Skip to content
ZK
ZAIN KHALIL KHAN
PORTFOLIO
All Projects
Live productFlagship case study

Aegis Intelligence

Autonomous AI PenTesting Assistant

Penetration-testing evidence arrives as disconnected scans and notes, making it difficult to explain which weaknesses form a credible attack path.

Interactive preview
Full demo

This is the actual deployed application, embedded live from aegisintelligence.org. If it doesn't load below (some browsers block third-party embeds), open it directly.

Loading live application...
Open directly

My Role

Founder, security product designer, and full-stack engineer

What I Built

Autonomous AI-powered penetration testing assistant that converts raw reconnaissance data into structured, actionable threat intelligence in real time. Ingests outputs from Nmap and Gobuster, performs live OSINT enrichment, and automatically maps potential vulnerabilities, misconfigurations, and attack paths.

Evidence

Working interface, documented system behavior, and implementation-level decisions.

Technical Architecture

From system input to explainable output.

The control gate is shown as a first-class stage, not an afterthought added around the workflow.

Five stages connect inputs to processing, security controls, stored state, and user output.SYSTEM FLOW / AEGIS INTELLIGENCETRACEABLE PIPELINE01INPUTSURLs, IPs &recon logsVERIFIED STAGE02PROCESSINGRecon orchestrationVERIFIED STAGE03SECURITY CONTROLSScope & safetycontrolsCONTROL GATE04STORAGE / STATEFindings graphVERIFIED STAGE05USER OUTPUTAttack paths & reportVERIFIED STAGEINPUT TO OUTCOME / EVIDENCE PRESERVED

Technical Decisions

  • Built an autonomous assistant that ingests raw Nmap and Gobuster output and converts it into structured, prioritised threat intelligence in real time.
  • Parsed scanner output into a normalised host, port, service, and version model, so downstream reasoning works on data rather than on text.
  • Built the React and TypeScript interface around an engagement workflow: scope, findings, evidence, and remediation, in the order a report is written.

Security Considerations

  • Built an autonomous assistant that ingests raw Nmap and Gobuster output and converts it into structured, prioritised threat intelligence in real time.
  • Mapped findings to likely attack paths, chaining a misconfiguration or outdated service into the next step an attacker would take.
  • Built the React and TypeScript interface around an engagement workflow: scope, findings, evidence, and remediation, in the order a report is written.

Outcome & Evidence

  • Ranked findings by exploitability and blast radius rather than raw CVSS, so the report leads with what actually matters in this environment.
Generative AIOSINTCybersecurityReactTypeScript

Working product

Try the interactive demo.

The product experience is part of this case study. Explore it here, reset its state, or switch viewport sizes without leaving the project page.

This is the actual deployed application, embedded live from aegisintelligence.org. If it doesn't load below (some browsers block third-party embeds), open it directly.

Loading live application...
Open directly

Next Case Study

Aegis SOC Analyst

Read Next Case Study