forumNew topic

Someone mentioned a tool called "Pentest GPT" — does anyone actually use this on pentests we've quoted?

HHüsniye D***Member
Job title
Customer Relations Manager
Sector
Law
Organization type
family business
Joined
Jul 2024
Message
384
#1

We're a 12-person fintech team developing microloan scoring software. Before going live next month, we got quotes from three cybersecurity firms for an independent penetration test. Prices range between 45,000 TL and 130,000 TL.

During our discovery call with the lowest bidder, a junior engineer mentioned that they leverage AI-based automation tools like Pentest GPT during the process, which allows them to cut operational costs significantly. I'd never heard the term before.

What exactly is Pentest GPT, and is using it standard practice in professional penetration testing? I'm worried about whether they're feeding snippets of our open-source code or vulnerability data from our cloud infrastructure into an external AI model. How should we vet this when reviewing proposals and drafting contracts?

UUfuk S***Member
Job title
Front office accounting
Sector
Agriculture
Organization type
cooperative
Joined
Jun 2022
Message
74

Doki · Incident response support · 2025

Most Helpful#2

Short answer: Pentest GPT is an open-source AI tool that helps penetration testers plan vulnerability scanning steps via the command line, analyze findings, and guide the test flow. It doesn't run an autonomous pentest on its own; it acts as an interactive assistant that speeds up an engineer's workflow.

The critical distinction here is how the tool is positioned. If a firm offloads the testing process entirely to this tool and simply copy-pastes the output into a report, that engagement will miss manual logic flaws and business logic vulnerabilities. Furthermore, tools like this rely on external LLM API services in the background. During testing, your server IP addresses, internal directory structures, API endpoints, or error outputs may be sent to these API endpoints. Unless the firm uses a dedicated enterprise API tier with strict data retention commitments, your vulnerability data could be processed on third-party servers.

When reviewing proposals, clarify three key points: Ask whether the scope includes dedicated manual testing hours aligned with international standards (such as the OWASP methodology). Write a clause into the contract specifying that no data, logs, or code snippets obtained during testing may be transmitted to third-party public AI models or public cloud services. A noticeably low bid like 45,000 TL usually means you're getting a superficial automated scan and summary rather than an in-depth scenario analysis.

BBurcu A***Member
Job title
IT Manager
Sector
Automotive aftermarket
Organization type
workshop
Joined
Jun 2024
Message
49
#3

The tool is essentially a prompt-chaining wrapper that parses network or vulnerability scan outputs fed by the tester and suggests which tool to run next. It queries a public AI model under the hood. Copy-pasting that output straight into a report is guaranteed to miss business logic vulnerabilities.

MMustafa Ç***Member
Job title
Clinic manager
Sector
Glass
Organization type
two-branch business
Joined
Oct 2022
Message
49
#4

Did the low-bid firm agree to sign a confidentiality and data retention protocol? If they can't provide a technical guarantee that test data won't hit public servers, is that a risk worth taking for software running financial credit scoring?

NNuri Y***ExpertCommunity member
Joined
Oct 2023
Message
246
#5

We had a similar automation-heavy pentest done last year in the 50,000 TL range. Nearly eighty percent of the report was standard automated scanner output, and they completely missed a critical privilege escalation flaw in our payment flow. When we later paid 110,000 TL for proper manual testing, the real vulnerabilities surfaced.

CCeren A***Expert
Job title
Brand Manager
Organization type
chain store
Joined
Aug 2023
Message
154
#6

In this industry, "we cut costs" usually translates to "we dumped the work on an intern who's feeding commands into a tool." AI is great as a supplementary tool, but if they're pitching it as a cost advantage, they're skimping on expert manual effort.

İİsmetMember
Job title
Logistics Manager
Joined
Nov 2023
Message
112
#7

Speak with the firm again and require them to include manual verification evidence for every single finding in the report. Make it clear upfront that you will not accept a list of hypothetical vulnerabilities spit out by a tool.

HHasan S***MemberCommunity member
Joined
Jan 2024
Message
114
#8

we set up that tool to try it out too, it shows basic commands but completely misses logic flaws like authorization checks but definitely cant be trusted on its own for a finance project, be sure to put an ai restriction in the contract.

FFerhat E***Expert
Job title
Production Manager
Sector
Real estate
Organization type
40-person manufacturing company
Joined
Aug 2023
Message
128

Doki · Infrastructure migration · 2024

#9

In accordance with the regulations governing institutions that process financial data, the uncontrolled transfer of internal network and customer data collected during testing processes to overseas cloud services may result in regulatory violations. It is recommended that you request a written data flow diagram from your service provider.

HHakan G***Member
Job title
Purchasing manager
Sector
Seafood
Organization type
300-person organization
Joined
Oct 2024
Message
185
#10

there are three things to check when doing this... if permission and scope arent in writing dont strt that test.

correct me if Im wrong.

EElif D***MemberCommunity member
Joined
Oct 2024
Message
98
#11

Thanks a lot, I'll try it today.

ZZerrin T***Member
Job title
Export manager
Sector
Law
Organization type
boutique agency
Joined
Mar 2024
Message
3
#12

I didn't know that.

TTuğçe K***Member
Job title
Warehouse Manager
Sector
Media and publishing
Organization type
40-person manufacturing company
Joined
Jan 2022
Message
5

Doki · Log management setup · 2024

#13

Here's how it went for us. If permission and scope aren't in writing, don't start that test.

That's all, sorry if I went on too long.

AAycan D***MemberCommunity member
Joined
Oct 2024
Message
240
#14

My perspective changed after experiencing that. Most incidents start with a leaked password, not a vulnerability.

PPınar G***MemberCommunity member
Joined
Jul 2024
Message
37
#15

The answer above hits the nail on the head. Most incidents start with a leaked password, not a vulnerability.

UUğur D***Member
Job title
Data entry clerk
Sector
Healthcare services
Organization type
sole proprietorship
Joined
Jan 2022
Message
2
#16

This thread is archived.

MMurat Ö***Member
Job title
Social media manager
Sector
Software
Organization type
cooperative
Joined
Mar 2025
Message
14
#17

Good call starting this thread. Trying to do this alone is the most expensive way.

If I were you, Id go this route.

EElif A***MemberCommunity member
Joined
Feb 2023
Message
81
#18

I'm curious too.

MMerve Ö***Expert
Job title
Technical service technician
Sector
Retail
Organization type
workshop
Joined
Oct 2022
Message
142
#19

There's a trap here, let me mention it. When we decide without measuring, we always end up in the same place.

BBurcu E***Member
Job title
Administrative manager
Sector
Real estate
Organization type
40-person manufacturing company
Joined
Feb 2023
Message
37
#20

Saved.

Reply