CyberForcesCybersecurity platform

Cybersecurity,
on one platform.

Find, protect, inspect, fix. Keep the security measures your company needs running on one platform. CyberForces is a cybersecurity platform developed, operated and sold by the Classmethod Group. AI handles day-to-day operations, so your people can focus on decisions and improvement. Today it focuses on public web, cloud and applications, and its coverage keeps expanding.

  • One console, one account, only the services you need
  • New areas are simply added to the same platform
  • Automation in stages: Off, Suggest or Auto

Classmethod, Inc.CyberForces is developed, operated and sold end to end by the Classmethod Group, a top-tier AWS partner.

5,600+Companies given technical support by Classmethod
40,000+AWS accounts supported
Since 2015AWS Premier Tier, continuously certified
Partner of the YearAWS Japan 2026 (2nd year in a row, 5th time)

Concept

Protect and inspect.
Keep both running without stopping.

Security is not something you do once and finish. The things you need to protect keep growing, environments change every day, and new vulnerabilities are disclosed daily. CyberForces puts services that “protect” by stopping attacks and services that “inspect” by finding weaknesses first on a single foundation. It is a platform for keeping the cycle of find, verify, fix and protect running without stopping. Its scope will not stop at public web and cloud; we are expanding it to cover enterprise cybersecurity as a whole.

“Protect” and “inspect” on one foundation

When defense and inspection live in separate tools, protection falls behind in the gap before a weakness found in inspection is fixed, and what is happening on the defense side does not inform inspection. With CyberForces, you see the results of both in the same console and decide your next move.

AI handles day-to-day operations

Finding WAF false blocks, running penetration tests, filtering out false positives in static analysis, judging whether a defacement is real. AI takes on work that has consumed experts' time, so people can focus on decisions and improvement. For automation that affects production, you can choose the level for each feature.

Expand your coverage on one foundation

Every service can be contracted individually and added to the same account and console. Start with protecting your public web, or start with checking your cloud configuration. Wherever you begin, services you add later appear on the same screen, and services in new areas join the same foundation.

Challenges

Risk spreads from what you can't see

You can't see every entry point you need to protect

Campaign sites, test environments, subdomains built by outside contractors. Attackers get in through “forgotten public assets.” First you need to know what is visible from the outside.

You have a WAF, but you can't run it

Fear of blocking legitimate traffic keeps it “in Count mode,” and tuning is left to whoever is in charge. A WAF that is only installed cannot stop real attacks either.

You can't keep up with cloud settings and changes

Misconfigured public access, excessive permissions, neglected vulnerabilities. Most cloud incidents come not from advanced attacks but from day-to-day changes that go unnoticed.

Services

The three areas we cover today

Web Security protects your public web, Cloud Security keeps checking your cloud, and Security Inspect finds weaknesses first. Each service can be used on its own and is managed in the same console. We keep expanding the areas we cover.

01Web Security

Find, know, stop, notice. Protect your public web from four angles

Discover and monitor internet-facing assets

ASM

Seeing what an attacker sees, ASM automatically discovers your subdomains and servers visible from the outside, every day. It inspects open ports, certificates and technology stacks, and alerts you first to vulnerabilities that are being exploited.

  • Discovers assets from certificate logs, DNS and AWS
  • Uses KEV and EPSS to flag what to fix now
  • Active checks only on targets you approve
Learn more →
Threat Intelligence Hub

Threat intelligence

Combines trusted public feeds, your own IOCs and the feeds you subscribe to in one place. It removes noise, assigns confidence scores, delivers over the REST API and TAXII 2.1, and feeds your WAAP WAF rules.

  • Public feeds + your IOCs + subscribed feeds in one place
  • Removes false-positive sources and assigns confidence
  • Delivered via TAXII 2.1 / API, applied to WAAP automatically
Learn more →
AWS WAF operations automation

WAAP

Reduces false blocks in AWS WAF and automates operations, from switching Count to Block to quarantining attacking IPs and bot defense.

  • Apply exclusions for false blocks in one click
  • Estimate impact before changes
  • Bot defense without paid rule groups
Learn more →
DefaceMonitor

Defacement detection

Crawls your public websites from the outside and inspects them for defacement in three layers: page content, rendered screen and AI analysis. It also detects skimming scripts that leave the page unchanged, by watching where scripts are loaded from.

  • Three layers: content, screen and AI
  • Detects unfamiliar script sources
  • Intervals as short as 5 minutes, logged-in pages too
Learn more →

Platform

How the platform is built

CyberForces arranges services with different roles on top of a single unified console. It currently offers 3 areas, “Web Security”, “Cloud Security” and “Security Inspect”, and each connects to your environment with the minimum permissions it needs. Services in new areas will also join this same structure.

01 / Console

Unified console

All services on one screen with one account. Adding services does not add more logins or more permission management.

  • Single sign-on (one account for all services)
  • Permission management by organization (tenant) and group
  • Role-based access control, such as view-only or able to run
  • Japanese / English display switching
02 / Services
Cloud Security
Security Inspect
Related services
03 / Your environment

Your environment

Each service connects with only the permissions it needs. Current connection targets fall roughly into these 3 types.

Public websites and APIs

Register domains or URLs, or connect to AWS WAF (WAAP). Defacement detection and ASM can start with external observation alone.

Cloud accounts

For AWS, a mostly read-only IAM role is created with CloudFormation. Some services also support Azure, Google Cloud and OCI.

