One Click.
Any Workflow.
Zero Friction.
AttackForge Actions lets your team build custom workflows directly into the AttackForge interface - and trigger them with a single button click. QA reviews, scanner launches, data exports, risk acceptance approvals, external integrations. If you can imagine it, you can automate it.
Your Pentest Workflows Are Held Together with Duct Tape
Every offensive security team has them. The manual steps that eat hours every week but nobody talks about. Copying vulnerability data into a ticketing tool by hand. Chasing QA reviewers over Slack. Running the same export script before every client call. Building one-off integrations that break when someone leaves the team.
These aren't testing problems. They're operational drag. And they compound as your program scales - more projects, more testers, more stakeholders, more process debt.
AttackForge Actions exists to eliminate that drag entirely.
What You Don't Need the Day You Deploy Actions
No waiting for vendor roadmap.
Pre-built connectors break when vendors change their APIs. Actions and Flows give your team the building blocks to create, maintain, and evolve integrations on your own terms - without waiting on a vendor roadmap.
No wasting time on context switching.
Actions live inside the menus your team already uses. There's no separate automation dashboard to learn, no context switching, no friction between "doing the work" and "automating the work."
Reduce load on admins and empower your users.
With granular access controls and AFScript's interpreted execution model, any team member can trigger powerful automations safely - without elevated privileges and without security risk.
No external infrastructure or dependency on IT teams.
No Zapier. No custom middleware. No Python scripts running on someone's laptop. Actions, Flows, and AFScript are a complete, self-contained automation system running inside your pentest management platform.
Custom Workflows, Built In. Triggered Instantly.
AttackForge Actions requires the Flows module to be enabled on your AttackForge instance.
AttackForge Actions are user-defined workflow triggers that live directly inside the AttackForge interface - right alongside your existing menus and system controls. They look and feel native because they are native.
Each Action connects to one or more Flows - AttackForge's powerful automation engine - which execute the logic you define using AFScript, a purpose-built scripting language designed for security teams. The result is a system where anyone on your team can trigger sophisticated, multi-step automations without leaving the application, without additional infrastructure, and without waiting for IT departments.
Every Action is fully manageable after creation - edit, reorder, or remove Actions at any time from a centralized dashboard, or directly from the menus where they live. No lock-in, no rigidity.
Custom Workflows
Build processes that match how your team actually works. QA approval chains, vulnerability triage routines, retest request pipelines - defined once, available everywhere.
Process Automation
Chain together AttackForge API calls, conditional logic, data transformations, and external HTTP requests into a single triggered sequence. No cron jobs. No glue scripts.
External Integrations
Push data to Jira, ServiceNow, Azure DevOps, Slack, Power BI, or any system with an API endpoint. Pull data back in. Keep your ecosystem synchronized without middleware.
From Idea to Running Workflow in Minutes
Create an Action
Click the Actions button in any supported menu, then hit the + button. Give your Action a name.
Choose Where It Lives
Select which entities your Action appears on. Actions can be attached to Projects, Vulnerabilities, Test Cases, Assets, Portfolios, Groups, Users, Writeups, Project Requests, Portfolio Streams, or the Application level. One Action can span multiple entity types.
Link Your Flows
Connect one or more Action Event Flows to your Action. There is no limit to how many Flows a single Action can trigger. Each Flow runs independently - so one button click can fire a QA notification, create a Jira ticket, and log an audit record simultaneously.
Add a Readme
OPTIONALAttach documentation so your team understands exactly what the Action does before they run it. This appears in the confirmation dialogue.
Run It
When a team member clicks the Action, a confirmation dialogue appears with details about what will happen - including the linked Flows and their status. Users with permission can click through to inspect the full Flow logic before running, so there are no black boxes. They click Run. Done. The Action Runs Manager tracks execution status in real time - succeeded, running, or failed - with full drill-down into Flow Run Logs for complete auditability. If a linked Flow is disabled or the user lacks trigger permissions, the system surfaces a clear warning and prevents execution - Actions fail safely, never silently.
AttackForge Actions Everywhere You Need Them
Other platforms bolt automation on as an afterthought - available in one or two places, disconnected from the daily workflow. AttackForge embeds Actions across 11 entity types, so your automations live exactly where the work happens.
Project Requests
Automate intake and approvals.
Click to see more
Projects
Launch scans, generate reports.
Click to see more
Vulnerabilities
Triage, export, and review findings.
Click to see more
Test Cases
Track completion with side effects.
Click to see more
Portfolios
Aggregate reporting and metrics.
Click to see more
Portfolio Streams
Stream-level tracking and workflows.
Click to see more
Groups
Team-level bulk automations.
Click to see more
Assets
Sync inventories, trigger scanning.
Click to see more
Writeups
Distribute and sync templates.
Click to see more
Users
Onboarding and permissions.
Click to see more
Application
System-wide global automations.
