Inside the Lory TUI & Split-Pane Workbench: Interactive Pentesting | Lorikeet Security Skip to main content
Back to Blog

Inside the Lory TUI & Split-Pane Workbench: Interactive Pentesting

Lorikeet Security Technical Team September 23, 2026 9 min read Lory AI & Developer Tools

Traditional cybersecurity scanners run as opaque background jobs, generating an unreadable report hours later. When vulnerabilities fail to reproduce, engineers are left wondering what tools executed, which HTTP headers were transmitted, and why an alert was triggered.

Lorikeet Security reimagined this paradigm with the Lory AI Workbench (workbench.php). Inspired by next-generation development environments, the Workbench provides an interactive split-pane terminal and inspection interface that puts security researchers, developers, and compliance officers directly in the driver’s seat.

Complete Operational Transparency: With Lory Workbench, there are zero black boxes. Every tool invocation, packet probe, and LLM reasoning step streams live in real time, accompanied by syntax-highlighted code and DOM preview states.

The Split-Pane Architecture Explained

The Workbench layout is optimized for high-velocity offensive engagements:

The Left Pane: Conversational Engine & Autonomous Planning

In the left pane, operators converse with Lory in natural language. You can define targets, specify testing depths (surface, standard, deep), supply test credentials, or instruct Lory to focus specifically on an edge-case attack vector like OAuth state tampering or GraphQL batching attacks.

The Right Pane: The 3 Operational Tabs

The right pane features three dynamic tabs that update in real time via Server-Sent Events (SSE):

1. The Preview Tab

Displays live visual state captures of target web interfaces, rendered DOM snapshots from headless Chromium instances, technology stack badges, and active vulnerability cards as they are verified.

2. The Code Tab

Inspects unpacked JavaScript source maps, API endpoints, OpenAPI schemas, and full HTTP request/response evidence pairs with Prism.js syntax highlighting and one-click copy buttons for curl reproduction.

3. The Terminal Tab

Streams the raw stdout and stderr of Lory’s underlying offensive toolbelt: Nmap port sweeps, Nuclei vulnerability templates, FFuf directory fuzzing, and custom exploit scripts.

From Workbench Session to Audit-Ready Report

Once an engagement concludes in Workbench, findings are not just isolated terminal output. Discovered vulnerabilities flow directly into LoryFindingsBus, undergo CVSS v3.1 scoring, and enter the Lorikeet Security human review queue.

Within 24 to 48 hours, verified findings are compiled into an accredited executive Letter of Attestation and technical remediation guide that satisfies SOC 2, ISO 27001, and PCI DSS compliance audits.

Experience Autonomous Pentesting with Lory

Take control of your attack surface. Launch an interactive Lory Workbench session or speak with our offensive security team to scope an engagement.

-- views
Link copied!
Lorikeet Security

Lorikeet Security Team

Penetration Testing & Cybersecurity Consulting

Lorikeet Security helps modern engineering teams ship safer software. Our work spans web applications, APIs, cloud infrastructure, and AI-generated codebases — and everything we publish here comes from patterns we see in real client engagements.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!