The #1 Offensive Security Management Platform

From Pentest to Patch: The Platform That Closes the Loop

Automate vulnerability workflows from discovery to verified remediation. Real-time visibility. Automated ticketing. SLA enforcement. One platform connecting pentesters, security managers, and engineers.

Plan, Perform, and Track

Offensive Security as a Project

Every pentest engagement follows a lifecycle. AttackForge gives that lifecycle a home.

01

Request or Create a Project

Clients submit project requests for approval, or your team creates projects directly. Set the scope, define the assets, assign the methodology, and schedule the work - all before the first test case is executed.

02

Invite Your Project Team

Bring together testers, clients, managers, and developers. Everyone gets role-based access so they see exactly what they need and nothing they should not. Consultants work alongside client stakeholders without permission headaches.

03

Complete Test Cases

Demonstrate testing progress against industry benchmarks. AttackForge ships preloaded with test suites from MITRE, OWASP, OSSTMM and others. Enforce consistent methodology on every engagement. Track daily progress automatically.

04

Add Vulnerabilities

Import findings from your scanner stack - Nessus, Burp Suite, Qualys, Invicti, and more - or create them manually using centralized writeup libraries that keep language consistent across your team. Create attack chains and map them to the MITRE ATT&CK framework.

05

Instant Reports

Generate DOCX reports on demand using ReportGen. Use pre-built templates or create your own with tags, functions, filters, conditions, tables, and charts. Reports inherit your branding and formatting from the Word template.

Supporting Capabilities:

Single-pane dashboard with quick navigation. Daily tracking of vulnerabilities discovered and test cases actioned. Dedicated workspace for notes, files, and testing logs. Custom fields with configurable access controls. Retesting flows for requesting and performing retesting rounds on every project. Scheduling views with user availability and project calendars. Powerful rules-based email notifications. Integrations, executive overview, project logs, and more.

Vulnerability Workflow Automation
That Actually Works

This is where AttackForge transforms your offensive security program. Every vulnerability—whether from a manual pentest, automated scanner, or red team engagement—flows through a unified workflow that ensures nothing falls through the cracks.

Feature 1

Every Finding. One Platform. Zero Friction.

Import vulnerabilities from Nessus, Burp Suite, Qualys, Checkmarx, and many more tools - or create them manually during pentests. AttackForge automatically maps them to your writeup libraries, and enriches them with context.

Import from all major scanners and pentest tools with native parsers
2,500+ pre-loaded writeups from MITRE CWE, CAPEC and AT&CK for instant consistency
Custom writeup libraries for organization-specific vulnerability definitions
💡

Eliminate hours of tedious copy-paste per engagement with automated import and mapping.

NessusBurp SuiteQualysOWASP ZAPCheckmarx...

Workflow Visualization

1. Select a tool
↓
2. Choose import preferences
↓
3. Import vulnerabilities
↓
4. Enrich vulnerabilities automatically

On-Demand Reports with ReportGen

Your Reports. Your Brand. Your Data. Generated in Seconds.

Pentest reports are the deliverable your clients pay for. AttackForge makes them effortless.

ReportGen is a custom-built reporting engine that combines DOCX templates with your project data to produce professional reports on demand. No manual formatting. No copy-paste errors. No waiting until the end of the engagement.

01

Create a template or adapt your own

ReportGen works with standard DOCX files. Apply formatting in Word the way you normally would. Style a tag bold, and the output will be bold. It is that simple. Extensive documentation and example templates are available to get started fast.

02

Test your template

Use the ReportGen browser tool or CLI to preview your report against real project data. Debug in the browser console. Iterate until it is perfect.

03

Upload your template

Upload as many templates as you need. Each template has configurable access controls so different teams or clients see different report options.

04

Generate on demand

Any authorized user can download reports directly from their project dashboard. Select specific vulnerabilities for targeted reports, or generate the full engagement report. Available as DOCX, CSV, JSON, and ZIP archive with all evidence.

Advanced Templating Engine

The templating engine supports tags, functions, filters, conditions, tables, and charts. Create custom sections, reference custom fields, build conditional logic, and produce reports that match exactly what each stakeholder needs - from the technical deep-dive to the board-level summary.

Executive Reporting

Analyze vulnerabilities across your organization or individual business units. Compare trends across time periods. Monitor remediation against SLAs. Measure Mean-Time-To-Remediate. See your top 10 most vulnerable assets. Executive line reporting for leadership visibility.

Event-Triggered Automations

Flows

Flows is the automation engine inside AttackForge. It lets you connect AttackForge to any system or APIs to perform powerful automations - without writing external code.

Send AttackForge data to your applications. Create a JIRA ticket every time a critical vulnerability is discovered. Post to Slack when an SLA is breached. Push findings to your GRC platform. Trigger a scan in your security toolset. The pattern is simple: an event happens in AttackForge, and Flows execute your requirements.

