Reference workflow / Pentest consultancies and AppSec teams

Web application surface review

Turn web discovery, probing and approved scanning into a visible workflow that can be repeated for each engagement.

Workflow contract
Audience
Pentest consultancies and AppSec teams
Authorized scope
Authorized application URLs and related hostnames
Expected outcome
A traceable view of discovered endpoints, observed technologies and approved scanner results.
Approval policy
Confirm the resolved application scope and active-test policy before the workflow is approved to run.
Expected artifacts
  • Reachable target inventory
  • HTTP metadata
  • Scanner artifacts
  • Approval and execution record
Node sequence

How the workflow is composed

  1. 01
    Input

    Application targets

    Capture the approved URLs and scope notes.

  2. 02
    Tool

    HTTP discovery

    Probe hosts and collect response metadata.

  3. 03
    Script

    Scope filter

    Keep later nodes inside the declared target boundaries.

  4. 04
    Tool

    Template scan

    Run the selected scanning policy against approved targets.

  5. 05
    Output

    Result package

    Centralize artifacts and execution context.

This blueprint describes the intended orchestration pattern. A pilot confirms the exact registered tools, worker dependencies, input schema and output contract before execution.
ChaosEngine early access

Bring your current web application surface review process.

We are onboarding a focused group of security teams and helping each one translate an existing process into a governed ChaosEngine workflow.