Pentesting is currently in beta and must be enabled for your company. If you do not see Pentests in the sidebar, contact your Corgea administrator or Corgea contact.
Targets
A target is a reusable pentest configuration. Each target includes a name, URL, optional credentials, optional instructions, and a default scan mode.1
Open Pentests
In Corgea, select Pentests from the sidebar.
2
Create a target
Click New target, then enter the target name and URL.
3
Add optional context
Add credentials when the test should cover authenticated areas. Use Additional instructions for rules of engagement, scope exclusions, or endpoints the agents should focus on.
4
Choose a default scan mode
Select Balanced for a faster run or Deep for a more thorough assessment.
Only add targets that your organization is authorized to test. Credentials are encrypted at rest and used only when a run is picked up for that target.
Start a Run
From the target list, start a new run for the target you want to test. You can use the target’s default scan mode or override it for a single run.- Balanced runs a faster assessment using the standard pentest agents.
- Deep runs a more thorough assessment and uses additional red-team coverage.
- Instruction override replaces the target’s additional instructions for that run only.
Review Results
The run detail page shows progress while agents are working and lists findings as they are reported. Findings are grouped by CWE and endpoint, with severity counts across all findings and focused categories such as Auth & AuthZ, Business Logic, and Injection. Open a finding to review its description, proof of concept, technical analysis, remediation guidance, target, endpoint, agent source, and detection history. You can update the finding status, add comments, and track re-detections across later pentest runs.Export Reports
When a run completes, use Export report to download a PDF report.- Technical report includes detailed finding evidence and remediation information.
- Executive report summarizes the assessment for less technical audiences.
