Skip to main content

Pentest Framework

PyPI Downloads GitHub stars License: MIT Python

A modular, automated penetration-testing pipeline that orchestrates open-source tooling, normalizes results into a single schema, deduplicates, optionally enriches findings with an LLM, and produces a professional PDF report.

FOR AUTHORIZED SECURITY TESTING ONLY. Only run this against assets you own or have explicit written permission to test. The pipeline asks for an authorization confirmation before active testing (skippable with --no-confirm for automation).

Pipeline

target ─▶ recon ─▶ scanners ─▶ api_checks ─▶ aggregate ─▶ [enrich] ─▶ PDF report
         (subfinder/    (nuclei/    (headers/CORS/   (dedup +        (Claude,
          amass/httpx)   nikto)      exposed paths)   group)          optional)

Low-noise by design

Most header/recon scanners drown you in false positives. This one suppresses the common ones at the source:

  • Content-type-aware headers — CSP, X-Frame-Options, Referrer-Policy and Permissions-Policy are flagged only on rendered HTML documents, not on JSON APIs where they have no effect.
  • HSTS only over HTTPS — never reported on plaintext http:// targets, where the header is ignored by browsers.
  • SPA-fallback fingerprinting — a single-page-app catch-all that returns the index shell for every path is not reported as an "exposed endpoint".
  • CORS — flags the precise dangerous combination (reflected / null origin with credentials), not a correctly-configured allowlist.
  • One schema — every tool's output is normalized, deduplicated, and severity- escalated into a single finding shape.

Architecture

pentest-framework/            # repo root
├── pentest_framework/        # the package
│   ├── main.py               # full pipeline (CLI: pentest-framework)
│   ├── scan_local.py         # scan a locally-running app by URL
│   ├── recon/ scanner/ api_checks/ parser/ enrichment/ report/
│   ├── models/               # the single Finding schema + Severity
│   └── utils/                # logging, subprocess runner, scope handling
├── examples/                 # standalone usage examples
├── tests/                    # pytest unit tests
└── pyproject.toml  LICENSE  README.md

Install

pip install -e ".[ai]"        # editable install; '[ai]' adds optional Claude enrichment
# or runtime deps only:
pip install -r requirements.txt

Installs a pentest-framework console command (equivalent to python -m pentest_framework.main).

External CLI tools are not Python packages — install them separately and put them on $PATH:

Tool Role Link
subfinder subdomain enumeration (primary) https://github.com/projectdiscovery/subfinder
httpx liveness + tech fingerprinting https://github.com/projectdiscovery/httpx
nuclei vulnerability scanning (primary) https://github.com/projectdiscovery/nuclei
amass subdomain enumeration (fallback) https://github.com/owasp-amass/amass
nikto web-server scan (fallback) https://github.com/sullo/nikto

The pipeline degrades gracefully: missing tools are logged and skipped rather than crashing the run.

Usage

# Full run
python -m pentest_framework.main example.com

# With a scope file and AI enrichment
python -m pentest_framework.main example.com --scope scope.txt --enrich

# Scan a single IP, custom output dir, no interactive prompt
python -m pentest_framework.main 203.0.113.10 -o /output --no-confirm

Output (under --output, default output/):

  • pentest_report.pdf — the report
  • findings.json — normalized, deduplicated findings
  • recon.json — recon results
  • pentest.log — full run log

On success it prints:

Pentest completed. Report saved at output/pentest_report.pdf

Scope file format

# one entry per line; '#' comments allowed
example.com
api.example.com
*.staging.example.com
203.0.113.10

Any discovered host not matching an in-scope entry is dropped before probing.

Run modules independently

Each module is runnable on its own:

python -m pentest_framework.recon.recon example.com
python -m pentest_framework.scanner.scanner --url https://example.com
python -m pentest_framework.api_checks.api_checks https://example.com
python -m pentest_framework.parser.aggregator findings.json
python -m pentest_framework.enrichment.enrich findings.json
python -m pentest_framework.report.report findings.json --target example.com

AI-assisted enrichment

enhance_finding(finding) clarifies the description, adds realistic impact, and suggests remediation. It is strictly editorial — it never invents vulnerabilities and never changes severity/title/target/evidence.

  • With anthropic installed and ANTHROPIC_API_KEY set, it uses Claude (claude-opus-4-8 by default; override with ANTHROPIC_MODEL).
  • Otherwise it falls back to a safe offline heuristic that only fills obviously missing fields.

Scan a local app

recon resolves hostnames, so for an app on a non-standard port, target the URLs directly instead:

python -m pentest_framework.scan_local            # defaults: localhost:8080 + :8000
python -m pentest_framework.scan_local --targets http://localhost:3000/

Finding schema

{
  "title": "",
  "severity": "Critical | High | Medium | Low | Info",
  "description": "",
  "target": "",
  "evidence": "",
  "remediation": ""
}

Tests

pip install -e ".[dev]" && pytest

License

MIT — see LICENSE. For authorized security testing only; please read CONTRIBUTING.md before contributing.

Related tools

Part of my open-source toolkit — github.com/matte97p:

  • rlsgrid — catch cross-tenant Row-Level Security leaks in Postgres/Supabase before your users do
  • demowright — record polished product-demo videos from a script that lives in your repo
  • GeoSuite CLIs — zero-dep Generative Engine Optimization toolkit

⭐ If pentest-framework saved you time on an engagement, give it a star — it's the cheapest way to help other testers find it.


🌐 Built by Matteo Perinomatteoperino.dev

Release files for pentest-framework 1.0.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pentest-framework 1.0.2
File Size Uploaded
pentest_framework-1.0.2.tar.gz 36.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pentest-framework 1.0.2
File Interpreter ABI Platform
pentest_framework-1.0.2-py3-none-any.whl Python 3 none any Details

Total release size: 75.3 kB

Release files / pentest_framework-1.0.2.tar.gz

Download URL pentest_framework-1.0.2.tar.gz
Size 36.0 kB
Tags Source
SHA-256 checksum
How to use checksums
7d6552989f7935f2f273e51abb7087525ebcb98d1b8c5c90dbe4b5d053e88bfe
BLAKE2b-256 checksum
How to use checksums
4717ec8e3ff470b5ddd669f9dc71a43fd9e1040cb23092e2df4cd292712dabfa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 11, 2026.

Transparency log

Release files / pentest_framework-1.0.2-py3-none-any.whl

Download URL pentest_framework-1.0.2-py3-none-any.whl
Size 39.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
59da038d62a9b957cb876798cbd4433dd37369af0195f21eade6f33dd886efa3
BLAKE2b-256 checksum
How to use checksums
2d465c93341ee2470de12a9c9f2dfe06400d63d8f82c18d5920b0e7d394b73f9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 11, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.2 This release

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page