AttackForge Connects to Everything. So You Can Focus on What Matters.
Your security tools shouldn't work in isolation. AttackForge plugs directly into ticketing, GRC, scanning, collaboration, BI, and AI systems. No middleware. No workarounds. No ripping and replacing.
150+
REST Endpoints
20+
Event Types
∞
Flow Automations
AI
MCP Ready
FLOWS - THE BUILT-IN AUTOMATION ENGINE
Automate Anything. No Middleware Required.
Flows is AttackForge's end-to-end automation engine - built directly into the platform so you can connect your offensive security data to virtually any system with an HTTP interface. You build automations inside AttackForge using a visual editor backed by AFScript, and the platform handles execution, monitoring, logging, secrets management, collaborative development, and error handling for you.
Event-Driven Triggers
20+ event types covering the full vulnerability and project lifecycle. Fire automations when findings are created, retests complete, evidence is uploaded, and more.
External HTTP Triggers
Let systems outside AttackForge initiate Flows via unique webhook URLs. Perfect for bi-directional integrations where updates in tools like Jira or ServiceNow flow back into AttackForge.
Scheduled Triggers
Run Flows on any cadence - hourly, daily, or custom. Ideal for automated compliance checks, recurring test creation, polling-driven integrations or batch-processing.
Scripting Logic
Execute custom logic with AFScript - AttackForge's own interpreted scripting language. Conditional branching, loops, pagination, error recovery, and data transformation.
HTTP Actions
Make outbound API requests to any system with an HTTP interface. Chain actions together - the output of one becomes the input of the next. Handle pre-request and post-response scripts.
Encrypted Secrets
Store credentials and script variables/parameters encrypted at rest. Flow-level and User-level secrets make rotation painless - update once, every Flow picks up the change automatically.
Some Examples For What You Can Do With Flows
- Push vulnerabilities to Jira, ServiceNow, Azure DevOps instantly
- Send pentest results to RSA Archer, MetricStream, OneTrust
- Trigger automated scanning in Rapid7, Tenable, Qualys
- Visualize data in Power BI and Tableau without CSV exports
- Pull Bug Bounty data from HackerOne and BugCrowd
- Create real-time Slack and Teams notifications
- Prioritize vulnerabilities with VulnDB threat intelligence
- Chain AttackForge APIs for complex internal workflows
Enterprise Access Controls
Control which event triggers each user can create, whether they can use authenticated or unauthenticated HTTP triggers, and visibility into shared Flows. Flow ownership can be transferred, and access levels range from Info through View, Edit, and Trigger.
Import, Export & Share
Export any Flow as a portable .flow file. Import into another instance. Share proven integrations across teams, maintain backups, and bootstrap new environments. Ready-made templates available on GitHub for common use cases.
Testing & Debugging
Every Flow run is fully logged with input data, output data, HTTP request/response details, AFScript log output, and execution timing. Manually trigger test runs, re-run previous executions, and trace every step.
SELF-SERVICE RESTful API
150+ Endpoints. OpenAPI v3. Enterprise Access Controls.
The AttackForge Self-Service RESTful API gives you complete programmatic access to your offensive security data. A fully documented, OpenAPI v3 compliant interface with over 150 endpoints covering projects, vulnerabilities, writeups, assets, test cases, users, groups, portfolios, and more.
150+ Endpoints
Full coverage of projects, vulnerabilities, writeups, assets, test cases, users, groups, portfolios, and more.
Per-Endpoint Access Control
Every endpoint is individually grantable per user. No user - including administrators - has access to any endpoint by default.
Advanced Query Filters
Construct precise, complex queries - filter by status, date range, custom fields, and asset scope. Chain conditions to pull exactly the data you need.
OpenAPI v3 Compliant
Full specification for code generation and client library support. Events-API Client libraries available in Node.js, Python, .NET, Java, and Go.
Some Examples For What You Can Build
- Custom dashboards pulling live vulnerability and project data
- Automated vulnerability ingestion pipelines from external scanners
- Bi-directional sync with CMDB, asset inventory, or ITSM platforms
- Programmatic project creation for high-volume testing operations
- Bulk operations for mass updates and compliance reporting
- Custom integrations with any HTTP-capable system
Developer Experience
- Full OpenAPI v3 specification for code generation
- CRUD REST Operations for every workflow
- Pagination support
- JSON request and response bodies throughout
- Events API Client libraries in Node.js, Python, .NET, Java, and Go
- Authentication via User API Key (X-SSAPI-KEY header)
EVENTS API
Real-Time, Event-Driven Updates
Subscribe to what matters. React instantly. The Events API delivers real-time push notifications whenever key activities happen in AttackForge.
Stop polling the REST API to check for changes. Your systems receive instant notifications the moment something happens - a vulnerability is created, a project enters retest, evidence is uploaded.