Click to see more
Built For Real World Scenarios
Click a scenario to see how teams use Actions in production.
QA happens over Slack messages and spreadsheet trackers. Findings get missed. Reviews stall.
A tester clicks "Request QA Review" on a vulnerability. The linked Flow notifies the assigned reviewer and logs the request. The reviewer clicks "Approve QA" to confirm acceptance - or "Reject" to return it with comments. One click each. Full audit trail.
QA happens over Slack messages and spreadsheet trackers. Findings get missed. Reviews stall.
A tester clicks "Request QA Review" on a vulnerability. The linked Flow notifies the assigned reviewer and logs the request. The reviewer clicks "Approve QA" to confirm acceptance - or "Reject" to return it with comments. One click each. Full audit trail.
Pentesters context-switch between AttackForge and scanning tools. Assets are re-entered. Scope gets misaligned.
From a project, a tester clicks "Launch Nessus Scan." The Flow sends the asset details to the scanning tool's API, initiates the scan, and writes the scan ID back to AttackForge for tracking. When results are ready, a separate event-triggered Flow imports the findings automatically.
Risk acceptance decisions happen in email threads with no audit trail. Months later, nobody can prove who approved what.
A project manager clicks "Request Risk Acceptance" on a critical vulnerability. The Flow routes the request to the designated risk owner based on business unit, captures their approval or rejection through a follow-up Action, timestamps every decision, and updates the vulnerability status. Auditors get a clean, defensible record.
Developers need findings in their ticketing system, not in a static report. Manual ticket creation takes hours per engagement.
A tester selects vulnerabilities and clicks "Export to Jira." The Flow maps severity to Jira priority, formats the description with reproduction steps and evidence, creates the tickets in the correct project board, and writes the Jira ticket URLs back to AttackForge for cross-referencing.
Senior testers need to perform certain admin-level tasks - but giving them full admin access violates least privilege.
An administrator creates an Action that performs a specific privileged operation (like inviting a user to the platform) and grants the Action to senior team members. They click the button; the Flow executes under controlled permissions. No privilege escalation. No risk.
Individual team members have recurring tasks - generating a personal status report, exporting their assigned findings, running a pre-meeting data pull - but these don't warrant a team-wide automation or admin involvement.
A tester creates an Application Action tied to their own workflow. Application Actions are accessible at any time, regardless of what other data or projects the user has access to. No entity context required. Click the Action from the main nav, hit Run, and the Flow handles the rest. Ideal for personal productivity automations that don't need to live on a specific project or vulnerability.
Actions+Flows+AFScript
Actions are the trigger. Flows are the engine. AFScript is the logic. Together, they form a complete in-platform automation system that replaces external scripting, third-party integration platforms, and manual coordination.
Actions - The Interface
Flows - The Engine
AFScript - The Logic
Automation Without Anarchy
Giving teams the power to automate is only valuable if you can govern how that power is used. AttackForge provides granular access controls for every layer of the automation stack.
Action-Level Access
Control who can see, trigger, and configure each Action.
Flow-Level Permissions
Separate Create and Run access for Event Triggers, authenticated HTTP Triggers, and non-authenticated HTTP Triggers.
Flow Ownership
Every Flow runs under the context of its owner. Ownership can be transferred but never shared - ensuring clear accountability for every automation.
Safe-Fail Guardrails
If a linked Flow is disabled or a user lacks the required trigger permissions, the system blocks execution and surfaces a specific warning - "Flow is disabled" or "Missing access to trigger action flows." Actions never run in a broken state. Your team sees exactly what needs fixing before anything fires.
Centralized Management
View, edit, reorder, and delete all Actions from a single dashboard accessible from the main navigation. Drag-and-drop reordering lets you prioritize the Actions your team uses most. Every Action is fully editable after creation - rename it, reassign entities, swap linked Flows, or update the Readme without recreating anything.
Audit Trail
The Action Runs Manager logs every execution with timestamp, user, status, and linked Flow Run Logs. Click into any run to see exactly what happened, step by step.
What's Next for Actions
We're building more. Here's what's on the way.
Sharing Actions
Share Actions across teams and roles. Create an Action once, then distribute it to other users or groups - so your best workflows become organizational standards, not isolated experiments. Control who can see and trigger shared Actions with the same granular permissions you already use.
Custom Forms on Actions
Add input forms to your Actions so users can provide context at trigger time. Imagine clicking "Export to Jira" and being prompted to select a target project board, add a custom note, or override the default priority - all within the confirmation dialogue. Dynamic, user-driven automation without hardcoded values.
Stop Building Automations Outside Your Pentest Platform. Start Building Them Inside It.
Every workflow stitched together with external tools is a workflow that can break, drift, or get forgotten.
AttackForge gives you Actions, Flows, and AFScript - so your team gets the automation they need, right where the work happens.
- SOC 2 Type II Certified
- Instant Deployment
- No credit card required