AI-driven security assessment

Security assessment that
actually runs the tools

An LLM agent that reasons step by step and executes real tools — nmap, nuclei, sqlmap, subfinder, katana, wpscan, nikto, and more — against targets you've verified you own. Not a simulation.

Start an assessment →
Sentinel's live reasoning stream, mid-assessment: an agent selecting tools, running them, and reporting real findings as it goes
The gap

Manual assessment is slow and expertise-gated. Automated scanners alone produce noise without judgment.

A real pentester reasons about a target — fingerprints it, forms a hypothesis, picks the next check based on what they just learned. A plain scanner just runs its whole list and hands you a report full of things that don't matter. Sentinel does the reasoning AND runs the real tools, so you get judgment and coverage, not one or the other.

Why not just open a Kali VM

Same real tools. None of the manual work.

Kali Linux is a toolbox — it doesn't decide what to run or read the output for you. Sentinel runs the same category of real, open-source tools, but the reasoning and orchestration are built in.

THE KALI LINUX WAY
  • Install and maintain a VM loaded with hundreds of tools
  • Learn each tool's own CLI syntax and flags from memory
  • Decide what to run next yourself, every single time
  • Copy output between tools by hand — IPs from nmap into nuclei, hosts from subfinder into httpx
  • Read raw terminal output, tool by tool
  • No built-in scope check — one wrong flag can hit the wrong host
  • Write the report yourself, after the fact
THE SENTINEL WAY
  • Nothing to install — runs in your browser
  • One conversation: describe the target, it does the rest
  • An LLM agent picks the next tool based on what it just learned
  • Real output from nmap, nuclei, subfinder, katana, and 20 more — chained automatically
  • A live reasoning stream, in plain language, as it works
  • Scope gate blocks anything outside your verified target — before it runs, not after
  • Ranked findings with real remediation, ready when it's done
How it works

Four steps. No wall of raw scanner output.

01

Describe the target

Tell it what you own and what you want checked. It asks what it needs to know before anything runs.

02

The agent reasons, live

An LLM agent picks the next tool based on what it's already learned — fingerprint first, then adapt: a confirmed WordPress install pulls in wpscan; a fingerprinted stack scopes nuclei's templates instead of running all 13,000+.

03

Real tools actually run

nmap, nuclei, subfinder, katana, and the rest execute for real, in a sandbox, against your verified target — not simulated, not mocked.

04

Ranked findings, real fixes

Every finding traces back to real tool output. Ranked by actual exploitability, with concrete remediation — not a wall of raw scanner noise.

The arsenal

24 real tools. Not a mock, not a wrapper.

20 run automatically once scope is verified. 4 exploitation-tier tools stay locked out unless you explicitly authorize active exploitation for that scan.

nmapdetect

Port and service scanner — what's actually exposed, and what version.

naabudetect

Fast port sweep that runs ahead of nmap, so it knows where to look.

nucleidetect

Template-matched CVE scanning, scoped to the fingerprinted stack.

niktodetect

Known-vulnerable server versions, dangerous files, risky HTTP methods.

httpxdetect

Fast fingerprint pass — status, title, server, CMS, framework.

tech_fingerprintdetect

CMS, JS framework, web server, and language detection.

wafw00fdetect

Active WAF fingerprinting — names the product, not just that one exists.

tls_probedetect

Deprecated protocols, weak ciphers, certificate trust issues.

security_headersdetect

CSP, X-Frame-Options, and other response-header hardening.

subfinderdetect

Passive subdomain enumeration, liveness-filtered automatically.

amassdetect

Deeper subdomain enumeration from a different source mix than subfinder.

katanadetect

JS-aware crawler — finds routes a wordlist would never guess.

ffufdetect

Content discovery — exposed configs, .env/.git, backup archives.

dns_securitydetect

SPF/DMARC/DKIM presence and strength, MX/NS posture.

secret_scandetect

Hardcoded API keys and tokens in pages and linked JS bundles.

graphql_probedetect

Common GraphQL endpoints, tested for open introspection.

wpscandetect

WordPress core/plugin/theme CVEs, exposed backups and debug logs.

http_probedetect

Composable request sequences for one specific, reasoned check.

cors_checkdetect

Reflected-Origin and null-origin CORS misconfigurations, credentials-aware.

cloud_storage_enumdetect

S3/GCS/Azure buckets named after the target — flags the ones left public.

sqlmapexploit

SQL injection testing against a parameter you have real reason to suspect.

dalfoxexploit

XSS scanning that DOM-confirms real execution, not just an unescaped reflection.

commixexploit

OS command injection, confirmed by observing actual command execution.

agent_scriptexploit

The agent writes and runs a short sandboxed script for logic no fixed tool expresses.

Global scan activity
Illustrative — not a real-time threat feed.
Reporting

Ranked findings, not raw scanner dumps

A real risk score, severity breakdown, and exploitability read on every finding — pulled straight from an actual scan, not a mockup.

Sentinel's scan report: risk score, severity donut, exploitability breakdown, and tool-by-tool findings from a real assessment
Safety

An agent with real guardrails, not a hope

Scope gate, fail closed

Every tool call is checked against your verified assets by exact host match before it runs — not after. Nothing reaches a target you haven't proven you own.

Exploitation needs your explicit sign-off

Detection-tier tools (nmap, nuclei, nikto, and 17 others) run freely once scope is verified. Exploitation-tier tools (sqlmap, dalfox, commix, agent_script) stay locked out entirely unless you explicitly authorize active exploitation for that scan.

Sandboxed execution

Every tool run happens in an isolated, egress-restricted sandbox — including agent-written scripts, which run under a real Python sandbox (RestrictedPython), not a trust-the-model hope.

Append-only audit log

Every action, every target, every command — logged and never edited or deleted. You can always answer "what did it actually do."

Point it at something you own

Start an assessment →