AttackForge Connects to Everything. So You Can Focus on What Matters.

Your security tools shouldn't work in isolation. AttackForge plugs directly into ticketing, GRC, scanning, collaboration, BI, and AI systems. No middleware. No workarounds. No ripping and replacing.

150+

REST Endpoints

20+

Event Types

Flow Automations

AI

MCP Ready


FLOWS - THE BUILT-IN AUTOMATION ENGINE

Automate Anything. No Middleware Required.

Flows is AttackForge's end-to-end automation engine - built directly into the platform so you can connect your offensive security data to virtually any system with an HTTP interface. You build automations inside AttackForge using a visual editor backed by AFScript, and the platform handles execution, monitoring, logging, secrets management, collaborative development, and error handling for you.

Event-Driven Triggers

20+ event types covering the full vulnerability and project lifecycle. Fire automations when findings are created, retests complete, evidence is uploaded, and more.

External HTTP Triggers

Let systems outside AttackForge initiate Flows via unique webhook URLs. Perfect for bi-directional integrations where updates in tools like Jira or ServiceNow flow back into AttackForge.

Scheduled Triggers

Run Flows on any cadence - hourly, daily, or custom. Ideal for automated compliance checks, recurring test creation, polling-driven integrations or batch-processing.

Scripting Logic

Execute custom logic with AFScript - AttackForge's own interpreted scripting language. Conditional branching, loops, pagination, error recovery, and data transformation.

HTTP Actions

Make outbound API requests to any system with an HTTP interface. Chain actions together - the output of one becomes the input of the next. Handle pre-request and post-response scripts.

Encrypted Secrets

Store credentials and script variables/parameters encrypted at rest. Flow-level and User-level secrets make rotation painless - update once, every Flow picks up the change automatically.

Some Examples For What You Can Do With Flows

  • Push vulnerabilities to Jira, ServiceNow, Azure DevOps instantly
  • Send pentest results to RSA Archer, MetricStream, OneTrust
  • Trigger automated scanning in Rapid7, Tenable, Qualys
  • Visualize data in Power BI and Tableau without CSV exports
  • Pull Bug Bounty data from HackerOne and BugCrowd
  • Create real-time Slack and Teams notifications
  • Prioritize vulnerabilities with VulnDB threat intelligence
  • Chain AttackForge APIs for complex internal workflows

Enterprise Access Controls

Control which event triggers each user can create, whether they can use authenticated or unauthenticated HTTP triggers, and visibility into shared Flows. Flow ownership can be transferred, and access levels range from Info through View, Edit, and Trigger.

Import, Export & Share

Export any Flow as a portable .flow file. Import into another instance. Share proven integrations across teams, maintain backups, and bootstrap new environments. Ready-made templates available on GitHub for common use cases.

Testing & Debugging

Every Flow run is fully logged with input data, output data, HTTP request/response details, AFScript log output, and execution timing. Manually trigger test runs, re-run previous executions, and trace every step.


SELF-SERVICE RESTful API

150+ Endpoints. OpenAPI v3. Enterprise Access Controls.

The AttackForge Self-Service RESTful API gives you complete programmatic access to your offensive security data. A fully documented, OpenAPI v3 compliant interface with over 150 endpoints covering projects, vulnerabilities, writeups, assets, test cases, users, groups, portfolios, and more.

150+ Endpoints

Full coverage of projects, vulnerabilities, writeups, assets, test cases, users, groups, portfolios, and more.

Per-Endpoint Access Control

Every endpoint is individually grantable per user. No user - including administrators - has access to any endpoint by default.

Advanced Query Filters

Construct precise, complex queries - filter by status, date range, custom fields, and asset scope. Chain conditions to pull exactly the data you need.

OpenAPI v3 Compliant

Full specification for code generation and client library support. Events-API Client libraries available in Node.js, Python, .NET, Java, and Go.

Some Examples For What You Can Build

  • Custom dashboards pulling live vulnerability and project data
  • Automated vulnerability ingestion pipelines from external scanners
  • Bi-directional sync with CMDB, asset inventory, or ITSM platforms
  • Programmatic project creation for high-volume testing operations
  • Bulk operations for mass updates and compliance reporting
  • Custom integrations with any HTTP-capable system

Developer Experience

  • Full OpenAPI v3 specification for code generation
  • CRUD REST Operations for every workflow
  • Pagination support
  • JSON request and response bodies throughout
  • Events API Client libraries in Node.js, Python, .NET, Java, and Go
  • Authentication via User API Key (X-SSAPI-KEY header)

EVENTS API

Real-Time, Event-Driven Updates

Subscribe to what matters. React instantly. The Events API delivers real-time push notifications whenever key activities happen in AttackForge.

Stop polling the REST API to check for changes. Your systems receive instant notifications the moment something happens - a vulnerability is created, a project enters retest, evidence is uploaded.

