Braintruder · the platform

Not just another tool.An AI security operator.

Braintruder runs methodology-led penetration tests against your real surface - hypothesising, probing, and capturing evidence like a seasoned operator, then turning it into a clear, prioritised report your team can act on. No specialist offensive expertise required, at a fraction of the cost and wait of a traditional engagement.

Mapping authentication surface across 14 subdomains…
MethodologyOWASP · CVSS
HostedUK · Sovereign
ModeSafe by default
SSRF · /api/renderStored XSSIDOR · /v2/invoicesSQLi · blindJWT · alg=noneTenant rewrite
Engagement live · 27 findings
Core Capabilities

Built around the work, not the dashboard.

Braintruder behaves like a member of your security team - methodical, transparent, and accountable for what it does.

Thinks like an attackerIt chains context across your whole target and hunts real attack paths - not a checklist of signatures matched one at a time.
Safe by defaultGuardrails are on from the first command. Anything higher-impact pauses for your explicit sign-off - nothing runs behind your back.
Proof, not guessworkEvery command, request, response, and result is recorded, so each finding arrives with the evidence that backs it.
Speaks complianceFindings are weighed against your own policies and the standards you're assessed on - real gaps, not theatre.
Beyond Scanning

A scanner flags. Braintruder investigates.

Vulnerability scanners match signatures and hand you a list. They can't tell you which of those findings an attacker could actually reach, chain, or exploit - and a clean scan only means nothing matched, not that you're safe. Braintruder starts where a scanner stops.

LAYER 01

Deterministic baseline

An optional scripted sweep - the same tools and coverage a careful pentester runs first, repeatable on every run. Run it on its own, or let it seed a full AI pentest with a ready-made picture of the target.

LAYER 02

AI investigation

Braintruder treats those results as leads, not conclusions. It forms hypotheses, corroborates each one against real evidence, stays inside your scope, and discards what doesn't hold up - the judgement a scanner has no way to apply.

LAYER 03

Proven, not padded

Confirmed findings ship with the command that proved them. CVE mentions are validated against NVD and OSV, and anything unverified is labelled as such. We would rather report the truth than inflate the count.

Our baseline scanner is the floor, not the ceiling.The scripted scan gives you consistent, repeatable coverage - optional, never mandatory. Schedule it to sweep your estate on a cadence, spotting drift and flagging what changed since last time; when something looks off, escalate straight to a full AI pentest with one click - no waiting for the next annual test. And when the baseline does feed a pentest, the AI re-validates its findings rather than parroting them and goes hunting for what signatures miss, in a single report that also tells you what was not tested.
See It Run

Watch a real methodology, not a marketing reel.

Braintruder narrates its work as it goes. You see the hypothesis, the probe, the evidence, and the next decision - the same way a thoughtful operator would walk you through it.

  • Transparent reasoningEvery step is logged with intent, target, and outcome.
  • Approval gatesHigher-impact actions pause for an operator to confirm.
  • Replayable evidenceFindings ship with the artefacts that proved them.

Capabilities shown are illustrative. Braintruder is evolving rapidly - get in touch for the current scope of supported methodologies and integrations.

braintruder@kali · engagement-acme-2026-04
└─$
A Glimpse of the Product

Designed for IT teams. Built for operators.

A workspace that makes a complex methodology feel obvious. Findings, evidence, and remediation in one place.

app.braintruder.io · engagement / acme-2026-04● live
Engagement
External · acme.io
OWASP-WSTGISO 27001
Critical
2
High
5
Medium
11
  • CRTCross-tenant access via X-Tenant-ID rewriteCVSS 9.1
  • CRTUnauthenticated SSRF on /api/renderCVSS 8.6
  • HGHStored XSS via display-name fieldCVSS 7.4
  • HGHIDOR on /v2/invoices/{id}CVSS 7.1
  • MEDJWT signed with HS256 + weak secretCVSS 5.9
Run Timeline14:02 UTC
  • 14:02Recon - discovered 14 subdomains across 3 providers.
  • 14:07Mapping - auth model: JWT (HS256). Flagged for review.
  • 14:11Hypothesis - tenant boundary may be header-controlled.
  • 14:14Validated - cross-tenant access reproduced (3 captures).
  • 14:16Approval - operator gated next step. Awaiting confirmation.
  • 14:24Drafting - reproduction steps and remediation guidance.
Operator approval requiredHigher-impact action queued: privilege-escalation chain test. Approve to proceed.
Compliance & Policy

Graded against the standards you're measured on.

Once the pentest is done, you answer a short structured questionnaire about your policies and controls. Braintruder's policy-comparison stage then weighs the technical findings against what you've said you already do - so nothing is judged in a vacuum. The result grades the whole picture: where reality matches policy, and where it doesn't.

  • Policy-aware findingsTechnical results are weighed against the controls you told us you run - surfacing the gap between what's written down and what's actually true.
  • Framework-taggedEach finding carries its Cyber Essentials / ISO 27001 / CIS relevance, so the report already speaks your assessor's language.
  • The full pictureNot just “is this exploitable”, but “does your posture hold up against the standard you're claiming”.
Report · Compliance alignmentacme.io
Frameworks mapped
Cyber EssentialsCyber Essentials PlusISO 27001:2022CVSS v3.1 / v4.0
Findings vs. your stated controls
  • A.9.4.1 · Access restrictionGap found
  • CE · Secure configurationAligned
  • A.12.6.1 · Vulnerability mgmtPartial
  • CE · User access controlAligned
One report, two lenses.The same evidence-backed findings, cross-referenced to the frameworks your buyers and auditors care about.
FAQ

Questions, answered.

How is Braintruder different from a vulnerability scanner?

A scanner matches signatures and hands you a list - it can't tell you which findings an attacker could actually reach or exploit, and a clean scan only means nothing matched. Braintruder investigates: it forms hypotheses, corroborates each one against real evidence, discards what doesn't hold up, and reports only what it can prove.

Does Braintruder include its own vulnerability scanner?

Yes. It has an optional deterministic baseline scanner that runs the same tools a careful pentester would run first. You can run it standalone, let it seed a full AI pentest, or schedule it to sweep your estate on a cadence with drift detection and one-click escalation to a full engagement.

Which compliance frameworks does Braintruder support?

Findings are graded against Cyber Essentials, Cyber Essentials Plus, and ISO 27001:2022, with severity scored on CVSS and engagements following OWASP WSTG methodology.

Do I need penetration-testing expertise to use it?

No. Braintruder is built for IT teams and operators without specialist offensive expertise - you configure the target, run the engagement, and read a clear, prioritised report.

Is it safe to run against real systems?

Guardrails are on from the first command and any higher-impact action pauses for your explicit sign-off, so nothing runs behind your back.

How does the compliance grading work?

After the pentest, a short structured questionnaire captures your policies and controls. The policy-comparison stage then weighs the technical findings against what you've said you already do - grading the full picture, where reality matches policy and where it doesn't.

Moving fast, shipping often.New methodology coverage, integrations, and reporting depth land on a regular cadence - often shaped by the teams already using Braintruder. Book a walkthrough to see what it does today and where it's headed.
Get In Touch

Ready to understand your real security risk?

Book a working session with our team. We'll walk through your environment, scope an engagement, and show you what evidence-backed assurance looks like.