Start with the current operating model
Most usedPlatform Operator Guide
Daily operations for scans, findings, reports, imports, exports, and completed assessment reopening.
Pentest Suite and Interceptor
Repeater, Intruder, Scanner, Decoder, Comparer, Sequencer, Clickjacking, Collaborator, Search, WebSocket, and traffic interception.
Assessment Wizard
Module-aware wizard guidance: relevant steps, target entry, connector checks, and launch review.
Reports and Exports
How completed assessments become reportable, what formats exist, and what evidence is preserved.
Surface playbooks
Module awareWeb / DAST
Authenticated crawling, workflow replay, OOB-backed validation, business-logic reasoning, and reporting lanes.
API Security
Spec-driven endpoint planning, auth and session abuse, BOLA and mass-assignment checks, GraphQL and gRPC coverage.
SAST / Secrets / SCA / SBOM
Static analysis, secret detection, dependency analysis, SBOM output, multi-engine correlation, and scan reopening.
Cloud / K8s / IaC
Identity validation, drift posture, IAM and RBAC context, inventory, runtime visibility, and evidence capture.
Mobile
APK and IPA analysis, SSL pinning handling, runtime hooks, storage checks, and backend API validation.
Network and Identity
Service detection, AD and identity attack paths, exposed services, protocol abuse, and lateral-movement evidence.
Firmware / IoT / OT
Extraction, protocol-aware analysis, lab-safe validation, and industrial or embedded evidence workflows.
AI / LLM / Agentic AI
Prompt injection, tool misuse, RAG leakage, memory abuse, and model/runtime assurance.
Methodology, evidence, and platform truth
CorporateOperations Methodology
The corporate overview of how PhantomYerra plans, validates, scores, evidences, and reports security work across surfaces.
Evidence Chain
How requests, responses, screenshots, hashes, timestamps, and exported artifacts remain attributable and auditable.
Coverage Matrix
Current scanner and capability coverage with present-tense language instead of frozen module-count claims.
Bundled Tools and Modules
What ships in the installer, what is module-managed, and what stays catalog-only or external by design.
Support and release operations
Keep currentTroubleshooting
Sidecar startup, runtime dependencies, packaged-app issues, AI provider reachability, and scan-state recovery.
Integrations and Connectors
Repo access, cloud authentication, report delivery, CI/CD export, and system-to-system orchestration.
What's New
Release notes focused on shipped changes, operational impact, and behavior that operators should expect now.
Changelog
Version-by-version record for support, validation, and long-running customer environments.