Cybersecurity,
on one platform.
Find, protect, inspect, fix. Keep the security measures your company needs running on one platform. CyberForces is a cybersecurity platform developed, operated and sold by the Classmethod Group. AI handles day-to-day operations, so your people can focus on decisions and improvement. Today it focuses on public web, cloud and applications, and its coverage keeps expanding.
- One console, one account, only the services you need
- New areas are simply added to the same platform
- Automation in stages: Off, Suggest or Auto
Concept
Protect and inspect.
Keep both running without stopping.
Security is not something you do once and finish. The things you need to protect keep growing, environments change every day, and new vulnerabilities are disclosed daily. CyberForces puts services that “protect” by stopping attacks and services that “inspect” by finding weaknesses first on a single foundation. It is a platform for keeping the cycle of find, verify, fix and protect running without stopping. Its scope will not stop at public web and cloud; we are expanding it to cover enterprise cybersecurity as a whole.
“Protect” and “inspect” on one foundation
When defense and inspection live in separate tools, protection falls behind in the gap before a weakness found in inspection is fixed, and what is happening on the defense side does not inform inspection. With CyberForces, you see the results of both in the same console and decide your next move.
AI handles day-to-day operations
Finding WAF false blocks, running penetration tests, filtering out false positives in static analysis, judging whether a defacement is real. AI takes on work that has consumed experts' time, so people can focus on decisions and improvement. For automation that affects production, you can choose the level for each feature.
Expand your coverage on one foundation
Every service can be contracted individually and added to the same account and console. Start with protecting your public web, or start with checking your cloud configuration. Wherever you begin, services you add later appear on the same screen, and services in new areas join the same foundation.
Challenges
Risk spreads from what you can't see
You can't see every entry point you need to protect
Campaign sites, test environments, subdomains built by outside contractors. Attackers get in through “forgotten public assets.” First you need to know what is visible from the outside.
You have a WAF, but you can't run it
Fear of blocking legitimate traffic keeps it “in Count mode,” and tuning is left to whoever is in charge. A WAF that is only installed cannot stop real attacks either.
You can't keep up with cloud settings and changes
Misconfigured public access, excessive permissions, neglected vulnerabilities. Most cloud incidents come not from advanced attacks but from day-to-day changes that go unnoticed.
Services
The three areas we cover today
Web Security protects your public web, Cloud Security keeps checking your cloud, and Security Inspect finds weaknesses first. Each service can be used on its own and is managed in the same console. We keep expanding the areas we cover.
01Web Security
Find, know, stop, notice. Protect your public web from four angles
ASM
Seeing what an attacker sees, ASM automatically discovers your subdomains and servers visible from the outside, every day. It inspects open ports, certificates and technology stacks, and alerts you first to vulnerabilities that are being exploited.
- Discovers assets from certificate logs, DNS and AWS
- Uses KEV and EPSS to flag what to fix now
- Active checks only on targets you approve
Threat intelligence
Combines trusted public feeds, your own IOCs and the feeds you subscribe to in one place. It removes noise, assigns confidence scores, delivers over the REST API and TAXII 2.1, and feeds your WAAP WAF rules.
- Public feeds + your IOCs + subscribed feeds in one place
- Removes false-positive sources and assigns confidence
- Delivered via TAXII 2.1 / API, applied to WAAP automatically
WAAP
Reduces false blocks in AWS WAF and automates operations, from switching Count to Block to quarantining attacking IPs and bot defense.
- Apply exclusions for false blocks in one click
- Estimate impact before changes
- Bot defense without paid rule groups
Defacement detection
Crawls your public websites from the outside and inspects them for defacement in three layers: page content, rendered screen and AI analysis. It also detects skimming scripts that leave the page unchanged, by watching where scripts are loaded from.
- Three layers: content, screen and AI
- Detects unfamiliar script sources
- Intervals as short as 5 minutes, logged-in pages too
02Cloud Security
Configuration, activity, vulnerabilities. Keep checking your cloud from three angles
CSPM
Continuously finds cloud misconfigurations against CIS Benchmarks and other standards, and prioritizes them by risk that accounts for external attack paths, data exposure and criticality.
- Assessed against CIS, AWS FSBP and more
- Visualizes attack paths and data exposure
- Supports AWS, Azure, Google Cloud and OCI
CSEM
Detects suspicious sign-ins, permission changes and external access every 15 minutes from AWS, Azure, Google Cloud and OCI audit and flow logs, and Microsoft 365 and Google Workspace logs. AI explains what each event means and how to respond.
