Back to the registry
Agent passport

Kali-AI: Autonomous Penetration Testing Platform with Authenticated Scanning

Madarson It, LLC · Operations & Productivity

Virtual MachinesNo attestation published

Certification per Microsoft Marketplace.

Virtual Machine Subscription
Provenance reach3 of 12 layers traced

Evidence tier Source Confirmed · 1 capture on record

User ratingNot rated0 reviews on the listing
Runs onVirtual MachinesVirtual machine
ProvenanceUnknown33% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on Microsoft Marketplace.

Kali-AI is a self-hosted, AI-powered autonomous penetration testing platform built on Kali Linux. It orchestrates industry-standard security tools, analyses findings with Claude AI, and generates professional 10-section PDF reports, with no manual effort from scan launch to final output.

This edition adds Authenticated Scanning: supply a session cookie or custom header per scan, and Kali-AI's web tools scan behind a login, surfacing findings on member areas and admin-adjacent paths an unauthenticated scan would miss.

Show the rest of the publisher’s description (44 more lines)

Built for MSSPs, security teams, red teams, and penetration testers who need repeatable automated assessments, including of logged-in application areas, without SaaS pricing or per-finding fees.

How It Works

On scan launch, Kali-AI runs Nmap, Nuclei, Nikto, WhatWeb, and Gobuster in sequence. When an authentication cookie or header is supplied, each applicable tool automatically includes it on every request. Findings are correlated, deduplicated, enriched with NIST NVD CVE data, and analysed by Claude to produce an executive summary, risk rating, attack path analysis, remediation plan, and compliance observations, delivered as a 10-section PDF.

Authenticated Scanning

  • Session cookie or custom header: optional per scan; unauthenticated scans work exactly as before
  • Encrypted at rest: never appears in scan logs, live console, or reports
  • Write-only: never returned by the API or shown in the UI once submitted
  • Applies automatically to Nuclei, Nikto, WhatWeb, and Gobuster

Platform Features

  • Security Score Dashboard: posture score (0-100, A-F), risk gauge, severity breakdown, findings-by-tool chart, 7-day timeline
  • Email Delivery: completion notifications, on-demand PDF delivery
  • Scheduled Scans: cron-based, persisted across restarts; batch up to 20 targets
  • Attack Path Visualisation and Scan Delta tracking across assessments
  • Remediation Tracker: assign findings, due dates, status, CSV export
  • Security Copilot: AI assistant for remediation queries
  • RBAC: admin, analyst, auditor roles with JWT authentication
  • Integrations: Slack/Teams webhooks, SIEM JSON export, REST API
  • First-Boot Setup: no default passwords

Security and Data Handling

No default credentials: a first-boot wizard has you create your own admin account. Authentication values you supply for logged-in scanning are encrypted and never appear in logs, console output, or reports. All scan data stays on your VM, nothing is sent to Madarson IT.

Quick Start

  • Deploy the VM and open port 80.
  • Browse to http://your-vm-ip/ to access setup.
  • Create an admin account (min. 12-character password).
  • Add your Anthropic API key in Settings.
  • Launch a scan, optionally expanding "Authentication" to supply a session cookie.
  • View the AI-analysed PDF report in Reports.

Configuration

All settings are managed via a single configuration file on the VM, including your Anthropic API key and optional email delivery settings. Full setup instructions are included in the documentation on the VM.

Who It's For

  • Penetration testers accelerating recon, authenticated crawling, and professional reporting
  • Red teams mapping attack paths and chained exploitation across public and login-gated systems
  • MSSPs delivering white-glove authenticated and unauthenticated assessments with client-ready PDF reports
  • Enterprise security teams running continuous internal assessments, including of member portals and admin dashboards
  • Compliance and audit teams in finance, healthcare, SaaS, and e-commerce needing NIST, PCI-DSS, and ISO 27001 gap observations
  • DevSecOps teams integrating automated scanning into CI/CD pipelines via the REST API

Why Madarson IT?

  • ✓ Azure Marketplace certified and production-ready
  • ✓ No default passwords or hidden data egress
  • ✓ All data stored locally; AI uses your API key
  • ✓ Support: info@madarsonit.com

Responsible Use & Disclaimer

AUTHORIZED USE ONLY. For authorised security testing, including with Authenticated Scanning. Supply credentials only for accounts and systems you have explicit written permission to test. Kali Linux is a trademark of Offensive Security. Claude is a third-party service requiring a user-provided API key.

Contact: info@madarsonit.com

Preview

5 images
Kali-AI: Autonomous Penetration Testing Platform with Authenticated Scanning preview 1Kali-AI: Autonomous Penetration Testing Platform with Authenticated Scanning preview 2Kali-AI: Autonomous Penetration Testing Platform with Authenticated Scanning preview 3Kali-AI: Autonomous Penetration Testing Platform with Authenticated Scanning preview 4Kali-AI: Autonomous Penetration Testing Platform with Authenticated Scanning preview 5

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment · as of 2026-08-29

CompanyMadarson ITAutomated
HQUnited States of AmericaAutomated
IndustryTechnologyAutomated
Websitehttps://madarsonit.com/

Sources

Marketplace listingmarketplace.microsoft.comSource
Privacy PolicyPrivacy PolicySource

Publisher resources

7 links
Supportmadarsonit.comSource
Our Servicesmadarsonit.comSource
Our Marketplace Productsazuremarketplace.microsoft.comSource
Marketplace Blogtechcommunity.microsoft.comSource
About Kali Linuxwww.kali.orgSource
Kali Linux Toolswww.kali.orgSource
Kali-AI: Autonomous Penetration Testing Platform with Authenticated Scanningwww.youtube.comSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Unknown
Not stated
Delivery
Virtual machine
https://madarsonit.com/
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.