Audits
An audit is one offensive engagement against a target domain. You choose a mode, pick targets, and Golem takes over.The three modes
Shallow
OWASP Top 10 + PoC only. ~30 min. No post-exploitation.
Deep
Full 10-phase attack chain. ~2 hrs. Includes post-exploitation.
Autonomous
Operator-defined mission brief. ~4 hrs. You write the scope.
How an engagement runs
What every audit produces
- Findings — confirmed vulnerabilities with severity, evidence, and remediation. See Findings & Evidence.
- Security score — letter grade A+ to F derived from finding weights. See Security Score.
- PDF report — cover page, executive summary, per-finding pages with evidence and recommendations. See Reports & Recordings.
- Asciinema recording — full terminal session replay of every command Golem ran.
- Screenshots — automatic visual evidence captured at the moment of discovery.
Choosing a mode
Audit statuses
Time budgets
Each mode has a default time budget that controls when Golem stops exploring and starts writing the report:- Shallow: 30 minutes
- Deep: 2 hours
- Autonomous: 4 hours