Overview
Pentest Copilot Enterprise documentation.
Pentest Copilot Enterprise helps security teams scope, run, and review external, internal, cloud, and code assessments from one control plane. It combines agent-based execution, browser automation, attack-path analysis, validated findings, scheduling, reporting, and API/MCP automation.
Assessment Types
External
Internet-facing domains, pages, APIs, services, authenticated flows, and vulnerability testing.
Approved domains, intent, authentication coverage, rate limits, and attack vectors.
Internal
Reachable networks, hosts, services, identities, trust relationships, and approved exploit validation.
A connected agent, subnet scope, intent, exploit families, and safety controls.
Cloud
AWS, Azure, and Google Cloud inventory and approved active validation through an attached workload identity.
A cloud-hosted agent, provider permissions, discovered scope, test categories, and rollback choices.
Code
Source-code risks, dependencies, secrets, authorization and business logic, SBOM, and AI-BOM.
GitHub App access, repositories, branches/PRs/commits, checks, and automation rules.
Run Assessment
External and internal work starts from Modules -> [assessment type] -> Run Assessment. Choose one intent:
Discovery maps the selected environment without active vulnerability testing.
Assessment tests inventory that has already been discovered.
Discovery + Assessment refreshes inventory and then assesses what was found.
The wizard then guides you through Scope, Scan settings, Automation, and Review. Code Assessment uses the same flow without an Intent step.

Main Navigation
Dashboard
Deployment readiness, mission status, agents, target entities, and the exploit graph.
Modules
Configure runs and review Statistics, Attack Paths, and code inventories.
Activity
Monitor runs, inspect logs, cancel work, and manage schedules.
Reports
Generate executive and comprehensive reports.
Settings
Manage scope, verification, agents, integrations, API keys, users, and tenant defaults.
Recommended First Run
Confirm your role has the required scan and settings permissions.
Add approved external domains or connect the internal/cloud agent that can reach the intended scope.
Verify external domain ownership when required.
For authenticated external testing, record and validate one browser session per user role.
Open the applicable Run Assessment page and start with Discovery or Discovery + Assessment.
Keep the first scope narrow and use conservative rate limits or exploit selections.
Confirm the complete configuration on Review, then choose Start run or Schedule run.
Monitor the run under Activity, triage findings under Attack Paths, and generate reports when the assessment is complete.
Pentest Copilot applies the same launch policy to UI, API, and MCP requests. Permissions, feature access, usage limits, scope controls, verification, and worker availability cannot be bypassed by changing the launch method.
See Scan Noise and Safety before testing production or stateful environments.
For onboarding or engagement-specific questions, contact queries@bugbase.ai.
Last updated