  • Feed real-time notifications into your SOC or SIEM
  • Trigger instant ticket creation for critical findings
  • Keep dashboards updated with live testing progress
  • Notify stakeholders via custom channels
  • Build event-sourced architectures

Supported Event Types

  • Project Created
  • Project Updated
  • Project Request Created
  • Project Request Updated
  • Project Retest Requested
  • Project Retest Completed
  • Project Retest Cancelled
  • Project Test Case Updated
  • Vulnerability Created
  • Vulnerability Updated
  • Vulnerability Evidence Created
  • Vulnerability Evidence Updated
  • Vulnerability Remediation Note Created
  • Vulnerability Remediation Note Updated
  • Vulnerability Remediation Note File Uploaded
  • Workspace File Uploaded
  • Writeup Created
  • Writeup Updated

AI & MODEL CONTEXT PROTOCOL

Your Pentest Data Meets Your AI

Native support for Model Context Protocol (MCP) - the open standard that lets AI assistants securely connect to your actual data and tools.

Available MCP Tools

  • whoami (user identity)
  • find_projects
  • find_vulnerabilities
  • find_affected_assets
  • find_writeups

What People Are Building

  • Generate executive summaries from live project data
  • Create AI-assisted vulnerability descriptions
  • Identify highest-risk vulnerabilities across portfolios
  • Build interactive CVSS dashboards and charts
  • Produce OWASP Top 10 mapping reports
  • Generate executive project closeout scorecards
  • Review vulnerabilities in retest with AI analysis
  • Query CVSS score distributions

Works With Your AI Tools

Integrates with frontier models like ChatGPT, Claude, Microsoft Copilot Studio; and open-source models like Gemma 4, Qwen, DeepSeek, Ollama and more.

Built-in OAuth v2.1

Self-registration for cloud AI assistants. Your team connects in minutes without admin intervention.

Air-Gapped Support

MCP server runs locally via npx with User API Key. Data never leaves your device - critical for classified environments and maximum data privacy and security.

Zero-Trust Access

Each MCP tool is individually enabled per user by an administrator. Full session visibility and instant revocation.

Vendor Independence

Open standard means workflows aren't locked to any single AI provider. Build once, switch between Claude, ChatGPT, Copilot, or self-hosted models.


NATIVE TOOL INTEGRATIONS

Import and Export Without Friction

AttackForge integrates natively with the tools your teams already use. No custom development needed for common workflows.

Vulnerability Scanners

  • Nessus (Tenable)
  • Burp Suite (PortSwigger)
  • Qualys

Import findings directly from your favourite scanners. CSV and JSON imports for ad-hoc scripts and tools. Self-Service API supports any source that produces structured data.

Ticketing & DevOps

  • Atlassian Jira
  • ServiceNow
  • Azure DevOps

Bi-directional sync - create tickets automatically when vulnerabilities are discovered, receive updates when tickets are resolved.

Collaboration

  • Slack
  • Microsoft Teams

Real-time notifications and structured messages. Alert channels on critical findings, send progress summaries, trigger SLA notifications.

GRC & Risk

  • RSA Archer
  • MetricStream
  • OneTrust
  • LogicGate

Feed live vulnerability data to your GRC team - no more stale spreadsheets exported weeks after testing concludes.

Scanning & Vulnerability Management

  • Rapid7
  • Tenable
  • Qualys

Trigger automated scans from AttackForge events. Create closed-loop workflows where AttackForge triggers scans and receives results.

Business Intelligence

  • Power BI
  • Tableau

Build executive dashboards that update automatically as testing progresses - no manual data extraction or transformation.

Bug Bounty

  • HackerOne
  • BugCrowd

Consolidate all vulnerability sources - internal pentests, automated scans, and bug bounty findings - into a single platform.

Threat Intelligence

  • VulnDB
  • Custom Feeds

Enrich vulnerability data with threat intelligence. Automatically prioritize findings based on active exploitation data.


AFSCRIPT

The Scripting Language Behind It All

AFScript is AttackForge's own interpreted programming language, purpose-built to power Flows and advanced customizations throughout the platform. It handles the logic, data transformation, conditional branching, and string manipulation that makes sophisticated automations possible without leaving AttackForge.

Flow Request & Response Scripts

Format vulnerability data for external API payloads, parse responses, make routing decisions, handle pagination, and implement retry logic.

Conditional Logic & Error Handling

Build complex multi-step sequences with conditional branching, loops, error recovery, and context passing between actions.

Custom Field Defaults

Dynamically compute suggested values for custom fields based on other data in the platform.

Built-In Debugging

Includes logging for debugging, supports encrypted Secrets for secure credential handling, and is continuously expanding with new capabilities.


SECURITY & ACCESS CONTROLS

Integration Without Security Compromise

AttackForge doesn't trade security for connectivity. Every integration mechanism has its own independently configurable access control layer.

RESTful API

Each of the 150+ endpoints individually grantable per user.

Events API

Subscription access to each event type controlled per user.

Flows

Administrators control trigger types per user. Flow sharing has four distinct access levels.

MCP

Each tool individually enabled per user. Full session visibility and revocation for administrators.

Every event, trigger, action, endpoint, and MCP tool includes configurable access.

All API traffic runs over HTTPS.

Secrets encrypted at rest, referenceable without exposing values and painless rotation.

Build your own APIs and publish unique routes for your external tools and scripts.

Configurable header redaction to prevent credential leakage in logs.

OAuth v2.1 secures MCP authentication.


See What Your Offensive Security Program Looks Like When Every Tool Works Together.

AttackForge deploys instantly with a free trial - no credit card required. Every integration capability on this page is available out of the box.

Explore the Self-Service API documentation. Import a pre-built Flow from GitHub. Connect your AI assistant via MCP.