Software
Breachwright
Get in Touch

Open-source pentest management

Advent Cybersecurity created Breachwright to bring evidence, findings, retests, attack paths, and reporting into one operator workflow. Version 2.4.1 is available under Apache License 2.0 with the same complete feature set on Windows and Linux.

Breachwright v2.4.1Open source
01Import scans and evidence
02Create a versioned snapshot
03Review changes and retests
04Check readiness and report

Built around how pentests are delivered.

Breachwright is not another scanner. It is the operating layer around your evidence, analysis, reporting, and client delivery.

Compare assessments over time

Create versioned scan snapshots and classify observations as new, persistent, resolved, or regressed during a retest.

Keep evidence and judgment together

Track finding history, evidence, due dates, methodology coverage, attack paths, and report readiness in one local workspace.

Use AI only when you choose

Draft findings and narratives with a provider you control, review every proposal, or use the complete manual workflow without an AI provider.

Every product feature is included.

No paid editions, activation keys, seat limits, engagement caps, finding caps, subscriptions, or upgrade gates.

Direct local workspace without accounts or activation

The same complete feature set on Windows and Linux

Refreshable engagement overview and workspace-wide local search

Versioned scan snapshots and assessment comparison

Evidence Notebook with validated attachments and finding conversion

Finding history, retest dates, and risk-first queues

Nmap and Nuclei Tool Runner workflows without a command shell

Web, API, network, Active Directory, and cloud templates

OWASP Top 10:2025 and OWASP API Security Top 10 (2023) baselines

Nuclei JSONL and SARIF 2.1 interoperability

Markdown and DOCX reports without an AI provider

Report-readiness blockers and advisory warnings

Portable project transfer, verified backups, and support snapshots

AI preflight with provider, redaction, readiness, and input-size details

API-key-first OpenAI and Anthropic setup with advanced model overrides

Azure OpenAI, Amazon Bedrock, and local compatible provider support

Reviewed AI proposals with evidence references and provenance

User-controlled cloud providers and compatible local model servers

Run Breachwright from source or a release build.

Review the code, contribute improvements, or run the complete application in your own environment.

These downloads are the verified Breachwright 2.4.1 release, which fixes Windows startup when downloaded files retain internet-zone metadata. Read the complete notes on the GitHub release page.

Clone

git clone https://github.com/Advent-Cybersecurity/breachwright.gitcd breachwright

Build

python -m pip install -r backend/requirements.txtcd frontend && npm ci && npm run buildcd .. && python run.py

AI-assisted workflows use an API provider you configure or a local model endpoint you control. Third-party provider charges may apply.

Review the Breachwright Privacy Policy for details about local storage, optional AI providers, and operator controls.