Pentoma Web
- Corpus
- OWASP Juice Shop, intentionally vulnerable API targets, PortSwigger-style labs, and permitted public validation cases.
- Methodology
- Authenticated and unauthenticated runs are scored on confirmed exploitability, replay quality, time-to-finding, false-positive rate, and severity accuracy.
- Pass criteria
- A finding passes only when request/response evidence, safe proof-of-exploit, reproduction steps, and non-destructive validation are present.