Changelog

These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!

Date

July 2025

  1. Choose API Scanner modes for better control

    Copy link to “Choose API Scanner modes for better control”

    Need fast, flexible API scans or do you want to do a full-fledged integration test?

    The API Vulnerability Scanner now supports all our scanning depths:

    🎯 Light for fast results

    🎯 Deep for full-coverage scans

    🎯 Custom lets you select scan depth and choose between REST or GraphQL APIs.

    🌟 Bonus: The API spec file is now optional — so you can start testing even if documentation is incomplete.

  2. The Network Scanner now flags several types of DNSSEC (Domain Name System Security Extensions) misconfigurations that are often overlooked, but impactful:

    ✅ Large DNSSEC responses (amplification risks)

    ✅ Weak cryptographic algorithms

    ✅ Missing or insecure DNS cookies

    ✅ Improper or missing EDNS usage

    Ideal for:
    🎯
    Security consultants doing external infrastructure reviews
    🎯 Internal security teams hardening critical DNS services

  3. Download scan group results directly from Reports

    Copy link to “Download scan group results directly from Reports”

    Running large test sets using grouped scans? Now, when all scans in a group finish, the aggregated results are available right in your Reports section - not just by email.

    This update makes life easier for consultants managing multiple clients and teams tracking internal remediation workflows.

  4. Get more proof of exploitation with Sniper

    Copy link to “Get more proof of exploitation with Sniper”

    Sniper: Auto-Exploiter, our proprietary offensive solution, now gives you proof of exploitation for two new RCEs - helping you confirm impact with just a few clicks:

    • CVE-2025-47577 (CVSSv3 10.0) – a dangerous RCE in WordPress TemplateInvaders TI WooCommerce Wishlist allowing for Upload a Web Shell to a server

    • CVE-2025-4427 (CVSSv3 5.3) – a medium RCE in Ivanti Endpoint Manager Mobile allowing attackers to access protected resources without proper credentials.

    Use Sniper to demonstrate real-world risk, complete with payloads and proof.

    Don’t forget: if Sniper can exploit it, our Network Scanner can detect it.

  5. The Website Scanner’s spidering process now uses Locality Sensitive Hashing (LSH) to compare similar pages more efficiently.

    What this means for you:

    ✅ Cover more ground in less time and surface hidden endpoints quickly

    ✅ Improve test coverage on apps with repetitive structures or dynamic content

    You may see more URLs discovered in your scans - slightly longer scan time, but way better visibility!

    We’re constantly optimizing our proprietary Website Scanner for better scan performance.

June 2025

  1. Filter scan results by time with the API integration

    Copy link to “Filter scan results by time with the API integration”

    Working with /api/v2/scans?

    You can now filter by start_time to get only the results you need at one point.

    Bonus: scan results are now sorted by most recent first by default, helping you spot what’s relevant without digging.

  2. Cut through the noise with ML-powered false positive filtering

    Copy link to “Cut through the noise with ML-powered false positive filtering”

    False positives don’t just waste time - they erode trust, delay remediation, and bury real issues under a pile of noise.

    That’s why we’ve built and integrated the Machine Learning classifier - a purpose-trained machine learning model - directly into our Website Scanner and URL Fuzzer.

    Instead of relying on brittle RegEx logic, the ML Classifier analyzes every HTML response during a scan and automatically sorts it into one of four smart categories:

    📌 HIT – High-value targets like login pages, exposed secrets, and backups

    📌 MISS – Confirmed dead ends, even when status codes are misleading

    📌 PARTIAL HIT – Ambiguous but interesting results (like firewall pages or redirects)

    📌 INCONCLUSIVE – Requires browser-based rendering for confirmation

    This means you can quickly focus on what matters, reduce triage time, and get clearer, cleaner results.

  3. NEW: Pentest-Tools.com x Nucleus Security for smoother findings management

    Copy link to “NEW: Pentest-Tools.com x Nucleus Security for smoother findings management”

    You can now push vulnerability scan results from Pentest-Tools.com into your Nucleus workspace. Choose to automate based on conditions, or manually send only the Findings you need. No more custom scripts. No more manual data wrangling. One single source of truth for smoother findings management.