Chain multiple actions with conditional decision logic. Use Script Actions with AFScript to separate your business logic from HTTP request and response handling.

Create dedicated trigger URLs to execute Flows from external systems and scripts.

Pre-built Templates

Pre-built templates are available for common integrations with JIRA, ServiceNow, Azure DevOps, and more. Use them to get running in minutes, then customize to match your workflows.

Granular Access Controls

Granular access controls on every Flow. Per-user permissions. README documentation built into each Flow so your team knows exactly how it works.

Conditional Logic

Chain multiple actions with conditional decision logic. Build complex automation workflows that respond intelligently to different scenarios and data conditions.

What teams automate with Flows:

Bi-directional sync with JIRA, ServiceNow Azure DevOps, and other ticketing tools. Visualization in Power Bl and Tableau. Integrate risk data to GRC platforms like RSA Archer, MetricStream, OneTrust, and LogicGate. Automated scanning triggers in Rapid7, Tenable, and Qualys. Messages to Slack and Teams. Threat intelligence enrichment with VulnDB. Custom webhooks and email notifications on any event.

Integrate AI Assistants

Get Real Work Done Fast with Your Al Plugged In

AttackForge is the only offensive security management platform with native Al assistant integration for any LLM, including yours - Local (custom models) or Remote (frontier models) - through the Model Context Protocol (MCP).

Connect your preferred AI assistant - Anthropic Claude, Microsoft Copilot, OpenAI ChatGPT, or local and open-source models via LM Studio and similar tools - directly to your AttackForge data. No middleware. No third-party connectors. Built into the platform.

What makes this different from bolting AI onto a security tool:

Per-user, per-tool access controls

Administrators enable specific MCP tools for each user individually. No blanket access. No uncontrolled data exposure. Maximum security.

Self-registration via built-in OAuth2

Users connect their AI assistant without needing administrators to manually provision credentials. Less friction. Less admin overhead.

Session visibility

Administrators can see active MCP sessions per user. Full accountability.

Local model support

Run MCP against local or open-source models for sensitive data processing in environments where nothing leaves the network. Configure in LM Studio or Claude Desktop with your AttackForge hostname and API key.

No vendor lock-in

Switch AI providers at any time. Your integrations keep working because they are built on the MCP standard, not on a proprietary API.

Growing tool library

As new MCP tools are released, authorized users gain access automatically. No custom development required.

What teams use AI assistants for:

Generate executive summaries from project data. Draft vulnerability descriptions and remediation recommendations. Identify the single highest-risk vulnerability across an engagement. Build vulnerability composition metrics dashboards. Create interactive charts for stakeholder presentations. Review vulnerabilities in retest cycles. And more as the tool library expands.

Connect Your Ecosystem

Self Service APIs

AttackForge fits into your existing toolchain. It does not replace it.

150+ REST API Endpoints

150+ REST API endpoints covering every data object in the platform. Event-driven APIs for real-time updates via data-driven events.

OpenAPI v3 Compliant

OpenAPI v3 compliant documentation for easy consumption and client library generation. Enterprise-ready access controls on every endpoint.

Visual Automation Layer

For teams that want integrations without writing code, Flows provide a visual, event-driven automation layer with pre-built templates.

Full Programmatic Access

For teams that want full control, the APIs provide complete programmatic access to all platform features and data.

Named integrations supported:

JIRA, ServiceNow, Azure DevOps, Slack, Microsoft Teams, Power BI, Salesforce, Synack, HackerOne, Bugcrowd, VulnDB, and any tool with a HTTP interface.

Adapt the Tool to Work for You

The Most Configurable Offensive Security Platform Available

AttackForge does not force a workflow on your team. You configure it to match how you already operate - then refine from there.

Switch entire workflows on or off. Build custom forms and data models. Leverage advanced features like field-level access controls and show/hide logic. Adjust features at the tenant level. Build custom menus with Actions. Customize the application to your style, your branding, and your processes. Use AFScript for complete personalization.

What you can configure:

Whitelabelling with your company logo. Custom colour themes including dark mode. Custom fields and custom forms with extensive field types. Configurable table views. Rule-based SLAs that match your remediation policies. Custom import mapping for vulnerability scanner output. Report template access controls. Email templates for every notification. Rules-based email notifications for automated escalations. Daily and weekly summary emails. Delegation workflows for workload distribution. And more.

Whether you are a solo tester on the Pro plan or a Fortune 500 enterprise running hundreds of engagements a year, AttackForge adjusts to your scale and your preferences.

Start your free fully featured AttackForge trial.

Instant deployment. No credit card required. Dedicated tenant. Every feature unlocked.