Kali-AI: Autonomous Penetration Testing Platform with Authenticated Scanning (v2)
Madarson It, LLC · Operations & Productivity
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 2 captures on record
What the publisher says
As described on Microsoft Marketplace.
Kali-AI v2 is a self-hosted, AI-powered autonomous penetration testing platform. It orchestrates a 7-tool pipeline, analyses findings with Claude AI, and generates professional white-label PDF reports - no manual effort from scan launch to final output.
This edition adds Authenticated Scanning: supply a session cookie or custom header per scan, and Kali-AI's applicable tools scan behind a login - surfacing findings on member areas and admin-adjacent paths an unauthenticated scan would miss.
Show the rest of the publisher’s description (42 more lines)
Built for MSSPs, security teams, red teams, and penetration testers who need repeatable automated assessments - including of logged-in application areas without SaaS pricing or per-finding fees.
How It Works
On scan launch, Kali-AI runs Nmap, Nuclei, Nikto, WhatWeb, Gobuster, WPScan, and SQLMap. When an authentication cookie or header is supplied, each applicable tool automatically includes it on every request. Findings are correlated, deduplicated, enriched with NIST NVD CVE data, and analysed by Claude to produce an executive summary, risk rating, attack path analysis, remediation plan, and compliance observations - delivered as a white-label PDF.
Authenticated Scanning
- Session cookie or custom header: optional per scan; unauthenticated scans work exactly as before
- Encrypted at rest: never appears in scan logs, live console, or reports
- Write-only: never returned by the API or shown in the UI once submitted
- Applies automatically to Nuclei, Nikto, WhatWeb, Gobuster, WPScan, and SQLMap
Platform Features
- Security Score Dashboard: posture score (0-100, A-F), risk gauge, severity breakdown, findings-by-tool chart, activity timeline
- White-Label PDF Reports: your company name and logo, email delivery on completion
- MSSP Multi-Tenant Support: client and project tagging, remediation tracker with CSV export
- Scheduled Scans: cron-based, persisted across restarts; batch up to 20 targets
- Attack Path Visualisation and Scan Delta tracking across assessments
- Security Copilot: AI assistant for remediation queries
- RBAC: admin, analyst, auditor roles with JWT authentication
- Integrations: Slack/Teams webhooks, SIEM JSON export, REST API
- First-Boot Setup: no default passwords
Who It's For
- Penetration testers accelerating recon, authenticated crawling, and reporting
- Red teams mapping attack paths across public and login-gated systems
- MSSPs delivering white-label assessments across multiple clients
- Enterprise security teams running continuous internal assessments
- Compliance teams in finance, healthcare, SaaS, and e-commerce needing NIST/PCI-DSS/ISO 27001 observations
- DevSecOps teams integrating automated scanning via the REST API
Security and Data Handling
No default credentials - a first-boot wizard has you create your own admin account. Authentication values you supply for logged-in scanning are encrypted and never appear in logs, console output, or reports. All scan data stays on your VM.
Quick Start
- Deploy the VM and open port 80.
- Browse to http://your-vm-ip/ to access setup.
- Create an admin account.
- Add your Anthropic API key in Settings.
- Launch a scan - optionally expand "Authentication" and supply a session cookie.
- View the AI-analysed PDF report in Reports.
About Madarson IT
Madarson IT certified images are always up to date, secure, follow industry standards, and are built to work right out of the box. Every image is designed to help organizations establish a strong security baseline and reduce risk exposure to common cyber threats. Madarson IT also offers hardened and custom images across AWS, GCP, and Azure Marketplace, covering multiple operating systems and compliance frameworks.
- ✓ No default passwords or hidden data egress
- ✓ All data stored locally; AI uses your own API key
- ✓ Support: info@madarsonit.com
Responsible Use & Disclaimer
AUTHORIZED USE ONLY. For authorized security testing, including with Authenticated Scanning - supply credentials only for accounts and systems you have explicit written permission to test. Claude is a third-party service requiring a user-provided API key.
Contact: info@madarsonit.com
Preview
5 imagesAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Sources
Publisher resources
7 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.






