This product has charges associated with it for the Kali-AI v2 automated penetration testing platform. Kali-AI v2 automates penetration testing with a 7-tool pipeline and Claude AI analysis, delivering white-label PDF reports. Built for MSSPs, red teams, and security professionals.
This is a repackaged software product wherein additional charges apply for the Kali-AI v2 automated penetration testing platform.
Kali-AI v2 is a self-hosted autonomous penetration testing platform built on hardened Ubuntu 24.04 LTS. It runs a 7-tool scanning pipeline, analyses every finding with Anthropic Claude AI, and generates professional 10-section PDF security reports automatically - no manual steps between scan launch and final deliverable.
Designed for MSSPs, security teams, red teams, and penetration testers who need repeatable automated assessments without SaaS pricing or data residency risk. All data stays on your EC2 instance.
How It Works
Kali-AI v2 automatically executes Nmap, Nuclei, Nikto, WhatWeb, Gobuster, WPScan, and SQLMap in sequence. Findings are correlated, enriched with CVE data, and analysed by Claude AI to produce an executive summary, risk rating, attack path analysis, remediation plan, and NIST/PCI-DSS/ISO 27001 compliance observations - delivered as a polished 10-section PDF.
Key Features
7-Tool Automated Pipeline: Nmap, Nuclei, Nikto, WhatWeb, Gobuster, WPScan, and SQLMap run automatically in sequence.
Claude AI Analysis: Every finding is risk-rated and written up by Anthropic Claude, producing actionable narratives rather than raw scanner output.
10-Section PDF Reports: Professional reports ready to deliver to clients or stakeholders. White-label with your company name and logo.
Scan Delta: Compare new vs resolved vs persistent findings across assessments.
Scheduled Scans: Cron-based recurring scans with Full, Quick, Web, or Network scan types.
Batch Scanning: Up to 20 targets with parallel execution for MSSP workflows.
Client and Project Tagging: Organize assessments by client and engagement.
Security Copilot: AI assistant for plain-language queries about results and remediation.
RBAC: Admin, analyst, and auditor roles with JWT authentication.
Integrations: Slack and Teams webhooks, SIEM JSON export, and REST API for CI/CD pipelines.
Security and Data Handling
The platform runs on a hardened Ubuntu 24.04 LTS base. The first-boot wizard ensures no default credentials exist. RBAC with JWT authentication controls access across roles. All scan data remains on your EC2 instance with no vendor data retention. API keys and SMTP credentials are stored in /opt/kali-ai/.env with restricted file permissions.
Getting Started
Launch an EC2 instance (t3.medium or larger, 30GB EBS). Open port 80 in your Security Group.
Create your admin account (12+ character password required).
Add your Anthropic API key in Settings (obtain from console.anthropic.com - pay-per-use).
Launch a scan. Try: scanme.nmap.org
View the AI-analyzed PDF report in the Reports section.
Requirements and Limitations
This is a repackaged software product with additional charges for the Kali-AI v2 platform.
An Anthropic API key is required for Claude AI analysis and is billed separately by Anthropic on a pay-per-use basis.
Buyers should verify compatibility with their target EC2 instance types before deploying at scale.
For HTTPS, deploy behind an AWS ALB or CloudFront distribution with an ACM certificate.
Responsible Use
AUTHORIZED USE ONLY. For security testing of systems you have explicit written permission to test. Unauthorized use violates the AWS Acceptable Use Policy, the Computer Fraud and Abuse Act (CFAA), and equivalent laws.
About Madarson IT
Madarson IT certified images are continuously updated, security-optimized, and built to meet enterprise requirements with minimal configuration. Madarson IT also offers hardened and custom images across AWS, GCP, and Azure Marketplace.
Highlights
7-Tool Automated Pentest Pipeline: Nmap, Nuclei, Nikto, WhatWeb, Gobuster, WPScan, and SQLMap run automatically in sequence. Findings are correlated, CVE-enriched, and analysed by Anthropic Claude AI - eliminating hours of manual tool orchestration per assessment. Schedule recurring scans, run batch assessments against up to 20 targets, and track delta changes across engagements without any manual pipeline management.
White-Label PDF Reports with Claude AI Analysis: Every scan produces a professional 10-section PDF report with executive summary, risk rating, attack path analysis, remediation plan, and NIST/PCI-DSS/ISO 27001 compliance observations generated by Claude AI. White-label with your company name and logo for direct client delivery. Email delivery on scan completion included.
Built for MSSP and Enterprise Workflows: Client and project tagging supports multi-tenant operations. Remediation tracker with assignee, due date, and CSV export integrates into project management workflows. Slack, Teams, and SIEM webhooks plus a full REST API enable CI/CD integration. RBAC with admin, analyst, and auditor roles controls access across your team.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for the software running on your chosen EC2 instance. Each dimension maps to one instance type, so your rate follows the compute size you pick. General-purpose (m, t), compute-optimized (c), memory-optimized (r), storage-optimized (i, d), and GPU-accelerated (g, p) families are all available. Smaller instances like t3.nano or t2.micro suit light testing, while larger sizes like p3.16xlarge or r7a.16xlarge handle heavier workloads. Billing scales with instance size and runtime hours. You add EC2 infrastructure charges separately, and you supply your own AI service key.
Top-of-mind questions for buyers
What does one billing unit represent for each instance type?
Each dimension bills per hour that the software runs on one EC2 instance of that type. One unit equals one running instance-hour. The instance type you launch, such as t3.small or g5.4xlarge, sets your hourly software rate. Running two instances doubles the software charge for the same period.
Am I charged when my instance is stopped or the scan queue is idle?
Software charges meter running instance-hours only. A fully stopped instance does not accrue software charges. Stopped instances may still incur AWS storage fees for attached volumes, which are separate from the software rate. Idle time while an instance runs still counts as billable hours.
What costs are not included in the hourly software rate?
The hourly rate covers the software only. You pay AWS separately for the EC2 instance and storage. You also supply your own AI service API key, billed by that third-party provider directly. Email delivery uses your own SMTP settings.
madarsonit.com
Helpful?
Vendor refund policy
There is no refund policy for this image
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Allow inbound SSH access in your security group (TCP port 22)
Allow inbound web access in your security group on TCP port 80
To connect to your instance using the Amazon EC2 console:
Open the Amazon EC2 console at https://console.aws.amazon.com/ec2/
In the navigation pane, choose Instances.
Select the instance and choose Connect.
Choose the EC2 Instance Connect tab.
For Connection type, choose Connect using EC2 Instance Connect.
Access the ec2 with the default username: "kali"
To Access Dashboard and setup admin account: http://your-vm-ip
Madarson IT provides support for Kali-AI v2 via email at info@madarsonit.com. Contact us for assistance with deployment, configuration, scanning issues, or report generation.
For private offers or custom licensing arrangements, reach out to the same email address with details about your requirements.
Please include your EC2 instance ID and a description of the issue when submitting support requests to help us assist you efficiently.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.