# Common Use Cases for VulnClaw: 9 AI-Powered Penetration Testing Workflows Explained

> Discover common use cases for VulnClaw, an AI-powered penetration testing tool. Explore automated tests, security monitoring, reconnaissance, and more with 9 explained workflows.

- Repository: [Unclecheng/VulnClaw](https://github.com/Unclecheng-li/VulnClaw)
- Tags: tutorial
- Published: 2026-07-03

---

**VulnClaw supports nine primary use cases including automated full-cycle penetration tests, continuous security monitoring, targeted reconnaissance, selective vulnerability scanning, exploit validation with PoC generation, and interactive modes for CTF competitions and red-team engagements.**

VulnClaw is an extensible, AI-driven penetration testing platform developed by Unclecheng-li that combines a natural-language front-end with a goal-driven OODA solver engine. Understanding the common use cases for VulnClaw helps security teams leverage its architecture—implemented across [`vulnclaw/agent/solver.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/agent/solver.py), [`vulnclaw/agent/blackboard.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/agent/blackboard.py), and the plugin subsystem—to automate everything from quick vulnerability assessments to long-term continuous security operations.

## Automated Full-Cycle and Continuous Testing

### One-Click Full-Cycle Penetration Testing

The `vulnclaw run <target>` command initiates a complete assessment workflow that automatically triggers the **solve engine** in [`vulnclaw/agent/solver.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/agent/solver.py). This engine performs information gathering, vulnerability discovery, exploitation, and report generation without manual intervention. The solver uses a **Fact/Intent blackboard** implemented in [`vulnclaw/agent/blackboard.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/agent/blackboard.py) to track progress and avoid exploration loops, while an **evidence-level hallucination gate** verifies claims before they are recorded as Facts.

```bash

# Execute a complete penetration test cycle

vulnclaw run https://target.example.com

```

### Continuous and Periodic Security Monitoring

For long-running assessments, `vulnclaw persistent <target>` executes multiple cycles (defaulting to 100 rounds per cycle for up to 10 cycles) and automatically emits Markdown reports after each completion. This mode reuses the same blackboard across cycles and persists failure memory via the **reflexion engine** located in [`vulnclaw/agent/reflexion.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/agent/reflexion.py), enabling the system to learn from previous unsuccessful attempts.

```bash

# Run continuous testing with 200 rounds per cycle for 5 cycles

vulnclaw persistent 10.0.0.5 --rounds 200 --cycles 5

```

## Targeted Testing and Validation

### Reconnaissance-Only Information Gathering

When exploitation is not required, `vulnclaw recon <target>` invokes only the **recon Skill** from [`vulnclaw/skills/core/recon.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/skills/core/recon.py), orchestrating MCP services such as `fetch`, `subdomain_enum`, and `dir_enum` without triggering exploit tools. This use case is ideal for initial asset discovery and mapping network attack surfaces.

```bash

# Perform reconnaissance without exploitation

vulnclaw recon http://intranet.local

```

### Selective Vulnerability Scanning

The `vulnclaw scan` command runs specific vulnerability detection plugins via the plugin runtime in [`vulnclaw/plugins/registry.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/plugins/registry.py), which loads each plugin once per stage and merges results into `SessionState.findings`. Users can specify ports and targets to constrain the scan scope.

```bash

# Scan specific ports using available plugins

vulnclaw scan <target> --ports 80,443

```

### Exploit Validation and PoC Generation

Security teams use `vulnclaw exploit <target> --cve CVE-2024-1234` to validate specific vulnerabilities. Upon successful exploitation, the system generates a proof-of-concept script using [`report/poc_builder.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/report/poc_builder.py) and adds structured results to the final report via [`report/generator.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/report/generator.py). The **exploitation Skill** calls the `python_execute` tool when needed to verify exploitability.

```bash

# Validate a specific CVE and generate PoC

vulnclaw exploit 192.168.1.10 --cve CVE-2024-5678

```

## Interactive Interfaces and Specialized Workflows

### Interactive REPL and Terminal UI

Launching `vulnclaw` (default REPL) or `vulnclaw tui` starts a terminal-graphical workbench that displays the current **origin → goal** blackboard, safety budget, and recent findings. These UI components in [`cli/main.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/cli/main.py) and [`cli/tui.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/cli/tui.py) are thin wrappers around the core agent, providing real-time visibility into the AI's decision-making process.

```bash

# Launch the terminal UI workbench

vulnclaw tui --target https://app.internal --mode quick