Applications and source code

Upload source code zip files or repositories, or mobile app binaries. The penetration test runtime is launched inside your AWS environment.

  • Connection methods and permissions differ by service. They are described under “Targets and delivery” on each service page.
  • We are expanding the covered areas step by step. Services in new areas are added to the same console and the same account.

How it fits together

Find, verify, fix and protect

Weaknesses found by inspection stay covered by defenses until they are fixed. Combine services to keep this cycle running.

  1. Find

    Continuously identify externally visible assets, cloud misconfigurations and vulnerabilities.

    ASM / Cloud Security
  2. Verify

    Verify, using an attacker's methods, whether the weaknesses found can really be exploited.

    AutoPentest
  3. Fix

    Turn code, dependency and configuration issues into fixes, highest priority first.

    SAST / SCA / CSPM
  4. Protect and monitor

    Until fixes are in, the WAF stops attacks, and you notice defacement and suspicious operations right away.

    WAAP / Defacement detection / CSEM

↻ Re-test after fixes, then the next cycle

AI in operations

The work AI does

AI in CyberForces is not there for show. We place it where operations run short of hands. Here is what it does in each service.

AI proposes and summarizes; people decide

Actions that affect production are, by default, reviewed before they are applied. In WAAP, you can choose “Off / Suggest / Auto” for each feature.

What was done is recorded

What AI proposed and executed is recorded and can be reviewed later.

AI can run under your control

AI in Cloud Security runs on your Amazon Bedrock, and you manage its usage fees and model selection.

Trust by design

Built securely, because it is a security product

Analysis runs inside your cloud

The AutoPentest execution environment, WAAP log analysis, the SCA scanner and more run inside your cloud account. Log and image contents are not taken out; CyberForces receives only findings and aggregate values.

Only authorized targets are inspected

Penetration tests are limited to the hosts and networks registered as in scope, and commands aimed outside that scope are blocked. ASM active checks run only against targets for which ownership and impact have been confirmed and agreed to.

Least-privilege integration

Integration with your environment goes through an IAM role created with CloudFormation. An external ID pins the caller, and only the permissions each feature needs are granted.

Every operation is logged

Audit logs record who ran or changed what, and when. Group-based permission management lets you separate people who can only view from people who can execute.

Classmethod Group

The Classmethod Group handles everything,
from development to operation and sales

CyberForces is a service developed, operated and sold entirely by the Classmethod Group, an AWS Premier Tier Services Partner, the highest AWS partner tier. You get the expertise built through cloud implementation and operations support, together with the development capability of the group's dedicated security company, as a single service.

Classmethod, Inc.

Classmethod Group

Classmethod website →

Built by a dedicated security company

Development is handled by Classmethod Security, Inc. (founded in 2019), the group's dedicated security company. It holds a patent on a method for detecting fraudulent access requests, and designs and implements its detection engines, use of AI and automation in-house. Results of joint research with a university are also incorporated into the products.

Top-tier AWS partner

Classmethod has been continuously certified as an AWS Premier Tier Services Partner since 2015. It received the AWS “Consulting Partner of the Year – Japan” award in 2026 (second consecutive year, fifth time overall), and the “Global SI Partner of the Year” award in 2022.

Extensive support record

Technical support for more than 5,600 companies and more than 40,000 AWS accounts. Classmethod has the largest number of AWS Certification holders among AWS partners in Japan.

Information security certifications

Certified to ISO/IEC 27001, 27017, 27701 and 20000-1, with a SOC 2 Type 1 report.

The group's specialist team supports you hands-on

We do not just hand over a tool. Classmethod, which has supported cloud implementation and operations, and Classmethod Security, a dedicated security company, work together within the same group. From consultation before adoption until operations are established, you have one point of contact.

Contact us
  1. Before adoption

    We listen to your systems and challenges and propose which service to start with. We can also advise on your AWS environment as a whole.

  2. During adoption

    We help with initial setup, including connection steps, how to define scope, and notification design.

  3. In operation

    You can consult the security specialist team on prioritizing findings and how to proceed with remediation.

Getting started

Steps to get started

  1. Contact us

    Tell us about your challenges and target environment. We'll propose the right combination of services.

  2. Open an account

    We issue an organization account. Choose only the services you need in the console and get started.

  3. Connect your environment

    Create an integration role with CloudFormation. Some services can be started just by registering a URL or domain.

  4. Operate and improve

    Improve based on findings and reports. Receive notifications by email, Slack or webhook.

FAQ

FAQ

How are services contracted?

Each service is contracted individually. Choose only what you need, and add more later. If you use multiple services, you manage them with the same account and console.

Which clouds are supported?

WAAP (AWS WAF operations automation) and the AutoPentest execution environment target AWS. Cloud Security supports AWS, Azure, Google Cloud and OCI, and CSEM can also monitor Microsoft 365 and Google Workspace logs (coverage varies by service). ASM, defacement detection, SAST and mobile app assessment can be used regardless of cloud.

Will inspections affect my production services?

Inspections are limited to targets registered as in scope. ASM active checks, which send real attack patterns from outside, run only against targets whose ownership and impact you have confirmed and agreed to. Even so, we cannot say load or side effects are zero, so we recommend running your first penetration test against a test environment or during off-peak hours.

Can we use it without a dedicated security specialist?

Findings are shown with their severity and how to address them, and things like WAF exclusions can be applied in one click. If you need help with onboarding or interpreting results, please contact us.

Tell us what you need to protect

Tell us about your systems and challenges, and we will propose the right combination of services. Demos are available on request.