Product Update (August 2026)

PentaTrail Editorial··4 min read
Contents

This covers everything since the last update on 19 July, through 16 August. Two things are new to use: an attack path view, and a rebuilt MCP server.

01 / You can follow an attack path from entry point to affected asset

The Mobilization phase has a new Attack Path tab. It draws the route from entry point, through choke points, to the assets at risk, on one diagram.

The attack path screen: three columns for entry points, choke points and affected assets, with a ranked list of remediation tasks below

Figure 1: The attack path screen (line thickness indicates impact magnitude)

A choke point is a spot where sealing one thing cuts several routes at once. Remediation tasks are ranked that way, so the order of work follows how much exposure each fix removes, not how many findings it closes. Selecting a row takes you straight to that task.

02 / We moved MCP to a hosted server and made it easier to use

Any MCP-capable AI tool can query PentaTrail and act on it. Ask what to fix first, and the risk bands, the hosts they sit on, and who owns them come back as one answer. Adding a domain to monitoring, archiving one, excluding an asset, closing a remediation task can be asked for the same way.

Table 1: What changed about using MCP

Aspect Before Now
Connecting Install and configure a package on your own machine Add https://api.pentatrail.co/mcp, approve in the browser it opens
What it can do Read only Ask questions, and make changes
Starting an AI Deep Scan On screen On screen (unchanged)

Approved tools can be revoked at any time from Settings in the admin console (admin.pentatrail.co).

All 17 tools are documented with a worked example on the MCP server page.

03 / Seven defects fixed

Table 2: What was going wrong

Area What was happening
AI Deep Scan The state was not reported correctly
Asset exclusion Bulk exclusion, and removing an exclusion, both failed
Detection rules Five flaws. Two rules were added that report when something could not be measured
Domain setup Five places where it stalled
Deleting a group The remediation records under it were deleted too
Remediation tasks The hosts covered could drift out of step; now reconciled every 30 minutes
Vulnerability counts The dashboard, the API and the reports disagreed

These updates are already available in your dashboard.

Visualize your attack surface with PentaTrail CTEM/ASM

From discovery to vulnerability validation and remediation — all powered by the CTEM framework.

Get Started

See pricing/Compare and choose