Retest Commands
Retest validation is a live fresh-oracle pass that runs inside Phase 2 of every repeat pentest. When you run a new pentest against a target that has been pentested before, Paladin re-evaluates each previous finding against fresh evidence and the retest oracle records a per-finding verdict of still_present, fixed, or unsure. These map to confirmed, not_confirmed, and unsure respectively. Findings then carry a continuity status: new, confirmed, or retest_confirmed.
How it works
- Fix the vulnerability in your code
- Deploy the fix
- Run a new pentest against the same target (use the repentest button on the pentest detail page, or the API)
- Each previous finding is re-checked live: issues that no longer reproduce come back as
fixed(not_confirmed), while issues that still reproduce are re-verified asconfirmed
The verdicts appear on the pentest detail page and in the PDF/JSON reports as verification evidence for each finding. Screenshots that a Phase 1 tool captured in the prior scan are carried forward and hard-captioned "prior pentest"; findings that are re-exploited during the retest get fresh screenshots.
Manual spot checks
If you want to re-run a specific check yourself before spending a credit, you can reproduce it with Docker using the underlying scanner images. For example, for a Vuln Scanner finding about an exposed .env file:
docker run --rm projectdiscovery/nuclei:latest \
-t http/exposures/configs/env-file.yaml \
-u https://example.comIf the output shows no findings, the .env file is no longer exposed.
Port Scanner (open ports)
docker run --rm projectdiscovery/naabu:latest \
-host example.com -p 3306Web Scanner (web vulnerabilities)
docker run --rm ghcr.io/zaproxy/zaproxy:stable \
zap-full-scan.py -t https://example.com -m 5TLS Analyzer (TLS issues)
docker run --rm drwetter/testssl.sh:3.2 \
--quiet https://example.comSecret Scanner (secrets in code)
docker run --rm -v /path/to/repo:/repo ghcr.io/gitleaks/gitleaks:latest \
detect --source /repoTips
- Manual spot checks use the same upstream Docker images as the full pentest
- No TurboPentest account or credit is needed for manual spot checks
- Only a full pentest updates finding continuity statuses and report evidence
Understanding Results
How to read TurboPentest findings - severity, CVSS scores, and evidence - and prioritize which vulnerabilities your team should remediate first.
Reports & Attestation
Every completed TurboPentest generates a PDF report with CVSS-scored findings plus a formal attestation letter you can hand to auditors and customers.