Agentic VAPT orchestrator. Drives ~60 open-source security engines through a custom MCP server, with scope, rate limiting, sanitization, approval and audit enforced server-side on every tool call. Authorized testing only.
Assess cloud and Kubernetes posture with Cordon: external storage discovery, IAM permission mapping, Prowler posture audit, attack-path analysis, Kubescape. Use when the target runs on AWS/Azure/GCP or Kubernetes, or when asked about buckets, IAM, cloud misconfiguration, or cluster security.
Map an authorized target's attack surface with Cordon: BBOT preset selection, DNS resolution, HTTP probing, endpoint and JavaScript analysis. Use when asked to do recon, enumerate subdomains, find assets, or map attack surface.
Synthesize an Cordon engagement into a submittable report: confirmed findings with reproducible PoCs, unproven leads kept separate, scope, methodology, tool inventory, and cost. Use when asked to write up, report, or submit findings.
Run vulnerability and port scans with Cordon under the program's rate limit: Nuclei templates and workflows, naabu/nmap port and service scanning, custom rule packs. Use when asked to scan for vulnerabilities, check for CVEs, or enumerate ports and services.
Detect and verify subdomain takeovers with Cordon's three-step flow, then produce a responsible PoC. Use when checking for dangling DNS, takeover candidates, unclaimed cloud resources, or NS/MX delegation issues.
Reduce scanner false positives with Cordon's adversarial taskflow triage and canary defense. Use after a scan produces candidates, when asked to triage findings, cut noise, or decide what is worth validating.
Prove candidate findings with minimal proof-of-concept validation in Cordon, and record human-reproduced PoCs. Use when asked to validate, confirm, prove, or produce a PoC for a finding — and before writing any report.
Orchestrate an authorized VAPT engagement end to end with the Cordon MCP server: authorize, recon, expand, scan, takeover, triage, validate, report. Use when the user asks to run Cordon, hunt a bug bounty target, assess an owned domain, or continue an existing engagement.