SOKOL Scanner - Evidence-led cybersecurity audits and pentesting
by•
SOKOL Scanner is a lightweight, AI-assisted cybersecurity platform built for small businesses and security teams. It helps users assess their own websites, APIs, servers, networks, cloud and e-commerce systems from one workspace. SOKOL Agent continuously expands its verified RAG knowledge base, explains risks in plain language, turns scanner signals into reproducible evidence, prioritizes findings, and supports reporting and retesting.

Replies
Hi Product Hunt!
I’m Zhenya, the builder behind SOKOL Scanner—an AI-assisted, all-in-one cybersecurity workspace designed for small businesses, developers and security teams.
Instead of requiring separate applications for network scanning, web and API assessment, HTTP traffic inspection, CVE research, evidence management and reporting, SOKOL brings these workflows together in one connected environment.
The platform can analyze networks, ports, services, TLS, DNS, websites, directories, CMS platforms, REST and GraphQL APIs, sessions, cookies, JWT, SSO/OIDC, HTTP/2, WebSockets and PCAP traffic. It also includes an Interceptor, Repeater, Intruder, Decoder, Comparer, Sequencer, scope management, a findings vault, retesting workflows and report generation.
At the center of the platform is SOKOL Agent. It analyzes results from different modules, explains risks in plain language, recommends next steps and converts scanner signals into validation plans. The agent expands its knowledge from trusted cybersecurity sources, uses persistent memory and RAG, and can work with local Ollama models, OpenAI, Anthropic or in an offline mode.
SOKOL can reduce the need for many separate tools in everyday security work because targets, scope, requests, results, evidence, recommendations, retesting and reports remain connected inside one system.
Our goal is to make the application lightweight and understandable enough for small businesses to assess their own websites and servers while retaining professional capabilities for security specialists.
I’d love to hear your feedback: which security tools or workflows would you most like to have combined in one platform?