---
title: "Retest Commands"
description: "Verify fixes automatically: every repeat TurboPentest re-checks each previous finding against fresh evidence and records a fixed-or-unresolved verdict."
canonical: https://turbopentest.com/docs/pentesting/retest-commands
source: "TurboPentest Docs"
---

# Retest Commands

Retest validation is a **live fresh-oracle pass that runs inside Phase 2** of every repeat pentest. When you run a new pentest against a target that has been pentested before, Paladin re-evaluates each previous finding against fresh evidence and the retest oracle records a per-finding verdict of **still_present**, **fixed**, or **unsure**. These map to **confirmed**, **not_confirmed**, and **unsure** respectively. Findings then carry a continuity status: **new**, **confirmed**, or **retest_confirmed**.

## How it works

1. Fix the vulnerability in your code
2. Deploy the fix
3. Run a new pentest against the same target (use the repentest button on the pentest detail page, or the API)
4. Each previous finding is re-checked live: issues that no longer reproduce come back as `fixed` (not_confirmed), while issues that still reproduce are re-verified as `confirmed`

The verdicts appear on the pentest detail page and in the PDF/JSON reports as verification evidence for each finding. Screenshots that a Phase 1 tool captured in the prior scan are carried forward and hard-captioned "prior pentest"; findings that are re-exploited during the retest get fresh screenshots.

## Manual spot checks

If you want to re-run a specific check yourself before spending a credit, you can reproduce it with Docker using the underlying scanner images. For example, for a Vuln Scanner finding about an exposed `.env` file:

```bash title="Terminal"
docker run --rm projectdiscovery/nuclei:latest \
  -t http/exposures/configs/env-file.yaml \
  -u https://example.com
```

If the output shows no findings, the `.env` file is no longer exposed.

### Port Scanner (open ports)
```bash title="Terminal"
docker run --rm projectdiscovery/naabu:latest \
  -host example.com -p 3306
```

### Web Scanner (web vulnerabilities)
```bash title="Terminal"
docker run --rm ghcr.io/zaproxy/zaproxy:stable \
  zap-full-scan.py -t https://example.com -m 5
```

### TLS Analyzer (TLS issues)
```bash title="Terminal"
docker run --rm drwetter/testssl.sh:3.2 \
  --quiet https://example.com
```

### Secret Scanner (secrets in code)
```bash title="Terminal"
docker run --rm -v /path/to/repo:/repo ghcr.io/gitleaks/gitleaks:latest \
  detect --source /repo
```

## Tips

- Manual spot checks use the same upstream Docker images as the full pentest
- No TurboPentest account or credit is needed for manual spot checks
- Only a full pentest updates finding continuity statuses and report evidence
