, BloodHound, and AD CS.
API
Endpoint discovery, parameter mining, injection testing, and auth flows.
Discovery
A fast "what's alive" inventory — hosts, open ports, and HTTP banners.
Deliverables your client's auditor will accept
A finding without evidence is a guess. SimpleSec keeps the chain.
AttackForge export
Auto-mapped to AttackForge's vulnerability schema with CVSS:3.1 lookup from NVD, remediation templates, and attack scenarios.
White-labeled PDF reports
Consultant-style narrative plus per-finding evidence and remediation guidance — carrying your client's logo on Pro.
CSV exports
Findings, compromised credentials, and asset inventory as flat CSVs for your own pipelines.
Evidence chain
Every finding ties back to raw tool output, the exact command run, and the parsed record. Defensible under audit.
SCA & SAST ingest
POST your dependency-scanner output (osv-scanner) or Semgrep/CodeQL SARIF results and they fold into the same unified findings model.
CVSS scoring
Findings carry CVSS scores, so severity lines up with whatever your risk register already speaks.
Built for accountable testing
Pentest tools that don't track who did what get banned by procurement. SimpleSec was built the other way around.
Approval gates
Destructive actions and credential spray require admin approval before they ever leave the orchestrator.
Audit log
Every CRUD operation, approval decision, and config change is timestamped and attributed to a user and IP.
Encrypted at rest
Captured passwords, MFA secrets, and WireGuard private keys stored with Fernet symmetric encryption.
Per-engagement isolation
Auth configs, network profiles, and evidence stores are scoped to the engagement — never bleed across clients.
The AI is the planner, not the pentester.
SimpleSec uses an LLM to decide what to scan next, but every action is sanitized against discovered services and known URLs before execution — no hallucinated tools, no scans against targets that don't exist. A rule-based judge decides whether each step advances, retries, or pauses for review. Resumes cleanly across server restarts. Closes the browser? The test keeps running.
Ready to run your first test?
Self-serve signup. Verify your work-email domain and you're testing the same day.