ClarityASM · PenTestGPT
Sign in
Authorized ClarityASM operators only.
Hints are queued and picked up by the worker on its next poll (~2s).
Launch Control
High-Ready Dispatch
Launch Wizard
Create Run
At A Glance
Launch Checklist
Live
Active Jobs 0
Active engagement
No engagement selected
Pick a run from the Runs tab to enter Mission Control.
Live
Activity
Confirmed
Findings
Hints are queued and picked up by the worker on its next poll (~2s). Best for nudging the agent toward an obvious path or steering away from a dead end.
Live
Active Engagements 0
Engagements running right now. Click any card to drill into the live activity feed.
Documentation
Job History
Per-job summary with downloadable evidence. Switch to By Execution to see each worker attempt (children of aggregate runs counted separately).
Templates
Prompt Library
Tune built-in prompts, create custom variants, and keep saved overrides in the portal so launch templates stay editable without touching source files.
Editor
Template Editor
Prompt Template
Child Overlay
Structured Operator Inputs
Runtime Policy
Comparison
Diff Vs Built-In Baseline
Operator Flow
Follow the playbook in three moves
Use the library as a guided sequence: choose the workflow, inspect the exact logic, then preserve findings that should survive the run.
Browse
Filter by OWASP, phase, or template until the operator sees the right workflow for the run.
Inspect
Read the goal, preconditions, steps, payloads, and evidence contract as one readable sequence.
Retain
Save reusable endpoints, notes, and branch clues so the next operator starts with context instead of rediscovery.
Step 1
Browse Curated Workflow Library
Start with the runbook list. Filter to the OWASP area or phase you need, then pick one workflow to inspect in full.
Step 2
Choose a playbook
Step 3
Promote Findings Into Passive DB
Retained findings now live in the Passive DB workspace. Group URLs by root domain, expand the domain row, and keep the editor focused on the specific result you want to preserve.
Passive DB
Retained Findings By Root Domain
Review the retained URL inventory as a passive database. Each domain row expands into the URLs, notes, and captured results currently attached to that surface.
Editor
Retained Finding
Artifacts
Attach CSV Or TXT Evidence
Inventory
Assets
Add Asset
Free tier · no Enterprise key required
Burp Suite Workbench
Craft and replay HTTP requests, sweep payloads, review findings, and export Burp-ready config — all in-portal. For full DAST scanning, add an Enterprise key (Enterprise DAST tab).
No response yet. Edit the request and hit Send.
Insert the marker §PAYLOAD§ anywhere in the request below. Each payload (one per line) is substituted in turn and fired; results are tabulated so anomalies stand out.
Generate config you can import into your own Burp Suite (Pro or Community) via Settings → Restore options from file. Seeded from the target below.
Enter a target and choose an export above.
Enterprise DAST
Burp Suite Enterprise ENTERPRISE
Orchestrate Burp Suite Enterprise scans and manage every API-controllable setting — scan profiles, scope, scheduling, and scanning agents — without leaving the portal.
Enterprise features locked
Add and validate a Burp Suite Enterprise API key to unlock orchestrated DAST scans, scan-configuration management, scope control, scheduling, and agent monitoring.
Recent Scans
Scan Configurations
Built-in and custom audit/crawl profiles available to this instance. Select profiles here, then launch from Scope & Sites.
Scope & Sites
The site tree defines scan scope. Launch an on-demand scan against any site using the selected scan configurations.
Scheduled Scans
One-off and recurring scans registered on this instance.
Scanning Agents
Registered scanning machines and their current load — capacity before launching scans.
Scan Reports
Generate an HTML report for any completed scan.
Per-Attempt Log
Job History
Worker execution history — each child run of an aggregate counts as its own row. Switch to By Job for parent-job summaries with downloadable evidence.
Infrastructure
Workers, Relays, And Control Plane
Command Snapshot
Active routing, ready regions, and operator-side reach at a glance.
Azure Worker Control
Deploy, activate, or retire a region without leaving the page.
Recent Executions
Worker Fleet
Loading regions...
Every supported Azure region stays visible here, including standby capacity that can be deployed on demand.
LAN Workers
Loading LAN workers...
Checked-in operator machines that can route Azure runs through a workstation-local proxy.
Azure Identity
Service principal and subscription used for ARM API calls.
Worker Configuration
Container Apps Job, Service Bus, and region defaults.
Platform Surface
Portal endpoints and public hostname.
Local LLM Gateway
ASUS NUC model-queue-manager endpoints and model routing.
Anthropic Provider
API key, balance, and rate-limit status.
Operations
User Management
Super-users can create portal users, grant admin access, and remove managed accounts.
Settings
Preferences
Defaults applied to every new engagement. Per-engagement overrides remain available in the New Engagement form.
Preferences are stored in this browser only.
Integrations · Admin
Burp Suite Enterprise
When configured, every hybrid engagement (Bundle 20) triggers a Burp Suite Enterprise DAST scan alongside the LLM worker. When unset, PenTestGPT falls back to the free Burp Suite Workbench (Bundle 18) — operators paste raw HTTP requests into their own Burp Pro / Community Edition for manual replay.
Integrations
API Keys
Scoped keys (scans:run) for the external Integration API
(POST /api/integrations/v1/scans). Hand one to an internal tool
(e.g. a Kali/Flask asset dashboard) instead of the admin token. Pair it with a
relay's agent_id to scan internal targets. The secret is shown
once at creation — copy it immediately.
Copy now — this secret will not be shown again.
| Name | Prefix | Scopes | Created | Last used | Status | Actions |
|---|