Tool Overview
TurboPentest runs up to 14 security tools during each pentest. Each tool runs in its own isolated container with dedicated resources.
Black box tools (11)
These run on every pentest - no source code access needed.
| Tool | Category | Purpose | Resources | |
|---|---|---|---|---|
| π | Port Scanner | Network | Fast port discovery, open-port and host enumeration | 1 CPU, 1 GB |
| πΈοΈ | Web Scanner | Web app | Comprehensive web app vulnerability testing | 1 CPU, 3 GB |
| π― | Vuln Scanner | Web app | Template-based vulnerability detection for known CVEs | 1 CPU, 2 GB |
| π | Server Audit | Web app | Web server misconfiguration and dangerous file detection | 0.5 CPU, 1 GB |
| π | Enumerator | Web app | Directory and file brute-forcing | 0.5 CPU, 1 GB |
| π‘οΈ | Net Scanner | Vulnerability | Full network vulnerability assessment | 2 CPU, 12 GB |
| π | TLS Analyzer | SSL/TLS | TLS certificate and cipher analysis | 0.5 CPU, 2 GB |
| π‘ | Sub Hunter | Recon | Passive subdomain enumeration | 0.25 CPU, 0.5 GB |
| π | Web Probe | Recon | HTTP response probing and technology detection | 0.25 CPU, 0.5 GB |
| π§± | WAF Detect | Recon | Web Application Firewall detection | 0.25 CPU, 0.5 GB |
| π§ | Security Checks | Multi | Additional vulnerability testing | 0.5 CPU, 1 GB |
White box tools (3)
These require a GitHub connection and run in addition to all black box tools.
| Tool | Category | Purpose | Resources | |
|---|---|---|---|---|
| π | Code Scanner | SAST | Static analysis for code-level vulnerabilities | 1 CPU, 2 GB |
| π¦ | Dep Scanner | SCA | Dependency vulnerability detection | 1 CPU, 1 GB |
| π | Secret Scanner | Secrets | Detect hardcoded secrets in source code | 0.25 CPU, 0.5 GB |
Paladin AI
In addition to the 14 Phase 1 tools above, Paladin is TurboPentest's autonomous agentic pentester. It is not one of the Phase 1 tools - it is the Phase 2 orchestrator that conducts the actual penetration test on top of their output, generates unified findings, and produces the executive summary and threat model. See Paladin AI for details.
Execution model
- Tools run as isolated containers on Azure Container Instances, in two waves: recon and non-web tools (Port Scanner, Sub Hunter, Secret Scanner, Code Scanner, Dep Scanner, Net Scanner) launch first, then the web tools launch against the web targets Port Scanner discovers
- Each tool has its own timeout - there is no single universal limit. They range from about 2 minutes (WAF Detect) up to about 160 minutes (Net Scanner)
- Tools report results via callbacks as they complete
- A pentest is complete once all tools have finished and the Phase 2 AI analysis is done
Cloud EASM & Assets
Discover your external attack surface with authenticated multi-cloud API discovery across 9 providers, track new and removed assets, and launch one-click pentests from verified assets.
OWASP Top 10 Coverage
How TurboPentest's 14 Phase-1 security tools map to the OWASP Top 10 2025, with Paladin (Phase 2) adding an analysis layer that spans every category.