Five testing layers, one engine.
Most tools test a single slice of your attack surface. We run the whole chain, from a line of source code to a proven root shell, and we correlate every result so nothing slips through.
Source code
Our 80+ static modules trace injection sinks, weak crypto, hardcoded secrets and unsafe patterns directly in your code.
Live web
160+ dynamic modules cover SQLi, XSS, SSRF, IDOR, XXE, auth and JWT, request smuggling, cache poisoning, GraphQL and current n-day CVEs.
Dependencies
We scan your libraries for known CVEs and map every hit to the CISA KEV, NVD, GHSA and EPSS feeds.
Server & infra
We test Ubuntu privilege escalation to root, multi-tenant isolation breakout, and hardening for nginx, SSL, databases, mail and SSH.
Secrets
We surface leaked keys, tokens and credentials across your code and build artifacts before an attacker finds them.
Proven exploitation
Our 90+ offensive modules do not stop at flagging a risk. They exploit it: login bypass, shell access, file read and write, database pivot, root. You get real proof, not a maybe.
Module coverage by layer
290+ modules spread across the five layers we run on every engagement. More than 90 of them exploit what they confirm, not just flag it.
Everything a modern pentest needs
Visual pipeline designer
We give you an n8n-style canvas to chain modules, raw commands and conditions into your own attack flow. Save it, run it, and watch each node light up live.
Correlated attack paths
We link findings across layers — a leaked credential, the login that accepts it, the database it reaches — into a single attack path instead of a list of disconnected issues.
Isolated Kali engine
We ship nuclei, sqlmap, nikto, ffuf, semgrep, grype, MobSF and around 40 more tools in a Docker sidecar. Your host stays clean and a single flag switches engines.
Live threat intelligence
We match the versions we detect against CISA KEV, NVD, GHSA and EPSS, so you see the CVEs that are actually being exploited in the wild. A Tenable Nessus bridge is built in.
Smart module selection
We detect your stack, whether it is PHP, Node, Java, Go or WordPress, and run only the modules that matter. Less noise, and faster, cleaner scans.
Learning from the real world
We build a methodology knowledge base from disclosed HackerOne reports and enrich your findings with the context real attackers use.
From target to proof in four steps
Configure
Point Koruqan at a URL or a codebase, choose a profile, and set your scope. Smart selection handles the rest.
Scan
We run the five layers in parallel with rate limiting and circuit breakers, streaming progress to you live.
Exploit and prove
Offensive modules and guided steps confirm each issue and capture concrete, reproducible proof.
Report
You get a branded HTML report plus JSON and SARIF, ready for the client and the pipeline alike.
Design your own attack flow. No code required.
Drag nodes onto the canvas and wire them together. Trigger a target, run any of our 290+ modules, drop in a raw Kali command, branch on a condition, then publish the proof.
- DAG validated: one trigger, no cycles, and safe structural conditions with no eval.
- Node output flows downstream through {{node.x}} templating.
- A per-node watchdog keeps a hung step from ever freezing your scan.
Reports your clients and your CI both trust
We produce branded HTML with a hardening plan, root-cause analysis and a scan-to-scan diff. For your pipeline, we also export machine-readable JSON and SARIF.
One workspace for the whole engagement
Every module lives in a single console — from launching a scan to triaging findings, driving exploits and shipping the report.
Overview
A live dashboard of active scans, risk grade and top findings.
New Scan
Point at a URL or codebase, pick a profile, and smart selection does the rest.
Exploit Console
Interactive, guarded exploitation with real command output and proof capture.
Findings
Triage every issue with severity, CWE, CVSS and reproducible evidence.
Threat Intel
Match detected versions against live CISA KEV, NVD, GHSA and EPSS feeds.
Semantic Search
Search findings and methodology by meaning, not just keywords.
Learning Model
A methodology knowledge base built from disclosed real-world reports.
Nessus Bridge
Pull Tenable Nessus findings straight into your correlated report.
One platform, many teams
Pentest firms
Cover more ground on every engagement and deliver proof-backed, branded reports faster.
AppSec and DevSecOps
Gate your CI/CD with SARIF and fail-on thresholds, and correlate SAST with live findings.
Hosting and VDS providers
Audit multi-tenant isolation, privilege escalation and service hardening at scale.
Bug bounty hunters
Chain modules and Kali tools into recon-to-exploit workflows you can repeat.
Frequently asked questions about Koruqan
What is Koruqan?
Koruqan is a self-hosted offensive security platform that combines source code analysis, live web testing, dependency scanning and infrastructure assessment in a single engine. It runs 290+ modules and roughly 50 Kali Linux tools across five layers of the attack surface. More than 90 of those modules do not stop at detection: they exploit what they confirm, so a result arrives as evidence rather than as a possibility. Read the full guide to self-hosted pentest platforms.
How is Koruqan different from a vulnerability scanner?
A vulnerability scanner flags what might be exploitable. Koruqan's 90+ offensive modules go further and actually exploit the finding: login bypass, shell access, file read and write, database pivot, privilege escalation to root. Each result is attached to the report as reproducible proof, which removes the false positives a scanner leaves behind.
Is Koruqan self-hosted, and where does my scan data go?
Koruqan is deployed inside your own network. Targets, scan results and proof-of-exploit artifacts never leave your infrastructure, which is why it fits regulated environments that cannot send target data to a third-party SaaS platform.
Which testing layers does Koruqan cover?
Five: source code (80+ static modules for injection sinks, weak crypto and hardcoded secrets), live web (160+ dynamic modules covering SQLi, XSS, SSRF, IDOR, XXE, auth and JWT, request smuggling, cache poisoning, GraphQL and current n-day CVEs), dependencies (CVEs mapped to CISA KEV, NVD, GHSA and EPSS), server and infrastructure (Linux privilege escalation, multi-tenant isolation breakout, nginx, SSL, database, mail and SSH hardening), and secrets (leaked keys, tokens and credentials in code and build artifacts). See the full module coverage reference.
Can Koruqan run in a CI/CD pipeline?
Yes. Alongside the branded HTML report, Koruqan exports machine-readable JSON and SARIF, so you can gate a pipeline with fail-on severity thresholds and surface findings in your existing code scanning UI. A scan-to-scan diff shows what is new and what has been fixed.
Which Kali tools are integrated into Koruqan?
Around 50 tools ship in an isolated Docker sidecar, including nuclei, sqlmap, nikto, ffuf, semgrep, grype and MobSF. The host system stays clean and a single flag switches engines.
Who is Koruqan built for?
Penetration testing firms that need broader coverage and faster proof-backed reporting, AppSec and DevSecOps teams gating CI/CD with SARIF, hosting and VDS providers auditing multi-tenant isolation and service hardening at scale, and bug bounty hunters chaining modules and Kali tools into repeatable recon-to-exploit workflows.
See Koruqan run on your own target.
We host nothing for you and your data never leaves your network. Book a live walkthrough and we will run a full scan-to-proof cycle end to end.
Tell us about your target.
Send us a note and we will set up a live walkthrough on a system you own or are authorized to test.
- destek@koruqan.com
- Self-hosted · your data stays in your network
- We reply within one business day