Automated pentesting · Continuous offensive

Test your defences
like an attacker.

Delivered as a VM deployed on your LAN — like the HoneyPot. Internal pentesting in continuous active discovery, every weakness verified by the AI. Seven modules: network, host, web, Active Directory, API, IoT/OT, cloud — driven remotely by your SOC.

Proxmox / VMware7 modules de scanAI verificationSOC control
7
modules offensifs
13 061
signed Nuclei templates
24/7
pentest en continu

An annual pentest was enough ten years ago. Today the estate changes daily: a new service, a new VLAN, a new firewall opening, a new CVE. Automated pentesting scans continuously from the inside, checks every finding with the AI (priority, exploitability, MITRE mapping, recommended actions) and reports to the SOC. Not a static checklist — an agent that learns and acts.

How it works

From threat to evidence, in real time.

The module captures the signal, SYLink AI correlates it and decides — you keep control.

Your estate
Network, AD, web, cloud
Automated pentesting
7 modules offensifs
SYLink AI
Checks exploitability
Prioritised findings
Fix what matters
Capabilities

The technology, in detail.

What the module actually does — functions, not promises.

Network discovery

  • nmap top 1000 then full TCP
  • 200+ services identified (banner + nuclei)
  • Automatic mapping of RFC1918 subnets
  • Static routes to scan remote VLANs
  • Discovery / audit / full modes

Active Directory

  • Kerberoast (service account TGS)
  • AS-REP roasting (accounts without pre-auth)
  • Controlled password spray (lockout policy respected)
  • BloodHound collection (attack paths)
  • ADCS misconfig + NTLM relay (SMB → LDAPS)

Web · API · IoT · Cloud

  • Web: nuclei (13,000+ templates) + nikto
  • API: REST / GraphQL fuzz, auth bypass, IDOR
  • IoT/OT: CoAP, MQTT, Modbus, S7, IEC-104, BACnet
  • Cloud: S3 misconfig, Azure SAS leak, GCP IAM
  • TLS: Heartbleed, DROWN, ROBOT, weak ciphers

Verified by SYLink AI

  • A structured JSON verdict for every finding
  • is_exploitable + priority_score + confidence
  • MITRE techniques (T1190 / T1059 / T1110…)
  • Concrete actions (patch / isolate / IDS rule)
  • False-positive probability — up to 80% less noise

CVE / KEV / Nuclei sync

  • Daily CVE pack (1,500+ with CVSS ≥ 7 over five years)
  • CISA KEV pack (1,562 actively exploited vulnerabilities)
  • Nuclei pack (13,061 UniSOC-signed templates)
  • Wordlists (top 1k/10k/100k plus AD-specific)
  • IoC blocklist excluded from the scan

Security & licensing

  • QR activation (HMAC-signed token)
  • Services enabled per tenant (network / AD / web…)
  • One month to three years, plus immediate revocation
  • Emergency kill switch on the SOC side
  • RFC1918 routes only (no hijacking of the default route)
Use cases

What is it actually for?

Find a critical CVE within 24 hours

A critical CVE lands on Exchange: automated pentesting pulls the day's pack, finds the affected servers, has the AI check exploitability → a SOC ticket at 95% priority within two hours.

Continuous AD auditing

A quarterly AD audit? Too late. Automated pentesting runs kerberoast, AS-REP and a controlled spray every week and raises an alert the moment a new vulnerable account appears.

Multi-site scope through routing

Three sites linked by VPN: one VM plus two static routes are enough to scan Paris, Lyon and Marseille from a single point.

Validate before the audit

Ahead of the NIS2 audit, the CISO launches a full scan. An executive report with three priority actions — ready for the management committee.

The method, in four steps
From raw signal to defensible evidence.
Detect
Understand
Decide
Prove
01The module captures the raw signal — traffic, behaviour or indicator.signal captured
Specifications
HypervisorProxmox VE 7+ / VMware ESXi 6.7+ / Hyper-V
Resources4 vCPU / 8 GB RAM / 100 GB disk
VM operating systemUbuntu Server 24.04 LTS
ModulesNetwork, Host, Web, AD, API, IoT, OT, Cloud
Delivery.ova / .qcow2 / .iso
ActivationQR from the console and the client portal
ControlHMAC-signed commands (polled every 60 s)
DeploymentOn-premise · inside your own infrastructure
Natively integrated with
SYLink AI — verification and executive summary
DPI sensor — scope taken from the real map
EDR agent — prioritised by asset criticality
HoneyPot — findings also exercise the decoys
Compliance module — NIS2 / DORA / ISO 27001
Sovereign

Driven by SYLink AI, hosted 100% in France (HDS v2), with no Cloud Act exposure. Every decision is logged and defensible under NIS2 and DORA.

Live in under 48 hours

Ready to see what is really
happening on your network?

First trial free, no credit card, no commitment. On your existing infrastructure.

Cookie settings

We use cookies to improve your experience on our site. By continuing to browse, you accept our privacy policy and our use of cookies under the GDPR.