SoulEyez

What It Is

Penetration Testing That Ends in Evidence, Not a Folder of Screenshots.

SoulEyez is a penetration testing management platform that replaces scattered terminals and stray text files with one organized workflow — and ends that workflow with a report you can hand to an auditor.

With SoulEyez you can:

  • Run security scans (Nmap, Gobuster, SQLMap, and more)

  • Automatically discover next testing steps

  • Store targets, findings, and credentials securely

  • Generate professional reports on a repeatable cadence

The gap most teams have isn't testing. It's proving the testing happened, on schedule, and that what you found got closed. SoulEyez keeps the engagement history behind every report, so the cadence itself becomes the evidence.

Every Compliance Training plan includes SoulEyez Pro free for the first year.

What It’s For

Compliance-driven teams. You owe someone a quarterly assessment and the budget for four external engagements a year doesn't exist. Run them in-house, generate the report, keep the evidence.

Security professionals. Authorized testers running real-world assessments, managing findings, and producing client-ready reports without rebuilding the reporting layer every engagement.

Purple hat wearers. Practitioners who blend offensive and defensive thinking to understand attack paths, detection gaps, and remediation strategy. Pro's MITRE and detection views map findings straight to coverage.

Students and learners. Anyone building penetration testing methodology and hands-on tooling skills in labs and controlled environments.

What It Satisfies

SOC 2 (2017 Trust Services Criteria)
CC7.1 — identification and monitoring of vulnerabilities. CC4.1 — periodic evaluation of whether your controls are actually operating. A quarterly SoulEyez assessment gives your auditor a dated, repeatable record of both, generated by the same tool each time.

HITRUST CSF — Domain 07, Vulnerability Management
Recurring assessments plus tracked remediation through to closure. That cadence-and-closure trail is what e1 and above are looking for.

Also reinforces
ISO 27001 A.8.8 (technical vulnerability management) · NIST CSF 2.0 ID.RA-01 and DE.CM · NIST 800-171 §3.11.2 and §3.12.1 · CIS Controls v8 #7 (Continuous Vulnerability Management) and #18 (Penetration Testing)

A straight answer on PCI DSS
Req 11.3.1 requires external scans by an Approved Scanning Vendor, and Req 11.4 sets qualification and independence requirements for penetration testers. SoulEyez does not replace either. What it does is keep you continuously ready for them — so the ASV scan and the annual pen test confirm what you already knew instead of surfacing surprises.

⚠️ SoulEyez must only be used on systems you own or have explicit authorization to test.

Installing SoulEyez for FREE

First, you need pipx - a tool that safely installs Python CLI apps:

sudo apt install pipx    # Install pipx
pipx ensurepath         # Add pipx apps to your PATH
source ~/.bashrc         # Reload your shell (or close and reopen terminal)

Installing & Launching SoulEyez

pipx install souleyez
souleyez dashboard

On your first run, SoulEyez guides you through:

  1. Tool Installation

  2. Vault Password

  3. Admin Account

  4. First Engagement

FREE

  • Run Security Scans

  • Organize Target & Findings

  • Encrypted Credential Storage

  • Report Generation

PRO

  • All free features

  • AI-Powered Suggestions

  • Automatic Tool Chaining

  • Natural Language Execution

  • MSF Integration

  • SIEM Integrations

  • MITRE & Detection Views