    ▶️ Watch this demo with our product manager, Dragos and:

    New in Pentest-Tools.com: Nucleus Security integration

    ✅ Control what gets sent and where
    ✅ Keep client data cleanly separated
    ✅ Centralize your vuln management in Nucleus

  4. Get more context with enriched JSON reports

    Copy link to “Get more context with enriched JSON reports”

    Every JSON report you generate from Pentest-Tools.com now includes scan metadata - including the target, scan type, and timing details.

    Perfect for consultants automating reporting workflows or teams feeding results into SIEMs, dashboards, or custom pipelines.

  5. Prioritize smarter with EPSS & CISA KEV

    Copy link to “Prioritize smarter with EPSS & CISA KEV”

    We’ve added EPSS scores & percentiles, and CISA KEV flags for the Network Scanner’s findings so you identify what’s critical, faster:

    • EPSS (Exploit Prediction Scoring System) helps you estimate the real-world likelihood of exploitation

    • CISA KEV (Known Exploited Vulnerabilities) flags confirmed threats

    You’ll now see this data in the classification section of each network scan finding.

    Whether you’re triaging results internally or reporting to clients, this adds vital context for a more accurate prioritization.

    Complement it with our case against single-metric risk models.

May 2025

  1. Deeper findings with Website Scanner upgrades

    Copy link to “Deeper findings with Website Scanner upgrades”

    We’ve made several key improvements to our proprietary Website Scanner to help you uncover more vulnerabilities - with greater precision:

    ✅ Light scans now include all passive detections so you get richer results with a quick scan
    ✅ GraphQL endpoint fuzzing now included to automatically identify GraphQL endpoints and test them as injection points
    ✅ Response Header Injection detection is still live in the active module since last month, but too useful not to mention again!

  2. Sniper: Auto-Exploiter, our proprietary offensive solution, now validates exploitability for CVE-2024-56145 (CVSSv3 9.8), a critical Remote Code Execution vulnerability in Craft CMS.

    Just like the rest of our exploit modules, this lets you:

    • Get proof of exploitation within minutes and skip manual PoC building

    • Strengthen your reports with screenshots and payload evidence

    As always, if Sniper can exploit it, our Network Scanner can detect it.

  3. Time matters - especially when a new critical CVE is looming over your infrastructures!

    That’s why the Network Vulnerability Scanner now automatically optimizes the engine selection when you scan for a specific CVE.

    This means:

    • We only enable the engines that can detect the targeted CVEs

    • Faster scan completion without losing detection depth

    • Quicker results your team can use to coordinate and patch

April 2025

  1. Automate report generation with our new Reports API

    Copy link to “Automate report generation with our new Reports API”

    Generate, download, and view your reports via API — no more account login needed!

    We’ve made this update so you can integrate reporting into your automated workflows at scale:

    • Trigger the reports you need programmatically

    • Save time on repetitive manual tasks

    • Control what gets delivered and where

  2. Get richer findings with the Website Scanner

    Copy link to “Get richer findings with the Website Scanner”

    We’ve upgraded our proprietary Website Scanner to give you better visibility and deeper coverage of your apps:

    • Findings now include port, service, and protocol data

    • The scanner’s Active module now detects Response Header Injection, a commonly missed attack vector in real-world apps

    Whether you're auditing a third-party web app or scanning production assets, these updates give you faster, more precise insights.

  3. Start Pentest Robot scans directly from the New Scan flow

    Copy link to “Start Pentest Robot scans directly from the New Scan flow”

    Pentest Robots make it easier to:

    • Set up repeatable testing flows across clients with predefined or custom Robots

    • Run scheduled assessment sequences on internal assets

    • Deliver consistent, scalable testing with less effort

    You can now launch a Pentest Robot from the New Scan button, thanks to the new dedicated Robots tab — making your workflows even faster.