- Spans multi-cloud and SaaS logs
- Predefined rules plus custom rules
- AI explains analysis, response and prevention
SCA
Builds SBOMs from the dependencies of containers, serverless functions, virtual machines and repositories, and continuously manages vulnerability, end-of-life, license and supply chain risks.
- AWS, Azure, Google Cloud plus GitHub and GitLab
- Prioritized with KEV, EPSS and JVN
- Automatic checks on pull requests
03Security Inspect
Find weaknesses before attackers do
AutoPentest
AI agents carry out reconnaissance, enumeration, vulnerability verification and reporting. Run penetration tests whenever and as often as you need, under guardrails that keep them within scope.
- Automated from recon to verification to reporting
- Guardrails block out-of-scope traffic
- Runs inside your AWS account
SAST
AI reads the code behind candidates detected by Semgrep, traces the data flow, and reports only what is truly exploitable. It also looks for authorization gaps that patterns can't find.
- AI filters out false positives
- Actively hunts for authorization gaps and business logic flaws
- From a zip or a Git repository
Mobile App Assessment
Static assessment of Android (APK) and iOS (IPA) apps against OWASP MASVS. Just upload the app to surface issues in configuration, cryptography, network communication and data storage.
- Follows OWASP MASVS / MASTG
- Supports Flutter, React Native and more
- Just upload the app
Related services
Services that protect new entry points into web services, such as generative AI apps and file upload features.
LLM Firewall
Inspects input before it reaches your generative AI app, with a single API. Detects prompt injection, personal and confidential information, web attacks, harmful content and obfuscated input.
- Detects injection with ML and rules
- Covers Japan-specific data such as My Number
- Removes obfuscation before analysis
MalScan
Automatically analyzes files stored in Amazon S3 and determines whether they are suspected malware. An input-side safeguard for services that accept file uploads from users.
- Automatic inspection on S3 upload
- Per-format analysis with verdict reasons
- IOCs to your SIEM via STIX / TAXII
Platform
How the platform is built
CyberForces arranges services with different roles on top of a single unified console. It currently offers 3 areas, “Web Security”, “Cloud Security” and “Security Inspect”, and each connects to your environment with the minimum permissions it needs. Services in new areas will also join this same structure.
Unified console
All services on one screen with one account. Adding services does not add more logins or more permission management.
- Single sign-on (one account for all services)
- Permission management by organization (tenant) and group
- Role-based access control, such as view-only or able to run
- Japanese / English display switching
- ASMFind
- Threat intelligenceKnow
- WAAPStop
- Defacement detectionNotice
- AutoPentestPenetration testing
- SASTCode assessment
- Mobile App AssessmentApp assessment
- LLM FirewallLLM protection
- MalScanFile inspection
Your environment
Each service connects with only the permissions it needs. Current connection targets fall roughly into these 3 types.
Public websites and APIs
Register domains or URLs, or connect to AWS WAF (WAAP). Defacement detection and ASM can start with external observation alone.
Cloud accounts
For AWS, a mostly read-only IAM role is created with CloudFormation. Some services also support Azure, Google Cloud and OCI.
Applications and source code
Upload source code zip files or repositories, or mobile app binaries. The penetration test runtime is launched inside your AWS environment.
- Connection methods and permissions differ by service. They are described under “Targets and delivery” on each service page.
- We are expanding the covered areas step by step. Services in new areas are added to the same console and the same account.
How it fits together
Find, verify, fix and protect
Weaknesses found by inspection stay covered by defenses until they are fixed. Combine services to keep this cycle running.
Find
Continuously identify externally visible assets, cloud misconfigurations and vulnerabilities.
ASM / Cloud SecurityVerify
Verify, using an attacker's methods, whether the weaknesses found can really be exploited.
AutoPentestFix
Turn code, dependency and configuration issues into fixes, highest priority first.
SAST / SCA / CSPMProtect and monitor
Until fixes are in, the WAF stops attacks, and you notice defacement and suspicious operations right away.
WAAP / Defacement detection / CSEM
↻ Re-test after fixes, then the next cycle
AI in operations
The work AI does
AI in CyberForces is not there for show. We place it where operations run short of hands. Here is what it does in each service.
Compiles proposed exclusions for false blocks every day and estimates the impact of rule changes in advance. AI summarizes each day's situation in a briefing.
Learn more →AutoPentestAn AI agent carries out reconnaissance, enumeration and verification the way an attacker would, and compiles the findings into a report. Every command it runs is logged.
Learn more →SASTReads static analysis findings in the context of the code and removes those that cannot actually be exploited before reporting.
Learn more →Mobile App AssessmentAI reviews the analysis tool output from the OWASP MASVS perspective and organizes the items that need checking.
