Adaptive test planner
Testing adapts to what your application reveals, not a fixed checklist. Every run is auditable.
Product · Inside every pentest
The AI penetration testing pipeline behind every Pentrova engagement. Everything below runs in every engagement. No tier-gating. No add-ons. No noise.
Web App Pentesting and API Pentesting are how you point Pentrova at a target. The capabilities below run inside every engagement: testing adapts to what your application reveals, every finding is verified against the live target, exploits are reproduced inside a sealed sandbox, and confirmed findings are escalated into business-impact paths.
Each card jumps to a section below. Capabilities work together as one engagement — recon, adaptive testing, verification, sandbox PoC, and escalation. None of them are tier-gated; pricing scales on portfolio scope, not pipeline features.
Testing adapts to what your application reveals, not a fixed checklist. Every run is auditable.
Multi-role session replay across reference responses surfaces real privilege bypasses.
Source-to-sink analysis across your client bundle, including React, Angular, and Vue sinks.
Sanitised RCE, LFI, SSRF, SQLi, XXE, SSTI exploits captured in a sealed sandbox.
Curated escalation catalog plus dynamic LLM chains turn one bug into business impact.
Coverage spans the full application attack surface — recon, injection, access control, business logic, protocol, and post-exploitation.
Every Pentrova engagement is one of two modes. The capabilities below describe how each mode exercises a target.
| Capability | Web App Pentesting | API Pentesting |
|---|---|---|
| Read-only reconnaissance | ||
| Adaptive test planner | ||
| Live-target finding verification | ||
| Sandbox PoC validation Critical / High findings | ||
| Authorization Matrix (multi-role replay) | ||
| Attack chain escalation | ||
| LLM-driven login (SPA / OAuth / SAML / MFA) | — | |
| JS-rendered crawl coverage | — | |
| DOM XSS source-to-sink analysis Browser-only signal | — | |
| OpenAPI / Postman / GraphQL / Protobuf / WSDL parsers | — | |
| Six auth modes (bearer / API key / basic / OAuth 2 / custom / mTLS) | — |
Capability · Adaptive test planner
Instead of a fixed test list, Pentrova adapts the test plan to what your application reveals — concentrating effort where the attack surface is richest and skipping what does not apply. Every decision is logged with its reasoning so the run is fully auditable after the fact.
Capability · DOM XSS taint
Reflected XSS fuzzing cannot catch DOM-only bugs. Pentrova analyses how untrusted values reach dangerous sinks in your actual client bundle — including the framework-specific sinks generic scanners miss in React, Angular, and Vue applications — then confirms exploitation in a real browser. Every finding ships with the source, the sink, and a reproducible URL.
Coverage for dangerouslySetInnerHTML, the sink generic scanners routinely miss in React bundles.
Coverage for the trusted-HTML and bind-HTML sinks Angular templates expose.
Coverage for the raw-HTML directive Vue templates expose.
Coverage for HTML-writing, script-evaluating, URL, and attribute sinks, plus the jQuery HTML helpers.
DOM XSS taint is a browser-side signal and runs only in Web App Pentesting engagements — API Pentesting has no DOM surface.
Capability · Sandbox PoC
For confirmed Critical and High findings, the sandbox renders a sanitised proof-of-concept — RCE, LFI, SSRF, SQLi, XXE, and SSTI classes included. Destructive payloads are swapped for read-only equivalents, egress defaults to deny-all, and customer data is redacted at the boundary. Every finding carries the captured request and response plus a reproducible command your engineers can run against the target themselves.
Capability · Attack chains
Confirmed findings feed the chain resolver. Pentrova ships a curated catalog of escalation chains and adds dynamic LLM-built chains at scan time when the catalog does not already encode a path between two findings. Both kinds are verified against the live target the same way, so the evidence quality is identical.
Impact: Full remote code execution on the application host
Impact: Instance IAM role takeover and downstream cloud access
Impact: Internal network read and cloud credential exposure
Capability · Agent library
Pentrova’s agent library is grouped by remit, not by name. Internal agent counts and the exhaustive inventory live behind the product console; the public surface here is the shape of the coverage so you can map it to your application boundaries before the call.
Observe traffic, DOM, headers, and responses without sending exploit payloads. Read-only by design, which is what lets Pentrova run safely against live systems.
Exercise classic injection classes — SQLi, command injection, LFI/RFI, SSTI — with conservative payload budgets and out-of-band confirmation. Every finding is verified before it reaches your queue.
Prove privilege bypasses through cross-role and cross-tenant replay. The Authorization Matrix above is the public face of this family.
Encode application-specific invariants — pricing, workflow order, rate and quota guards. These are findings a generic scanner can never ship because only the application knows what "broken" looks like.
Exercise modern API surfaces — REST, GraphQL, gRPC, SOAP, JSON-RPC, WebSocket — with parser-aware payloads tuned to each transport.
Once a beachhead is confirmed, post-exploitation agents pivot deterministically — cloud metadata reads, file exfiltration, lateral movement — under sandbox guardrails.
Authenticated crawl, JS-rendered DOM coverage, replay-verified findings.
Open Web App Pentesting →OpenAPI, Postman, GraphQL, Protobuf, WSDL across six auth modes.
Open API Pentesting →Findings flow into Slack, Microsoft Teams, Discord, email, and custom webhooks. CI gating templates ship for GitHub Actions, GitLab CI, Jenkins, CircleCI, Azure Pipelines, and Bitbucket.
Open Integrations →Next step
No sales call. No setup fee. Proof in minutes.