Start Here
5 articlesFirst Launch
Activate your license, configure AI, and run your first scan — zero to operational in minutes.
Quick-Start Guide
A guided walkthrough of your first end-to-end pentest with evidence capture and reports.
Scan Modes
Understand Automated AI, Semi-Automated, and Manual modes — and when to use each.
Mission Control Wizard
Configure scope, authentication, and engagement type through the guided wizard.
Home Screen Tour
Every element of the PhantomYerra home screen and what it does.
Attack Surface Playbooks
12 playbooksWeb Applications
SQLi, XSS, CSRF, SSRF, SSTI, XXE, request smuggling, cache poisoning + full OWASP Top 10 coverage.
API / GraphQL
BOLA, BFLA, mass assignment, rate-limit bypass, OpenAPI fuzzing, GraphQL introspection abuse.
Network / Infrastructure
Nmap, service enum, SMB/Kerberos attacks, SNMP, DNS recon, TLS analysis.
Cloud Security
AWS/Azure/GCP IAM privilege escalation, S3 takeover, IMDS SSRF, misconfig drift.
Mobile (Android / iOS)
APK static + dynamic analysis, DEX bytecode, intent fuzzing, WebView bridge abuse.
Firmware / IoT
Binwalk extraction, signature detection, UART/JTAG probing, insecure update mechanisms.
Automotive / ICS-SCADA
CAN bus injection, Modbus/DNP3/BACnet abuse, PLC logic injection, HMI auth bypass.
SAST · DAST · SBOM
Interprocedural taint, symbolic execution, coverage-guided fuzzing, CycloneDX generation.
SCA / Reachability
Dependency CVE mapping, reachability analysis, supply-chain scan.
Reverse Engineering
PE/ELF/Mach-O analysis, .NET decompilation, symbolic execution, AI-assisted deobfuscation.
AI / LLM Security
Prompt injection, jailbreak testing, RAG poisoning, model inversion, OWASP LLM Top 10 2025.
DevOps / CI/CD
Secret scanning, pipeline injection, IaC misconfig, container scanning, OWASP CI/CD Top 10.
Core Technology
6 deep-divesAdaptive Attack Loop
The 8-level feedback loop that rewrites payloads based on target response — WAF-aware, context-aware.
Zero-Day Workflow
11-engine zero-day suite — taint flow, race conditions, crypto oracles, deserialization gadgets.
Exploitation Gate
How findings are validated before they reach the report — no unconfirmed claims, ever.
Business Logic Testing
Price tampering, race conditions, workflow bypass, IDOR / BOLA / BFLA — where scanners miss.
Multi-Role IDOR
Test object-level authorization across every user role automatically.
Full Attack Methodology
The complete PhantomYerra methodology — from recon to reporting, with evidence chain.
Platform Features
10 featuresAsk PhantomYerra (AI Pentester)
The AI pentester assistant — natural-language scope configuration + live scope expansion.
AI Provider Setup
Configure Anthropic / OpenAI / Google / Groq / Together / Azure Copilot / Ollama / LM Studio.
Reports & Evidence
Generate PDF / DOCX / HTML / JSON / SARIF reports with RFC 3161-sealed evidence chain.
Integrations
Jira, ServiceNow, Slack, Teams, GitHub, GitLab, Azure DevOps — bi-directional ticketing.
Enterprise RBAC
Super-admin, pentest lead, tester, reviewer, client — role-based access control.
Air-Gapped Mode
Zero external calls, local Ollama / LM Studio for classified and sensitive environments.
Local-Only Scanning
Restrict scans to internal / RFC1918 targets only — enforced at license level.
Pause & Resume
Interrupt long-running scans, resume where you left off — state survives crashes.
CLI Reference
Full command-line reference for headless scanning, CI/CD automation, scripted runs.
License Activation
Activate your license, manage seats, view module entitlements, understand quotas.
Manual Pentest Toolkit
4 toolsToolkit Overview
All in-app manual tools — when to use each, how they integrate with the scan flow.
Interceptor
Live-edit requests, modify headers, tamper with bodies, observe responses in real time.
Repeater
Replay requests with tweaks. Your hypothesis-testing workspace.
Intruder
Payload-set attacks — BOLA enumeration, login brute, fuzz lists against chosen positions.
Advanced & SDK
4 articlesRed-Team Intel Feeds
Live threat intel from CISA KEV, MITRE ATT&CK, EPSS, 15+ vendor feeds.
SDK Overview
Extend PhantomYerra — custom scanners, payloads, report templates.
Build a Custom Scanner
Author a new scanner that plugs into the orchestrator + reports.
Custom Report Template
Brand the PDF / DOCX output with your own template.