Kali-AI: Autonomous Penetration Testing Platform with Authenticated Scanning
Madarson It, LLC · Operations & Productivity
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 1 capture on record
What the publisher says
As described on Microsoft Marketplace.
Kali-AI is a self-hosted, AI-powered autonomous penetration testing platform built on Kali Linux. It orchestrates industry-standard security tools, analyses findings with Claude AI, and generates professional 10-section PDF reports, with no manual effort from scan launch to final output.
This edition adds Authenticated Scanning: supply a session cookie or custom header per scan, and Kali-AI's web tools scan behind a login, surfacing findings on member areas and admin-adjacent paths an unauthenticated scan would miss.
Show the rest of the publisher’s description (44 more lines)
Built for MSSPs, security teams, red teams, and penetration testers who need repeatable automated assessments, including of logged-in application areas, without SaaS pricing or per-finding fees.
How It Works
On scan launch, Kali-AI runs Nmap, Nuclei, Nikto, WhatWeb, and Gobuster in sequence. When an authentication cookie or header is supplied, each applicable tool automatically includes it on every request. Findings are correlated, deduplicated, enriched with NIST NVD CVE data, and analysed by Claude to produce an executive summary, risk rating, attack path analysis, remediation plan, and compliance observations, delivered as a 10-section PDF.
Authenticated Scanning
- Session cookie or custom header: optional per scan; unauthenticated scans work exactly as before
- Encrypted at rest: never appears in scan logs, live console, or reports
- Write-only: never returned by the API or shown in the UI once submitted
- Applies automatically to Nuclei, Nikto, WhatWeb, and Gobuster
Platform Features
- Security Score Dashboard: posture score (0-100, A-F), risk gauge, severity breakdown, findings-by-tool chart, 7-day timeline
- Email Delivery: completion notifications, on-demand PDF delivery
- Scheduled Scans: cron-based, persisted across restarts; batch up to 20 targets
- Attack Path Visualisation and Scan Delta tracking across assessments
- Remediation Tracker: assign findings, due dates, status, CSV export
- Security Copilot: AI assistant for remediation queries
- RBAC: admin, analyst, auditor roles with JWT authentication
- Integrations: Slack/Teams webhooks, SIEM JSON export, REST API
- First-Boot Setup: no default passwords
Security and Data Handling
No default credentials: a first-boot wizard has you create your own admin account. Authentication values you supply for logged-in scanning are encrypted and never appear in logs, console output, or reports. All scan data stays on your VM, nothing is sent to Madarson IT.
Quick Start
- Deploy the VM and open port 80.
- Browse to http://your-vm-ip/ to access setup.
- Create an admin account (min. 12-character password).
- Add your Anthropic API key in Settings.
- Launch a scan, optionally expanding "Authentication" to supply a session cookie.
- View the AI-analysed PDF report in Reports.
Configuration
All settings are managed via a single configuration file on the VM, including your Anthropic API key and optional email delivery settings. Full setup instructions are included in the documentation on the VM.
Who It's For
- Penetration testers accelerating recon, authenticated crawling, and professional reporting
- Red teams mapping attack paths and chained exploitation across public and login-gated systems
- MSSPs delivering white-glove authenticated and unauthenticated assessments with client-ready PDF reports
- Enterprise security teams running continuous internal assessments, including of member portals and admin dashboards
- Compliance and audit teams in finance, healthcare, SaaS, and e-commerce needing NIST, PCI-DSS, and ISO 27001 gap observations
- DevSecOps teams integrating automated scanning into CI/CD pipelines via the REST API
Why Madarson IT?
- ✓ Azure Marketplace certified and production-ready
- ✓ No default passwords or hidden data egress
- ✓ All data stored locally; AI uses your API key
- ✓ Support: info@madarsonit.com
Responsible Use & Disclaimer
AUTHORIZED USE ONLY. For authorised security testing, including with Authenticated Scanning. Supply credentials only for accounts and systems you have explicit written permission to test. Kali Linux is a trademark of Offensive Security. Claude is a third-party service requiring a user-provided API key.
Contact: info@madarsonit.com
Preview
5 imagesAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Sources
Publisher resources
7 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.






