Skip to content
BreachPilot

Capabilities

Full assessment lifecycle, under supervision

Recon, target-locked execution, adaptive intelligence, and evidence-backed reporting — for authorized testing only. Capability overview, not a how-to.

  1. ReconnaissanceDiscover
  2. ExecutionChain
  3. IntelligenceLearn
  4. ReportingProve

Authorized testing only — only test systems you own or have explicit written permission to assess.

Reconnaissance

See the whole surface first

Parallel discovery against allowlisted targets — cached per run, enriched with vuln intel.

Parallel discovery

Concurrent TCP + service/OS fingerprint, cached per run.

quick_scan · run_full_recon

Nmap workflows

Sweep → triage → service → vuln, with priv_fallback.

pre-flight reachability probes

Depth enumerators

UDP top-ports, SNMP, WAF, vhost, cloud-metadata.

dns_recon · vhost_enum · AXFR

Intel enrichment

NVD + EPSS + CISA KEV + OSV + GHSA, rate-limited.

circuit-breaker research tools

Execution

Capability-aware, target-locked

Modules, payloads, and bridges compose into chains against explicitly authorized targets.

15 module families

Web, auth, JWT, SMB, privesc, AD, ICS/IoT, supply-chain.

run_attack_module · 0–100 scoring

Prerequisite chaining

Modules declare requires/produces; planner composes.

find_producers · phase hints

Payloads + bridges

Crafter/mutator, Metasploit lifecycle, web scanners.

msfvenom · nuclei · sqlmap

Post-exploitation, in scope

Encrypted vault, Impacket lateral, Kerberoast, cracking.

hashcat/john · BloodHound CE

Guardrail: lab targets (RFC1918/loopback) run relaxed; public targets get pacing, jitter, and noise accounting — advisory only, the operator always sees the advice. Every action stays target-locked to explicitly authorized scope. Safety model

Intelligence

Sharper across missions

Skills, memory and telemetry turn each run into training data — advisory only, never a bypass.

Advisory skill pick

Deterministic tags + lexical + Bayesian feedback.

top skills per context

Campaign memory

SemanticMemory + ExperienceStore, per-attempt compaction.

lessons survive runs

Telemetry + peer consult

Tokens/context per call; advisory second opinions.

consult_peer_models · gated

Reporting

Evidence-backed, export-ready

  • Findings with timeline, CVSS, chain, and linked evidence
  • Markdown + HTML reports with decision log and audit chain
  • MITRE ATT&CK Navigator export + ticket creation
  • Oracle-verified outcomes — verified ≠ claimed

See how outcomes are verified →