Pentest tooling

The report that tells the whole story.

Cybreach Engine runs your pentest engagements end to end (projects, vulnerabilities, infrastructure, AI) and produces branded PDF and Word reports in one click. Self-hosted: your instance, your data.

  • 26 Modules
  • 6 Export formats
  • 1 Install command
Illustration: a penetration tester at work, surrounded by security icons (firewall, encryption, vulnerability detection) around the message “Efficient reporting”.
What it does

The entire pentest engagement, one platform.

Projects

Vulnerabilities & VulnDB

CVSS, OWASP, CWE, multilingual. One-click import from a library of reusable templates.

Reports

PDF & Word in one click

Branded Jinja2 and docxtpl templates, plus six additional export formats.

AI

Context-aware assistant

Knows the project in real time. Drafts, classifies, translates. OWASP and CWE mandatory on every finding.

Auto-audit

Real tools, isolated

nmap, ffuf, sqlmap in a dedicated container, cut off from the network. Results imported straight into the project.

See all 26 modules

Free for solo work. Genuinely.

Solo Free gives a single auditor the whole engine (projects, vulnerabilities, infrastructure, reports, invoicing) with no time limit and no licence to configure. Solo Pro adds the AI, Team adds the team.

Frequently asked

What people ask us most.

Where is my engagement data stored?
On your own systems, exclusively. Cybreach Engine installs on your infrastructure: projects, vulnerabilities, clients and reports never leave your server. Cybreach Consulting has no access to your instance and collects no usage data.
Do I need an internet connection to use Cybreach Engine?
Not for the core of the tool. Projects, vulnerabilities, infrastructure and report generation all work fully offline. Only the AI assistant needs network access, and even then, running Ollama locally keeps everything inside your network.
Does the auto-audit really run offensive tools?
Yes. nmap, ffuf, sqlmap, dirb, curl and openssl genuinely execute, but inside a dedicated Docker container, isolated from the network and unreachable from the host or the internet. The AI then parses the raw output and imports structured findings into the project.
Which languages are reports generated in?
Five: French, English, German, Spanish and Italian. Vulnerability content is stored per language, and automatic captions (figures, tables, appendices) are translated accordingly.