Guide5 October 2026

AI Pentesting Explained: What It Is, Who It's For and What Decloak Offers

AI Pentesting Explained: What It Is, Who It's For and What Decloak Offers

AI Pentesting Explained: What It Is, Who It's For and What Decloak Offers

Most security tools stop at "this looks wrong". A missing header, an outdated library, a form that reflects input. Those are signals. Whether any of them can actually be exploited is a different question, and until now answering it meant hiring a human tester.

AI pentesting is an attempt to close that gap automatically. This guide explains what it is, who benefits, where it falls short and what we offer. We covered the launch in AI Pentesting Is Live. This is the longer explainer.

Scanning versus pentesting

The difference is the verb.

A vulnerability scanner observes. It reads responses, matches patterns and reports things that look risky. It is fast, cheap and broad, and it produces false positives because a pattern match isn't proof.

A penetration test attacks. A tester tries to exploit what they find and reports only what worked, with evidence. It is slower and more expensive, and the findings are far more trustworthy.

AI pentesting sits between the two. It automates the "try it and see" step, so a finding can move from "this might be exploitable" to "this is, and here is the request and response that proved it".

What it is for

The point is confirmation. If a scan says a search field reflects input, the useful next question is whether that is exploitable XSS or harmless output. If it finds a form, is it injectable? Teams get long lists of findings and very little way to tell which ones are real. Proof does three things:

Who it is for

It is most useful if you:

It is not for you if you need a formal, human-signed penetration test to satisfy a specific requirement. More on that below.

What Decloak's AI Pentesting does

AI Pentesting is the one layer in Decloak that attempts real exploitation. Everything else, including our eight scan layers and Active Testing, detects and flags. This layer only reports something as confirmed once a real tool has proven it.

A fixed toolkit, not an AI improvising attacks

This is a deliberate choice. Every target comes from a finding the rest of the scan already produced: a parameter that reflects input, a discovered API endpoint, a page with a form, a confirmed exposed file, a token spotted while crawling. Nothing is invented mid-scan by a model deciding what to attack.

That is what keeps the scope predictable, the runs reproducible and the consent meaningful. The AI is not picking targets. Real, named tools are doing the testing:

ToolWhat it does
sqlmapTests for SQL injection through URL parameters and forms
dalfoxTests for cross-site scripting, verifying payload execution rather than just reflection
ffufDiscovers hidden parameters using a curated wordlist
nucleiGoes deeper on confirmed exposed files and paths using misconfiguration templates
jwt_toolAttempts offline cracking of weak secrets on any JWT found while crawling

Testing is non-destructive by design. Confirmation relies on response signatures such as timing, status codes and error strings. It never extracts or changes your data. The JWT check is offline cracking only. We deliberately don't tamper with and replay tokens against a live endpoint.

Sandboxed and contained

Each tool run gets its own fresh, ephemeral sandbox, destroyed straight after. Network egress is limited in two independent ways: the sandbox platform's own allow-list, and a filtering proxy we built inside the sandbox that only permits traffic to the one domain under test.

Every outcome is shown

A check can end in one of five states, each visually distinct:

You never see a tool silently missing with no explanation.

Details are on the AI Pentesting page.

What it doesn't do yet

Being honest here matters more than sounding comprehensive.

So the right description is real confirmation for the classes it covers, not a replacement for a full penetration test. If a regulation, a customer contract or a certification requires a human-led test, you still need one. What AI Pentesting gives you is continuous confirmation between those tests. We're working on wider coverage, and we'll say so when it ships.

How to get it

AI Pentesting is an Enterprise feature (£99 a month), on top of Active Testing, and it runs as a second phase after the rest of a scan completes. Non-Enterprise plans see a locked preview so you can see what it checks before you upgrade.

Two things to do first: confirm you own or are authorised to test the target, and tick the second consent box when you set up the scan.


See the difference between "looks wrong" and "proven exploitable". Explore AI Pentesting →