Documentation · Guides · Methodology

Everything you need to run PhantomYerra.

Step-by-step guides for first launch, scan modes, every attack surface, integrations, troubleshooting, and the complete attack methodology — from zero to operational pentest in minutes.

53
Guides & How-tos
25
Attack Surfaces
87+
Security Engines
8
AI Providers

Start Here

5 articles
🚀

First Launch

Activate your license, configure AI, and run your first scan — zero to operational in minutes.

Quick-Start Guide

A guided walkthrough of your first end-to-end pentest with evidence capture and reports.

Scan Modes

Understand Automated AI, Semi-Automated, and Manual modes — and when to use each.

🎯

Mission Control Wizard

Configure scope, authentication, and engagement type through the guided wizard.

🏠

Home Screen Tour

Every element of the PhantomYerra home screen and what it does.

Attack Surface Playbooks

12 playbooks
🌐

Web Applications

SQLi, XSS, CSRF, SSRF, SSTI, XXE, request smuggling, cache poisoning + full OWASP Top 10 coverage.

🔌

API / GraphQL

BOLA, BFLA, mass assignment, rate-limit bypass, OpenAPI fuzzing, GraphQL introspection abuse.

🔗

Network / Infrastructure

Nmap, service enum, SMB/Kerberos attacks, SNMP, DNS recon, TLS analysis.

Cloud Security

AWS/Azure/GCP IAM privilege escalation, S3 takeover, IMDS SSRF, misconfig drift.

📱

Mobile (Android / iOS)

APK static + dynamic analysis, DEX bytecode, intent fuzzing, WebView bridge abuse.

🔧

Firmware / IoT

Binwalk extraction, signature detection, UART/JTAG probing, insecure update mechanisms.

🚗

Automotive / ICS-SCADA

CAN bus injection, Modbus/DNP3/BACnet abuse, PLC logic injection, HMI auth bypass.

🔍

SAST · DAST · SBOM

Interprocedural taint, symbolic execution, coverage-guided fuzzing, CycloneDX generation.

📦

SCA / Reachability

Dependency CVE mapping, reachability analysis, supply-chain scan.

Reverse Engineering

PE/ELF/Mach-O analysis, .NET decompilation, symbolic execution, AI-assisted deobfuscation.

🤖

AI / LLM Security

Prompt injection, jailbreak testing, RAG poisoning, model inversion, OWASP LLM Top 10 2025.

DevOps / CI/CD

Secret scanning, pipeline injection, IaC misconfig, container scanning, OWASP CI/CD Top 10.

Core Technology

6 deep-dives

Adaptive Attack Loop

The 8-level feedback loop that rewrites payloads based on target response — WAF-aware, context-aware.

🕳

Zero-Day Workflow

11-engine zero-day suite — taint flow, race conditions, crypto oracles, deserialization gadgets.

🎯

Exploitation Gate

How findings are validated before they reach the report — no unconfirmed claims, ever.

🧠

Business Logic Testing

Price tampering, race conditions, workflow bypass, IDOR / BOLA / BFLA — where scanners miss.

👥

Multi-Role IDOR

Test object-level authorization across every user role automatically.

📋

Full Attack Methodology

The complete PhantomYerra methodology — from recon to reporting, with evidence chain.

Platform Features

10 features
🤖

Ask PhantomYerra (AI Pentester)

The AI pentester assistant — natural-language scope configuration + live scope expansion.

🔑

AI Provider Setup

Configure Anthropic / OpenAI / Google / Groq / Together / Azure Copilot / Ollama / LM Studio.

📄

Reports & Evidence

Generate PDF / DOCX / HTML / JSON / SARIF reports with RFC 3161-sealed evidence chain.

🔌

Integrations

Jira, ServiceNow, Slack, Teams, GitHub, GitLab, Azure DevOps — bi-directional ticketing.

🛡

Enterprise RBAC

Super-admin, pentest lead, tester, reviewer, client — role-based access control.

🔒

Air-Gapped Mode

Zero external calls, local Ollama / LM Studio for classified and sensitive environments.

🏠

Local-Only Scanning

Restrict scans to internal / RFC1918 targets only — enforced at license level.

Pause & Resume

Interrupt long-running scans, resume where you left off — state survives crashes.

CLI Reference

Full command-line reference for headless scanning, CI/CD automation, scripted runs.

📜

License Activation

Activate your license, manage seats, view module entitlements, understand quotas.

Manual Pentest Toolkit

4 tools
🧰

Toolkit Overview

All in-app manual tools — when to use each, how they integrate with the scan flow.

🎯

Interceptor

Live-edit requests, modify headers, tamper with bodies, observe responses in real time.

🔁

Repeater

Replay requests with tweaks. Your hypothesis-testing workspace.

💥

Intruder

Payload-set attacks — BOLA enumeration, login brute, fuzz lists against chosen positions.

Advanced & SDK

4 articles
🎭

Red-Team Intel Feeds

Live threat intel from CISA KEV, MITRE ATT&CK, EPSS, 15+ vendor feeds.

🧩

SDK Overview

Extend PhantomYerra — custom scanners, payloads, report templates.

🔨

Build a Custom Scanner

Author a new scanner that plugs into the orchestrator + reports.

📐

Custom Report Template

Brand the PDF / DOCX output with your own template.

Release Notes & What's New

live

What's New in PhantomYerra

Full version history — new capabilities, fixes, performance improvements. Updated with every release.

📜

Version History (marketing)

Timeline of every public release on the marketing site.