
AI Pentesting Explained: What It Is, Who It's For and What Decloak Offers
Most security tools stop at "this looks wrong". A missing header, an outdated library, a form that reflects input. Those are signals. Whether any of them can actually be exploited is a different question, and until now answering it meant hiring a human tester.
AI pentesting is an attempt to close that gap automatically. This guide explains what it is, who benefits, where it falls short and what we offer. We covered the launch in AI Pentesting Is Live. This is the longer explainer.
Scanning versus pentesting
The difference is the verb.
A vulnerability scanner observes. It reads responses, matches patterns and reports things that look risky. It is fast, cheap and broad, and it produces false positives because a pattern match isn't proof.
A penetration test attacks. A tester tries to exploit what they find and reports only what worked, with evidence. It is slower and more expensive, and the findings are far more trustworthy.
AI pentesting sits between the two. It automates the "try it and see" step, so a finding can move from "this might be exploitable" to "this is, and here is the request and response that proved it".
What it is for
The point is confirmation. If a scan says a search field reflects input, the useful next question is whether that is exploitable XSS or harmless output. If it finds a form, is it injectable? Teams get long lists of findings and very little way to tell which ones are real. Proof does three things:
- It cuts noise. Confirmed findings go to the top. Unconfirmed ones can wait.
- It ends arguments. "Is this actually a problem?" is much easier to settle with a captured request and response than with a severity label.
- It gives you evidence. Proof of exploit is what you attach to a ticket, an audit file or a customer's security questionnaire.
Who it is for
It is most useful if you:
- Ship often. A yearly manual pentest is out of date within weeks. Automated confirmation can run on every meaningful release.
- Have a small or no security team. You can't triage hundreds of unverified findings. Confirmed ones are actionable on their own.
- Answer to customers or auditors. Evidence that you test for exploitability, and what happened when you did, is worth more than a list of warnings.
- Build with AI tools. Generated code tends to be weak on exactly the classes that need context to spot. Veracode's latest benchmark found AI models pass only 15% of cross-site scripting checks (see our digest on the report).
- Run an agency. You can show clients proof rather than a screenshot of a warning.
It is not for you if you need a formal, human-signed penetration test to satisfy a specific requirement. More on that below.
What Decloak's AI Pentesting does
AI Pentesting is the one layer in Decloak that attempts real exploitation. Everything else, including our eight scan layers and Active Testing, detects and flags. This layer only reports something as confirmed once a real tool has proven it.
A fixed toolkit, not an AI improvising attacks
This is a deliberate choice. Every target comes from a finding the rest of the scan already produced: a parameter that reflects input, a discovered API endpoint, a page with a form, a confirmed exposed file, a token spotted while crawling. Nothing is invented mid-scan by a model deciding what to attack.
That is what keeps the scope predictable, the runs reproducible and the consent meaningful. The AI is not picking targets. Real, named tools are doing the testing:
| Tool | What it does |
|---|---|
| sqlmap | Tests for SQL injection through URL parameters and forms |
| dalfox | Tests for cross-site scripting, verifying payload execution rather than just reflection |
| ffuf | Discovers hidden parameters using a curated wordlist |
| nuclei | Goes deeper on confirmed exposed files and paths using misconfiguration templates |
| jwt_tool | Attempts offline cracking of weak secrets on any JWT found while crawling |
Testing is non-destructive by design. Confirmation relies on response signatures such as timing, status codes and error strings. It never extracts or changes your data. The JWT check is offline cracking only. We deliberately don't tamper with and replay tokens against a live endpoint.
Sandboxed and contained
Each tool run gets its own fresh, ephemeral sandbox, destroyed straight after. Network egress is limited in two independent ways: the sandbox platform's own allow-list, and a filtering proxy we built inside the sandbox that only permits traffic to the one domain under test.
Every outcome is shown
A check can end in one of five states, each visually distinct:
- Confirmed: real proof, with the exact request and response.
- Signal: a heuristic hit worth looking at, but not proof.
- Clean: genuinely tested, nothing found.
- Inconclusive: blocked by a firewall or a TLS failure. Never shown as a clean pass.
- Not applicable: nothing on the site matched what that tool looks for, so it never ran, and the report says so in plain language.
You never see a tool silently missing with no explanation.
Consent, scoring and reports
- A second, explicit consent checkbox is required on top of Active Testing's, naming that real exploitation attempts will run.
- The Pentest Score is separate from your main security score and your Active Testing score. It is never blended into either.
- There is a dedicated Pentesting tab in the report, and a standalone Pentest Report PDF with the full proof of exploit. It is also bundled into the evidence package.
Details are on the AI Pentesting page.
What it doesn't do yet
Being honest here matters more than sounding comprehensive.
- It confirms SQL injection and XSS with proof. Hidden parameter discovery, exposure deepening and weak JWT secret cracking are narrower, and mostly produce signals rather than proof.
- It doesn't yet attempt SSRF, XXE, command injection, CSRF, IDOR or broken object-level authorization, or several other classes a human tester would cover.
- It is bounded on purpose. Targets come from what the scan found. It won't wander into areas the scan never discovered.
So the right description is real confirmation for the classes it covers, not a replacement for a full penetration test. If a regulation, a customer contract or a certification requires a human-led test, you still need one. What AI Pentesting gives you is continuous confirmation between those tests. We're working on wider coverage, and we'll say so when it ships.
How to get it
AI Pentesting is an Enterprise feature (£99 a month), on top of Active Testing, and it runs as a second phase after the rest of a scan completes. Non-Enterprise plans see a locked preview so you can see what it checks before you upgrade.
Two things to do first: confirm you own or are authorised to test the target, and tick the second consent box when you set up the scan.
See the difference between "looks wrong" and "proven exploitable". Explore AI Pentesting →