Pentest recon and coverage, accelerated
The first days of an engagement go to mapping and tooling. NightVision compresses that, so you spend the engagement on the work that earns your day rate.
Recon and breadth eat the calendar.
Enumerating an undocumented API by hand, keeping a scanner's session alive, and re-verifying tool output burn hours that were sold as testing time; the creative work gets squeezed into what is left.
Where NightVision accelerates the engagement
Recon from source, when you have it
On gray-box engagements, API eNVy generates an OpenAPI spec from supported source in under 20 seconds, locally and deterministically, surfacing routes missing from documentation or observed traffic.
A fully authenticated coverage baseline
Record the login once with Playwright, TOTP and MFA included, and the real-browser crawler sweeps the broad surface for common vulnerability classes while your manual time goes to logic flaws, chaining, and authorization depth.
Evidence you can hand to the client
Request-level findings retain HTTP evidence with, where supported, a Validate with Curl replay; findings export as CSV or SARIF to fold into your report instead of transcribing by hand.
What stays yours
NightVision is not a replacement for a penetration tester. Business logic abuse, chained exploitation, and authorization design are human work, and they are what clients pay for. NightVision's job is to start that work on day one: map drawn, session held, baseline swept.
Source-to-OpenAPI in under 20 seconds: the target map that used to take the first day of the engagement.
Pentest recon questions
Does NightVision replace manual penetration testing?
No. Business logic abuse, chained exploitation, and authorization design review are human work, and they are what clients pay a tester for. NightVision accelerates the parts that precede that work: target mapping, authenticated coverage of the broad surface, and evidence collection.
How does it accelerate recon?
With source access, API eNVy generates an OpenAPI spec in under 20 seconds, surfacing undocumented endpoints that manual enumeration would take days to find. Without source, the crawler maps the running application in a real browser, including single-page apps, using LLM-based form handling, intelligent waiting, and duplicate page detection.
Can it test fully authenticated application states?
Yes. Record the target's login once as a Playwright script; credentials are vaulted and replayed at scan time, with TOTP and MFA supported. A login check verifies the session is real, so you know immediately if authentication broke rather than discovering a hollow scan later.
Can I verify the findings myself?
Yes. Request-level findings retain HTTP evidence and, where supported, include a Validate with Curl replay so you can confirm the behavior and fold the result into your report. Findings export as CSV or SARIF.
Does it work on internal engagements?
Yes. The Smart Proxy makes an outbound connection from inside the client's network, so internal applications are reachable without inbound firewall changes or appliances. See private network scanning.
Start the engagement with the map already drawn.
Book a demo, or start free and generate a spec from source before your next kickoff.