```

### Web-Based Interface

The `vulnclaw web` command starts a local FastAPI server on `127.0.0.1:7788`, exposing the entire workflow through a browser-based interface. The web UI code resides under `frontend/` and provides the same goal-driven engine access as the CLI but through a graphical interface.

```bash

# Start the web UI server

vulnclaw web

# Access at http://127.0.0.1:7788

```

### CTF and Security Training

VulnClaw includes built-in **CTF Skills** (`ctf-web`, `ctf-crypto`, `ctf-misc`) that automatically load reference documents from `secknowledge-skill/references/` via the **secknowledge-skill** loader. This use case triggers payload-generation helpers and leverages external knowledge bases to solve capture-the-flag challenges.

### Red-Team and Long-Term Engagements

For advanced simulations, teams combine **persistent mode** with custom MCP services defined in [`mcp/registry.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/mcp/registry.py), such as Chrome DevTools or Burp Suite integration. This configuration simulates realistic web application attacks while persisting findings across multiple cycles using the reflexion engine's adaptive failure memory.

```bash

# Enable Chrome DevTools MCP for browser automation

vulnclaw config set mcp.servers.chrome-devtools.enabled true
vulnclaw config set mcp.servers.chrome-devtools.transport.command npx
vulnclaw config set mcp.servers.chrome-devtools.transport.args '["-y","chrome-devtools-mcp@latest"]'

```

## Summary

- **One-click automation**: The `vulnclaw run` command leverages the OODA solver in [`vulnclaw/agent/solver.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/agent/solver.py) to execute complete penetration tests from reconnaissance to reporting.
- **Continuous monitoring**: `vulnclaw persistent` uses the reflexion engine in [`vulnclaw/agent/reflexion.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/agent/reflexion.py) to maintain context across multiple testing cycles.
- **Targeted operations**: Reconnaissance, scanning, and exploitation modes allow selective engagement via specific Skills and plugins.
- **Flexible interfaces**: Both terminal ([`cli/tui.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/cli/tui.py)) and web (`frontend/`) interfaces provide access to the core goal-driven engine.
- **Extensible architecture**: MCP services and the plugin registry in [`vulnclaw/plugins/registry.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/plugins/registry.py) support custom tools for CTF and red-team scenarios.

## Frequently Asked Questions

### What is the difference between `vulnclaw run` and `vulnclaw persistent`?

`vulnclaw run` executes a single, complete penetration testing cycle and terminates upon completion or budget exhaustion, making it ideal for point-in-time assessments. In contrast, `vulnclaw persistent` runs multiple cycles (defaulting to 100 rounds per cycle for up to 10 cycles) while maintaining state across iterations via the reflexion engine, making it suitable for continuous monitoring and long-term red-team operations.

### How does VulnClaw prevent false positives during vulnerability scanning?

The platform implements an **evidence-level hallucination gate** within the solve engine ([`vulnclaw/agent/solver.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/agent/solver.py)) that requires verified Facts to be backed by tool output before being recorded on the blackboard ([`vulnclaw/agent/blackboard.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/agent/blackboard.py)). This ensures that only validated findings from actual tool execution—such as those from [`vulnclaw/skills/core/recon.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/vulnclaw/skills/core/recon.py) or exploitation plugins—are included in the final report.

### Can VulnClaw integrate with existing security tools like Burp Suite?

Yes, VulnClaw supports integration with external tools through its **MCP toolchain** configured in [`mcp/registry.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/mcp/registry.py). Users can enable services such as Chrome DevTools or Burp Suite via `vulnclaw config set mcp.servers.<service>.enabled true`, allowing the AI agent to leverage existing browser automation and HTTP proxy capabilities during testing workflows.

### What file generates the PoC scripts after successful exploitation?

Upon successful exploitation, the **PoC builder** located in [`report/poc_builder.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/report/poc_builder.py) generates proof-of-concept scripts. These are then incorporated into the structured final report by [`report/generator.py`](https://github.com/Unclecheng-li/VulnClaw/blob/main/report/generator.py), which produces both Markdown and HTML outputs documenting the vulnerability and validation steps.