---
title: "Tool Overview"
description: "All 14 TurboPentest security tools at a glance - 11 black-box scanners plus white-box source tools, each running in its own isolated container."
canonical: https://turbopentest.com/docs/tools/overview
source: "TurboPentest Docs"
---

# Tool Overview

TurboPentest runs up to 14 security tools during each pentest. Each tool runs in its own isolated container with dedicated resources.

## Black box tools (11)

These run on every pentest - no source code access needed.

| | Tool | Category | Purpose | Resources |
|--|------|----------|---------|-----------|
| 🌐 | **Port Scanner** | Network | Fast port discovery, open-port and host enumeration | 1 CPU, 1 GB |
| 🕸️ | **Web Scanner** | Web app | Comprehensive web app vulnerability testing | 1 CPU, 3 GB |
| 🎯 | **Vuln Scanner** | Web app | Template-based vulnerability detection for known CVEs | 1 CPU, 2 GB |
| 🔍 | **Server Audit** | Web app | Web server misconfiguration and dangerous file detection | 0.5 CPU, 1 GB |
| 📂 | **Enumerator** | Web app | Directory and file brute-forcing | 0.5 CPU, 1 GB |
| 🛡️ | **Net Scanner** | Vulnerability | Full network vulnerability assessment | 2 CPU, 12 GB |
| 🔒 | **TLS Analyzer** | SSL/TLS | TLS certificate and cipher analysis | 0.5 CPU, 2 GB |
| 📡 | **Sub Hunter** | Recon | Passive subdomain enumeration | 0.25 CPU, 0.5 GB |
| 🔌 | **Web Probe** | Recon | HTTP response probing and technology detection | 0.25 CPU, 0.5 GB |
| 🧱 | **WAF Detect** | Recon | Web Application Firewall detection | 0.25 CPU, 0.5 GB |
| 🔧 | **Security Checks** | Multi | Additional vulnerability testing | 0.5 CPU, 1 GB |

## White box tools (3)

These require a GitHub connection and run in addition to all black box tools.

| | Tool | Category | Purpose | Resources |
|--|------|----------|---------|-----------|
| 📝 | **Code Scanner** | SAST | Static analysis for code-level vulnerabilities | 1 CPU, 2 GB |
| 📦 | **Dep Scanner** | SCA | Dependency vulnerability detection | 1 CPU, 1 GB |
| 🔑 | **Secret Scanner** | Secrets | Detect hardcoded secrets in source code | 0.25 CPU, 0.5 GB |

## Paladin AI

In addition to the 14 Phase 1 tools above, Paladin is TurboPentest's autonomous agentic pentester. It is not one of the Phase 1 tools - it is the Phase 2 orchestrator that conducts the actual penetration test on top of their output, generates unified findings, and produces the executive summary and threat model. See [Paladin AI](/docs/tools/paladin) for details.

## Execution model

- Tools run as isolated containers on Azure Container Instances, in two waves: recon and non-web tools (Port Scanner, Sub Hunter, Secret Scanner, Code Scanner, Dep Scanner, Net Scanner) launch first, then the web tools launch against the web targets Port Scanner discovers
- Each tool has its own timeout - there is no single universal limit. They range from about 2 minutes (WAF Detect) up to about 160 minutes (Net Scanner)
- Tools report results via callbacks as they complete
- A pentest is complete once all tools have finished and the Phase 2 AI analysis is done
