Demo Environment Argos Console preview: This is an interactive demo console. No real security scans are executed on this site. Request Live Pentest Demo →

Argos Console Dashboard

Argos Console

Everything Argos can do from the CLI, in one place — launch, watch, and review autonomous AI pentests.

Running now
0
Total findings
28
Critical
0
Total runs
6
Assets in scope
20
Top issues
Highest-severity findings across recent runs.
HIGH CVE-2024-51466: Critical Expression Language Injection
HIGH CVE-2024-40695: Unrestricted File Upload in Upload Endpoint
MEDIUM Broken Object Level Authorization (IDOR) on User Profile API
MEDIUM User Enumeration via Auth Response Differential Timing
MEDIUM Improper Input Validation on Config Endpoint Causes Exception
Top affected assets
Targets with the most open findings.
app.example-saas.com 4
api.cloud-infra.io 4
auth.enterprise-portal.net 2
billing.example-saas.com 2
demo.argos.sec/login 1
Severity breakdown
Findings on file, by severity.
28 TOTAL
High 2
Medium 20
Low 6
Recent Assessment Runs
Target Status Mode Started Action
https://app.example-saas.com Completed standard Today, 2:13 PM
api.cloud-infra.io/v2 Completed standard Today, 1:53 AM
https://auth.enterprise-portal.net Completed deep Yesterday, 3:46 PM
https://billing.example-saas.com Completed deep Yesterday, 2:55 PM
https://demo.argos.sec Interrupted standard Sep 3, 5:49 PM
https://demo.argos.sec Completed quick Sep 3, 5:47 PM

Launch an Assessment

Configure target URLs, repos, instructions, and launch AI penetration testing agents.

Same targets the CLI's -t/--target accepts. One per line.
Authorization Notice
Demo Notice: This is a public demo console. No live network scans are executed on this preview site.

Live Agent Activity

Real-time status and graph of multi-agent AI pentesting teams.

Agents Ready
Agent #1: Reconnaissance
Task: Attack surface mapping
Status: Completed
Agent #2: Exploitation
Task: OWASP & logic flaw testing
Status: Standby
Agent #3: Patching
Task: Auto-fix PR generation
Status: Ready

Assessment Runs History

Review all 6 demo assessment runs on record.

Target Status Mode Started Action
https://app.example-saas.com Completed standard Today, 2:13 PM
api.cloud-infra.io/v2 Completed standard Today, 1:53 AM
https://auth.enterprise-portal.net Completed deep Yesterday, 3:46 PM
https://billing.example-saas.com Completed deep Yesterday, 2:55 PM
https://demo.argos.sec Interrupted standard Sep 3, 5:49 PM
https://demo.argos.sec Completed quick Sep 3, 5:47 PM

Findings & Proof-of-Concepts

28 validated findings on file — zero false positives with working PoCs.

HIGH CVE-2024-51466: Critical Expression Language Injection
https://app.example-saas.com

Expression Language Injection vulnerability in analytics rendering endpoint allowing unauthorized command execution.

PoC Payload: GET /api/v1/analytics?render=%24%7B%22%22.getClass%28%29.forName%28%22java.lang.Runtime%22%29...%7D
HIGH CVE-2024-40695: Unrestricted File Upload in Upload Endpoint
https://api.cloud-infra.io

File upload module fails to restrict executable extensions, allowing remote execution of uploaded scripts.

PoC Payload: POST /api/v2/upload --data-binary @shell.php
MEDIUM Broken Object Level Authorization (IDOR) on User Profile API
https://app.example-saas.com

User ID parameter manipulation allows unauthorized retrieval of arbitrary user records.

PoC Payload: GET /api/users/10492 HTTP/1.1 (Authenticated as User 10021)
MEDIUM User Enumeration via Auth Response Differential Timing
https://auth.enterprise-portal.net

Login response times differ significantly between valid and invalid usernames, enabling account discovery.

PoC Payload: POST /auth/login (Delta: 420ms vs 12ms)
MEDIUM Improper Input Validation on Config Endpoint Causes Exception
https://demo.argos.sec

Malformed JSON body payload triggers unhandled internal server error revealing stack trace details.

PoC Payload: POST /api/config {invalid_json:true}

Target Scopes & Rules of Engagement

Manage allowed targets, excluded paths, and CI/CD diff-scope rules.

Active Scopes (Example Targets)
https://app.example-saas.com/*Active Scope
https://api.cloud-infra.io/*Active Scope
https://auth.enterprise-portal.net/*Active Scope

LLM Configuration & Providers

Configure AI model providers, API keys, or self-hosted air-gapped runtimes.

Burp Suite / MCP Integration

Model Context Protocol integration for HTTP interception and tool execution.

MCP Server Active
MCP Server Endpoint: mcp://burp.argos.local:9876
Interception Proxy: Active

System Settings & Preferences

Argos console runtime configuration and user access controls.