Enterprise BAS · Cloud, API, Web & Mobile Autonomous Pentest

Puppet Master

Autonomous attack emulation with 100% BAS parity across 15 offensive modules (Modules A through O, emphasizing Modules K to O). Puppet Master actively executes the attack paths discovered by Ghost Mode: credential chaining, safe SSRF IMDSv1/v2 probing, active REST & GraphQL API injection, mobile instrumentation via Frida, read-only host post-exploitation, and SIEM/CDR correlation — all anchored in ECDSA P-256 cryptographic custody.

puppet-master · run #A7F3 live

01 RoE scope confirmed · api.prod · us-east-1 · multi-cloud

02 PLAN 15 offensive modules loaded (A–O) · 16 attack paths

03 EXEC GraphQL introspection → SSRF IMDSv2 (Mod. K) → sts:AssumeRole

04 API proof captured · req-id 8f21c… · SIEM alert correlated (Mod. O)

05 GATE certified sign-off · signed ECDSA P-256 evidence

— 100% auditable proof · non-destructive execution guaranteed

How it works

Autonomous engine, human attestation

PCI-DSS and SOC 2 reject purely declarative or simulated reports. Puppet Master executes autonomous offensive emulation and compiles a digitally signed evidence dossier for certified reviewer sign-off — ensuring full regulatory standing.

01 · RoE

Rules of Engagement

Scope every account, region and technique up front. Nothing runs without an explicit, signed RoE — and offensive engines operate under strict safety boundaries.

02 · Emulate

Multi-step kill chains

The engine executes attack paths found by Ghost Mode — propagating credentials and tokens from one step to the next with verified zero-destructive-command guarantees.

03 · Prove

Auditable evidence

Every action persists the raw provider request/response, request-id, timestamp and proof of access — a reproducible chain of custody backed by SHA-256 integrity.

04 · Attest

Cryptographic Attestation & Sign-off

Dossier digitally signed with ECDSA P-256 elliptic curve and certified reviewer approval — the human gate PCI-DSS 11.4 and SOC 2 require, backed by irrefutable raw evidence.

Why Puppet Master

A pentest that survives an audit

Semantic integrity

Puppet Master never claims exploitation without proof. Each finding states exactly what happened — configuration observed, permission confirmed, or effective access proven — eliminating overstatements and false positives.

Real kill chains

Credentials obtained in one step feed the next. It proves "key in A → access to B → data in C" end to end — the essence of a pentest — instead of a pile of disconnected findings.

Audit-grade evidence

Reproducible request/response evidence with provider request-ids and complete chain of custody — the standard demanded by PCI-DSS 11.4, SOC 2 CC7 and BACEN 4893.

Controlled by design

Explicit scope by account and region, safe by default, with strict read-only command allowlists and active containment — zero risk of production downtime or data corruption.

Enterprise BAS Parity (Phase 6 Complete)

100% parity with market-leading BAS engines

Puppet Master v2 implements all 15 offensive modules across cloud, REST & GraphQL APIs, web, mobile, and host with verified non-destructive safety and undeniable raw evidence.

SSRF & Metadata Theft (Mod. K)

Active probing across AWS IMDSv1/v2, OCI, GCP, Azure and Huawei Cloud; strict credential elevation only upon genuine downstream attack chain consumption.

Active Web & API Injection (Mod. L)

Safe active proofs for REST/GraphQL APIs and web endpoints (blind SQLi/NoSQLi, BOLA, timing side-channels, path traversal) — zero destructive commands (DROP/DELETE).

Frida Mobile Hooking (Mod. M)

Automated dynamic Frida instrumentation for SSL Pinning bypass and root detection evasion on banking and enterprise mobile apps, testing runtime API integrity.

Safe Host Post-Exploitation (Mod. N)

Credential dumping (T1552) and lateral movement (T1078) governed by strict read-only command allowlists (whoami, id, netstat) — sandboxed execution without disk mutation.

SIEM & CDR Correlation (Mod. O)

Cross-validation with CloudTrail, Azure Monitor, OCI Audit, GCP Logging, and Wazuh, verifying with mathematical precision which attacks your SOC detected vs missed.

Zero Footprint & Rollback

Atomic post-execution cleanup of ephemeral credentials or artifacts, ensuring continuous pentesting never introduces residue into production environments.

Pentest FAQ

Answers about autonomous penetration testing

Everything you need to know about safety, evidence, Rules of Engagement, and regulatory audit compliance with Puppet Master.

Vulnerability scanners only enumerate static theoretical risks. Puppet Master actively validates attack paths end to end in real multi-step kill chains — proving whether a vulnerability is truly exploitable with irrefutable raw evidence, eliminating false positives.

No. Puppet Master is engineered under a strict 'Safe by Default' principle. It validates exploitability via non-destructive methods (timing side-channels, boolean inference, and read-only enumeration). Destructive commands (DROP, DELETE, mass data exfiltration, service crashes) are strictly prohibited and architecturally blocked.

Nothing runs without an explicit, cryptographically signed Rules of Engagement (RoE) contract. You strictly define target accounts, VPCs, IP ranges, domains, and allowed time windows. High-sensitivity actions require explicit Human-in-the-Loop (HITL) authorization before proceeding.

Every finding generates an EvidenceRecord containing sanitized HTTP/CLI requests, responses, provider request-IDs, and timestamps. Dossiers are sealed with SHA-256 hashes and ECDSA P-256 signatures in our Attestation Vault, allowing external auditors (PCI QSA, SOC 2, BACEN) to verify authenticity publicly via /verify.

Yes. Through the Detection-Validation layer (Module O), Puppet Master cross-references the exact timestamps and MITRE ATT&CK techniques of simulated actions with telemetry from your connected SIEM/EDR, generating an objective Detection Coverage Index (% detected vs missed).

Puppet Master covers multi-cloud infrastructure across AWS, Azure, GCP, OCI and Huawei Cloud, web and API attack vectors (OWASP Top 10, SSRF instance metadata pivots, active injection), mobile security via dynamic Frida instrumentation, and read-only host lateral movement.

Ready to see your cloud
as an attacker does? 

Book a demo and our team will walk you through Arkhein on your own cloud.