Learn more →Defacement detectionImage recognition AI compares page changes and suppresses alerts for those it can judge to be normal updates. When it cannot decide, it errs on the safe side.
Learn more →CSPM / CSEMAI explains what detected misconfigurations and events mean and how to address them. The AI runs on your Amazon Bedrock.
Learn more →AI proposes and summarizes; people decide
Actions that affect production are, by default, reviewed before they are applied. In WAAP, you can choose “Off / Suggest / Auto” for each feature.
What was done is recorded
What AI proposed and executed is recorded and can be reviewed later.
AI can run under your control
AI in Cloud Security runs on your Amazon Bedrock, and you manage its usage fees and model selection.
Trust by design
Built securely, because it is a security product
Analysis runs inside your cloud
The AutoPentest execution environment, WAAP log analysis, the SCA scanner and more run inside your cloud account. Log and image contents are not taken out; CyberForces receives only findings and aggregate values.
Only authorized targets are inspected
Penetration tests are limited to the hosts and networks registered as in scope, and commands aimed outside that scope are blocked. ASM active checks run only against targets for which ownership and impact have been confirmed and agreed to.
Least-privilege integration
Integration with your environment goes through an IAM role created with CloudFormation. An external ID pins the caller, and only the permissions each feature needs are granted.
Every operation is logged
Audit logs record who ran or changed what, and when. Group-based permission management lets you separate people who can only view from people who can execute.
Classmethod Group
The Classmethod Group handles everything,
from development to operation and sales
CyberForces is a service developed, operated and sold entirely by the Classmethod Group, an AWS Premier Tier Services Partner, the highest AWS partner tier. You get the expertise built through cloud implementation and operations support, together with the development capability of the group's dedicated security company, as a single service.
Built by a dedicated security company
Development is handled by Classmethod Security, Inc. (founded in 2019), the group's dedicated security company. It holds a patent on a method for detecting fraudulent access requests, and designs and implements its detection engines, use of AI and automation in-house. Results of joint research with a university are also incorporated into the products.
Top-tier AWS partner
Classmethod has been continuously certified as an AWS Premier Tier Services Partner since 2015. It received the AWS “Consulting Partner of the Year – Japan” award in 2026 (second consecutive year, fifth time overall), and the “Global SI Partner of the Year” award in 2022.
Extensive support record
Technical support for more than 5,600 companies and more than 40,000 AWS accounts. Classmethod has the largest number of AWS Certification holders among AWS partners in Japan.
Information security certifications
Certified to ISO/IEC 27001, 27017, 27701 and 20000-1, with a SOC 2 Type 1 report.
The group's specialist team supports you hands-on
We do not just hand over a tool. Classmethod, which has supported cloud implementation and operations, and Classmethod Security, a dedicated security company, work together within the same group. From consultation before adoption until operations are established, you have one point of contact.
Contact usBefore adoption
We listen to your systems and challenges and propose which service to start with. We can also advise on your AWS environment as a whole.
During adoption
We help with initial setup, including connection steps, how to define scope, and notification design.
In operation
You can consult the security specialist team on prioritizing findings and how to proceed with remediation.
Getting started
Steps to get started
Contact us
Tell us about your challenges and target environment. We'll propose the right combination of services.
Open an account
We issue an organization account. Choose only the services you need in the console and get started.
Connect your environment
Create an integration role with CloudFormation. Some services can be started just by registering a URL or domain.
Operate and improve
Improve based on findings and reports. Receive notifications by email, Slack or webhook.
FAQ
FAQ
How are services contracted?
Each service is contracted individually. Choose only what you need, and add more later. If you use multiple services, you manage them with the same account and console.
Which clouds are supported?
WAAP (AWS WAF operations automation) and the AutoPentest execution environment target AWS. Cloud Security supports AWS, Azure, Google Cloud and OCI, and CSEM can also monitor Microsoft 365 and Google Workspace logs (coverage varies by service). ASM, defacement detection, SAST and mobile app assessment can be used regardless of cloud.
Will inspections affect my production services?
Inspections are limited to targets registered as in scope. ASM active checks, which send real attack patterns from outside, run only against targets whose ownership and impact you have confirmed and agreed to. Even so, we cannot say load or side effects are zero, so we recommend running your first penetration test against a test environment or during off-peak hours.
Can we use it without a dedicated security specialist?
Findings are shown with their severity and how to address them, and things like WAF exclusions can be applied in one click. If you need help with onboarding or interpreting results, please contact us.
Tell us what you need to protect
Tell us about your systems and challenges, and we will propose the right combination of services. Demos are available on request.