SoulEyez
What It Is
Penetration Testing That Ends in Evidence, Not a Folder of Screenshots.
SoulEyez is a penetration testing management platform that replaces scattered terminals and stray text files with one organized workflow — and ends that workflow with a report you can hand to an auditor.
With SoulEyez you can:
Run security scans (Nmap, Gobuster, SQLMap, and more)
Automatically discover next testing steps
Store targets, findings, and credentials securely
Generate professional reports on a repeatable cadence
The gap most teams have isn't testing. It's proving the testing happened, on schedule, and that what you found got closed. SoulEyez keeps the engagement history behind every report, so the cadence itself becomes the evidence.
Every Compliance Training plan includes SoulEyez Pro free for the first year.
What It’s For
Compliance-driven teams. You owe someone a quarterly assessment and the budget for four external engagements a year doesn't exist. Run them in-house, generate the report, keep the evidence.
Security professionals. Authorized testers running real-world assessments, managing findings, and producing client-ready reports without rebuilding the reporting layer every engagement.
Purple hat wearers. Practitioners who blend offensive and defensive thinking to understand attack paths, detection gaps, and remediation strategy. Pro's MITRE and detection views map findings straight to coverage.
Students and learners. Anyone building penetration testing methodology and hands-on tooling skills in labs and controlled environments.
What It Satisfies
SOC 2 (2017 Trust Services Criteria)
CC7.1 — identification and monitoring of vulnerabilities. CC4.1 — periodic evaluation of whether your controls are actually operating. A quarterly SoulEyez assessment gives your auditor a dated, repeatable record of both, generated by the same tool each time.
HITRUST CSF — Domain 07, Vulnerability Management
Recurring assessments plus tracked remediation through to closure. That cadence-and-closure trail is what e1 and above are looking for.
Also reinforces
ISO 27001 A.8.8 (technical vulnerability management) · NIST CSF 2.0 ID.RA-01 and DE.CM · NIST 800-171 §3.11.2 and §3.12.1 · CIS Controls v8 #7 (Continuous Vulnerability Management) and #18 (Penetration Testing)
A straight answer on PCI DSS
Req 11.3.1 requires external scans by an Approved Scanning Vendor, and Req 11.4 sets qualification and independence requirements for penetration testers. SoulEyez does not replace either. What it does is keep you continuously ready for them — so the ASV scan and the annual pen test confirm what you already knew instead of surfacing surprises.
⚠️ SoulEyez must only be used on systems you own or have explicit authorization to test.
Installing SoulEyez for FREE
First, you need pipx - a tool that safely installs Python CLI apps:
sudo apt install pipx # Install pipx pipx ensurepath # Add pipx apps to your PATH source ~/.bashrc # Reload your shell (or close and reopen terminal)
Installing & Launching SoulEyez
pipx install souleyez souleyez dashboard
On your first run, SoulEyez guides you through:
Tool Installation
Vault Password
Admin Account
First Engagement
FREE
Run Security Scans
Organize Target & Findings
Encrypted Credential Storage
Report Generation
PRO
All free features
AI-Powered Suggestions
Automatic Tool Chaining
Natural Language Execution
MSF Integration
SIEM Integrations
MITRE & Detection Views

