⬡
Pistos Security
Features Tools Compliance
Authorized Security Assessment Platform

Enterprise-Grade
Web Security
Assessment

Automate reconnaissance, detect vulnerabilities, and deliver compliance-ready reports — powered by 12 native Kali Linux tools.

See Features
12Kali Tools
3Scan Profiles
5Report Formats
100%Audit Trailed
Features

Everything you need for a thorough assessment

⟳

Automated Reconnaissance

Orchestrates Nmap, Subfinder, Amass, DNSRecon and HTTPX across Quick, Standard, and Deep profiles.

  • Port & service enumeration
  • Subdomain discovery
  • DNS zone analysis
  • HTTP fingerprinting
◈

Vulnerability Detection

Combines Nikto, Nuclei, and OWASP ZAP to surface CVEs, misconfigurations, and OWASP Top-10 flaws.

  • CVE & template-based scanning
  • OWASP Top-10 coverage
  • WAF detection via Wafw00f
  • TLS/SSL audit via SSLyze
◎

Content Discovery

Gobuster brute-forces directories while WhatWeb fingerprints technologies and CMS platforms.

  • Directory & endpoint brute-force
  • Technology fingerprinting
  • Hidden path discovery
  • Configurable wordlists
⬡

Compliance & Authorization

Built-in authorization workflow with acknowledgment-gated scans and an immutable audit trail.

  • Acknowledgment-gated scans
  • Immutable audit log
  • Compliance disclaimers
  • Role-based access control
◇

Report Generation

Executive and technical reports in multiple formats with AI-generated remediation per finding.

  • PDF, HTML, DOCX, JSON, CSV
  • Executive & technical templates
  • AI remediation suggestions
  • Scan comparison reports
⚡

Scalable Infrastructure

PostgreSQL-backed storage with batch scanning, concurrency control, and background worker queues.

  • Concurrent scan control
  • Batch target processing
  • Persistent findings database
  • Worker health monitoring
Tooling

Powered by industry-standard Kali Linux tools

■NmapPort & service scan
■NiktoWeb server scan
■NucleiTemplate-based CVEs
■WhatWebTech fingerprint
■GobusterDir brute-force
■Wafw00fWAF detection
■SSLyzeTLS/SSL audit
■SubfinderSubdomain enum
■AmassAttack surface map
■HTTPXHTTP probing
■DNSReconDNS enumeration
■OWASP ZAPActive web scanner
Compliance

Built for authorized, auditable assessments

▮

Authorization Gating

Every scan requires an explicit written acknowledgment before execution. No scan runs without documented consent.

▮

Immutable Audit Trail

Every action, finding, and report is timestamped and stored. Full chain-of-custody for every assessment.

▮

Role-Based Access

Separate analyst and admin roles with scoped permissions. Admin approval required for new account registration.

Authorized Use Only. Explicit written permission is required before scanning any target. Unauthorized use is strictly prohibited and may violate local laws.

Ready to start your assessment?

Sign in to access the full platform — targets, scans, reports, and more.

⬡ Pistos Security © 2025 — Authorized use only

Security Dashboard