Back to the registry
Agent passport

Kali-AI v2 - Automated Pentest Platform on Hardened Ubuntu 24.04 LTS

Madarson IT · Cybersecurity & IT

Partial captureNo attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownVirtual machine
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

This is a repackaged software product wherein additional charges apply for the Kali-AI v2 automated penetration testing platform.

Kali-AI v2 is a self-hosted autonomous penetration testing platform built on hardened Ubuntu 24.04 LTS. It runs a 7-tool scanning pipeline, analyzes every finding with Anthropic Claude AI, and generates professional 10-section PDF security reports automatically - no manual steps between scan launch and final deliverable.

Show the rest of the publisher’s description (36 more lines)

Designed for MSSPs, security teams, red teams, and penetration testers who need repeatable automated assessments without SaaS pricing or data residency risk. All data stays on your EC2 instance.

## How It Works

Kali-AI v2 automatically executes Nmap, Nuclei, Nikto, WhatWeb, Gobuster, WPScan, and SQLMap in sequence. Findings are correlated, enriched with CVE data, and analyzed by Claude AI to produce an executive summary, risk rating, attack path analysis, remediation plan, and NIST/PCI-DSS/ISO 27001 compliance observations - delivered as a polished 10-section PDF.

## Key Features

  • **7-Tool Automated Pipeline:** Nmap, Nuclei, Nikto, WhatWeb, Gobuster, WPScan, and SQLMap run automatically in sequence with no manual orchestration required.
  • **Claude AI Analysis:** Every finding is risk-rated and written up by Anthropic Claude, producing actionable narratives rather than raw scanner output.
  • **10-Section PDF Reports:** Professional reports ready to deliver to clients or stakeholders. White-label with your company name and logo. Email delivery on scan completion.
  • **Security Score Dashboard:** Posture score (0-100, A-F), risk gauge, severity chart, and 7-day timeline.
  • **Remediation Tracker:** Assign findings, set due dates, track status, and export to CSV.
  • **Attack Path Visualization:** Interactive graph showing chained vulnerability sequences.
  • **Scan Delta:** Compare new vs resolved vs persistent findings across assessments.
  • **Scheduled Scans:** Cron-based recurring scans with Full, Quick, Web, or Network scan types.
  • **Batch Scanning:** Up to 20 targets with parallel execution for MSSP workflows.
  • **Client and Project Tagging:** Organize assessments by client and engagement.
  • **Security Copilot:** AI assistant for plain-language queries about results and remediation.
  • **RBAC:** Admin, analyst, and auditor roles with JWT authentication.
  • **Integrations:** Slack and Teams webhooks, SIEM JSON export, and REST API for CI/CD pipelines.

## Security and Data Handling

The platform runs on a hardened Ubuntu 24.04 LTS base. The first-boot wizard ensures no default credentials exist. RBAC with JWT authentication controls access across roles. All scan data remains on your EC2 instance with no vendor data retention. API keys and SMTP credentials are stored in /opt/kali-ai/.env with restricted file permissions.

## Getting Started

  • Launch an EC2 instance (t3.medium or larger, 30 GB EBS). Open port 80 in your Security Group.
  • Browse to http://your-ec2-ip/ and complete the setup wizard.
  • Create your admin account (12+ character password required).
  • Add your Anthropic API key in Settings (obtain from console.anthropic.com - pay-per-use).
  • Launch a scan. Try: scanme.nmap.org
  • View the AI-analyzed PDF report in the Reports section.

## Evaluate Before You Commit

To assess report quality and platform capabilities, request a sample anonymized PDF report from Madarson IT before deploying. Launch a t3.medium instance and run a scan against scanme.nmap.org to experience the full scan-to-report workflow with minimal commitment.

## Requirements and Limitations

  • An Anthropic API key is required for Claude AI analysis and is billed separately by Anthropic on a pay-per-use basis.
  • Buyers should verify compatibility with their target EC2 instance types before deploying at scale.
  • For HTTPS, deploy behind an AWS ALB or CloudFront distribution with an ACM certificate.

## Responsible Use

AUTHORIZED USE ONLY. For security testing of systems you have explicit written permission to test. Unauthorized use violates the AWS Acceptable Use Policy, the Computer Fraud and Abuse Act (CFAA), and equivalent laws.

## About Madarson IT

Madarson IT certified images are continuously updated, security-optimized, and built to meet enterprise requirements with minimal configuration. Madarson IT also offers hardened and custom images across AWS, GCP, and Azure Marketplace.

Highlights

Highlighted by the publisher on AWS Marketplace.

7-Tool Automated Pentest Pipeline: Nmap, Nuclei, Nikto, WhatWeb, Gobuster, WPScan, and SQLMap run automatically in sequence. Findings are correlated, CVE-enriched, and analysed by Anthropic Claude AI - eliminating hours of manual tool orchestration per assessment. Schedule recurring scans, run batch assessments against up to 20 targets, and track delta changes across engagements without any manual pipeline management.

White-Label PDF Reports with Claude AI Analysis: Every scan produces a professional 10-section PDF report with executive summary, risk rating, attack path analysis, remediation plan, and NIST/PCI-DSS/ISO 27001 compliance observations generated by Claude AI. White-label with your company name and logo for direct client delivery. Email delivery on scan completion included.

Built for MSSP and Enterprise Workflows: Client and project tagging supports multi-tenant operations. Remediation tracker with assignee, due date, and CSV export integrates into project management workflows. Slack, Teams, and SIEM webhooks plus a full REST API enable CI/CD integration. RBAC with admin, analyst, and auditor roles controls access across your team.

Preview

3 images
Kali-AI v2 - Automated Pentest Platform on Hardened Ubuntu 24.04 LTS preview 1Kali-AI v2 - Automated Pentest Platform on Hardened Ubuntu 24.04 LTS preview 2Kali-AI v2 - Automated Pentest Platform on Hardened Ubuntu 24.04 LTS preview 3

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Refund terms

As stated by the publisher on AWS Marketplace.

There is no refund policy for this image

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
StandardEulaStandardEulaSource

Publisher resources

3 links
Our Servicesmadarsonit.comSource
Our AWS Marketplace Productsaws.amazon.comSource
Kali Toolswww.kali.orgSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
Rate card pricing
Delivery
Virtual machine
## Support for Kali-AI v2 Madarson IT provides support for Kali-AI v2 via email at info@madarsonit.com. Contact us for assistance with deployment, configuration, scanning issues, report generation, or troubleshooting. ## How to Submit a Request When contacting support, please include: - Your EC2 instance ID - A description of the issue or question - Any relevant error messages or log output This information helps us diagnose and resolve your issue efficiently. ## Private Offers and Custom Licensing For private offers, volume licensing, or custom deployment arrangements, contact info@madarsonit.com with details about your requirements and expected usage.
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.