- Feed real-time notifications into your SOC or SIEM
- Trigger instant ticket creation for critical findings
- Keep dashboards updated with live testing progress
- Notify stakeholders via custom channels
- Build event-sourced architectures
Supported Event Types
- Project Created
- Project Updated
- Project Request Created
- Project Request Updated
- Project Retest Requested
- Project Retest Completed
- Project Retest Cancelled
- Project Test Case Updated
- Vulnerability Created
- Vulnerability Updated
- Vulnerability Evidence Created
- Vulnerability Evidence Updated
- Vulnerability Remediation Note Created
- Vulnerability Remediation Note Updated
- Vulnerability Remediation Note File Uploaded
- Workspace File Uploaded
- Writeup Created
- Writeup Updated
AI & MODEL CONTEXT PROTOCOL
Your Pentest Data Meets Your AI
Native support for Model Context Protocol (MCP) - the open standard that lets AI assistants securely connect to your actual data and tools.
Available MCP Tools
whoami (user identity)find_projectsfind_vulnerabilitiesfind_affected_assetsfind_writeups
What People Are Building
- Generate executive summaries from live project data
- Create AI-assisted vulnerability descriptions
- Identify highest-risk vulnerabilities across portfolios
- Build interactive CVSS dashboards and charts
- Produce OWASP Top 10 mapping reports
- Generate executive project closeout scorecards
- Review vulnerabilities in retest with AI analysis
- Query CVSS score distributions
Works With Your AI Tools
Integrates with frontier models like ChatGPT, Claude, Microsoft Copilot Studio; and open-source models like Gemma 4, Qwen, DeepSeek, Ollama and more.
Built-in OAuth v2.1
Self-registration for cloud AI assistants. Your team connects in minutes without admin intervention.
Air-Gapped Support
MCP server runs locally via npx with User API Key. Data never leaves your device - critical for classified environments and maximum data privacy and security.
Zero-Trust Access
Each MCP tool is individually enabled per user by an administrator. Full session visibility and instant revocation.
Vendor Independence
Open standard means workflows aren't locked to any single AI provider. Build once, switch between Claude, ChatGPT, Copilot, or self-hosted models.
NATIVE TOOL INTEGRATIONS
Import and Export Without Friction
AttackForge integrates natively with the tools your teams already use. No custom development needed for common workflows.
Vulnerability Scanners
- Nessus (Tenable)
- Burp Suite (PortSwigger)
- Qualys
Import findings directly from your favourite scanners. CSV and JSON imports for ad-hoc scripts and tools. Self-Service API supports any source that produces structured data.
Ticketing & DevOps
- Atlassian Jira
- ServiceNow
- Azure DevOps
Bi-directional sync - create tickets automatically when vulnerabilities are discovered, receive updates when tickets are resolved.
Collaboration
- Slack
- Microsoft Teams
Real-time notifications and structured messages. Alert channels on critical findings, send progress summaries, trigger SLA notifications.
GRC & Risk
- RSA Archer
- MetricStream
- OneTrust
- LogicGate
Feed live vulnerability data to your GRC team - no more stale spreadsheets exported weeks after testing concludes.
Scanning & Vulnerability Management
- Rapid7
- Tenable
- Qualys
Trigger automated scans from AttackForge events. Create closed-loop workflows where AttackForge triggers scans and receives results.
Business Intelligence
- Power BI
- Tableau
Build executive dashboards that update automatically as testing progresses - no manual data extraction or transformation.
Bug Bounty
- HackerOne
- BugCrowd
Consolidate all vulnerability sources - internal pentests, automated scans, and bug bounty findings - into a single platform.
Threat Intelligence
- VulnDB
- Custom Feeds
Enrich vulnerability data with threat intelligence. Automatically prioritize findings based on active exploitation data.
AFSCRIPT
The Scripting Language Behind It All
AFScript is AttackForge's own interpreted programming language, purpose-built to power Flows and advanced customizations throughout the platform. It handles the logic, data transformation, conditional branching, and string manipulation that makes sophisticated automations possible without leaving AttackForge.
Flow Request & Response Scripts
Format vulnerability data for external API payloads, parse responses, make routing decisions, handle pagination, and implement retry logic.
Conditional Logic & Error Handling
Build complex multi-step sequences with conditional branching, loops, error recovery, and context passing between actions.
Custom Field Defaults
Dynamically compute suggested values for custom fields based on other data in the platform.
Built-In Debugging
Includes logging for debugging, supports encrypted Secrets for secure credential handling, and is continuously expanding with new capabilities.
SECURITY & ACCESS CONTROLS
Integration Without Security Compromise
AttackForge doesn't trade security for connectivity. Every integration mechanism has its own independently configurable access control layer.
RESTful API
Each of the 150+ endpoints individually grantable per user.
Events API
Subscription access to each event type controlled per user.
Flows
Administrators control trigger types per user. Flow sharing has four distinct access levels.
MCP
Each tool individually enabled per user. Full session visibility and revocation for administrators.
Every event, trigger, action, endpoint, and MCP tool includes configurable access.
All API traffic runs over HTTPS.
Secrets encrypted at rest, referenceable without exposing values and painless rotation.
Build your own APIs and publish unique routes for your external tools and scripts.
Configurable header redaction to prevent credential leakage in logs.
OAuth v2.1 secures MCP authentication.
See What Your Offensive Security Program Looks Like When Every Tool Works Together.
AttackForge deploys instantly with a free trial - no credit card required. Every integration capability on this page is available out of the box.
Explore the Self-Service API documentation. Import a pre-built Flow from GitHub. Connect your AI assistant via MCP.