Complete AI Training
Sign inGet my AI kit

Your job's AI kit

Get your AI kit

Tell us who you are and what you do. We show you your kit right away and email you the link: skills, prompts, AI agents, MCP servers and courses for your job.

500+ jobs ready, and we make a kit for any other job. No payment needed to look.

Share

AI agent for penetration testers

Engagement Evidence Log Agent

An evidence log with a timeline where every finding has reproducible proof

Engagement Evidence Log Agent: what goes in, what the agent does and what you get

What it does

At the end of a two-week test, the tester has command history in one place, screenshots in another and notes in a third, and the report needs proof for every finding. During the test, this agent collects tool output, screenshots and commands as they are made. It stamps each with time and target, and links it to the finding it supports. It builds the engagement timeline automatically. At each check point it tests whether every finding has evidence that someone else could reproduce: the command, the output and a screenshot. Findings lacking proof are put on a list so the tester can capture it while the access still exists. The tester approves the log. Edge case: output that contains client credentials is masked in the log, with the original kept in a protected folder.

How it works

Follow the arrows from top to bottom. The orange dashed arrow is the loop: when a check fails, the agent goes back and tries again.

Start and resultWhat it doesA check on its own workWaits for your OKGoes back and retries
Yes, continueYes, continueApprovedNoNo 1 STARTS WHEN Engagement begins 2 USES A TOOL Collect tool output, commands and screenshots asthey are created 3 DOES Timestamp each item and tag its target 4 DOES Link each item to the finding it supports 5 USES A TOOL Mask credentials and sensitive data in the workinglog 6 CHECKS THE RESULT Does every finding have a command, output andscreenshot? If not: list the missing proof for the tester tocapture. Back to step 3. 7 CHECKS THE RESULT Are all timestamps inside the authorized testwindow? If not: flag the entry for review. Back to step 2. 8 DOES Build the timeline from the log 9 YOU APPROVE Tester approves the evidence log 10 RESULT Evidence log and timeline
Read the steps as a list
  1. Engagement begins
  2. Collect tool output, commands and screenshots as they are created
  3. Timestamp each item and tag its target
  4. Link each item to the finding it supports
  5. Mask credentials and sensitive data in the working log
  6. Does every finding have a command, output and screenshot?If not: list the missing proof for the tester to capture. Back to step 3.
  7. Are all timestamps inside the authorized test window?If not: flag the entry for review. Back to step 2.
  8. Build the timeline from the log
  9. Tester approves the evidence logThe agent waits here for your OK.
  10. Evidence log and timeline

How it decides

A finding is documented when it has a command, output and screenshot, with timestamps inside the test window. Missing pieces go on a to-do list.

  • Require command, output and screenshot for every finding
  • Mask passwords, keys and personal data in the working log
  • Flag any entry outside the authorized window
  • Link items by target and time when no tag exists

Make it yours

Every agent is a starting point. You choose these settings for your own situation.

  • Evidence required per finding
  • Masking rules
  • Test window dates and hours
  • Where logs and screenshots are stored

What keeps you in control

It always asks you first

  • The final evidence log and timeline

Hard limits

  • Stores unmasked client secrets only in the protected folder
  • Never alters original tool output

It stops when

  • Done: every finding has complete proof
  • Stop: the capture folder is unavailable

Set it up

We guide you through the set-up, step by step

Members get the full set-up guide for this agent. No technical skills needed: you copy, paste and upload.

10 minto set it up in your AI
5 AIsChatGPT, Claude, Copilot, Gemini, Grok
  • One set of instructions to paste into your AI, with the clicks for ChatGPT, Claude, Microsoft 365 Copilot, Gemini and Grok
  • The agent then walks you through connecting your own data, one source at a time
  • A downloadable copy with the flow chart, the rules and the full guide
Get access to this agent

An example run

What happensOn day 8, the daily check found 3 of 17 findings had no screenshot, and one command entry was timestamped after the signed window ended at 18:00. The agent listed the missing proof for the tester. The tester captured 2 screenshots the next morning, and the third was linked from an earlier session. The late entry was explained and approved. The final timeline covered 10 days.

More agents for penetration testers