Home / About CyberForces
What is CyberForces
CyberForces is a platform developed, operated and sold by the Classmethod Group that delivers the cybersecurity measures enterprises need on a single foundation. Services that “protect” and services that “inspect” share the same console, and we currently focus on public web, cloud and applications. We will continue to expand the areas we cover.
Background
Why one foundation
What you protect grows faster than you can track
Campaign sites, test environments, subdomains set up by contractors, newly connected cloud accounts. The things you need to protect multiply before your inventory can catch up.
Check intervals do not match the pace of change
Even between annual assessments and audits, releases ship every week and new vulnerabilities are disclosed every day. With checks spaced far apart, weaknesses that slip in between go unnoticed.
Separate tools mean people have to connect them
When WAF, vulnerability assessment and cloud configuration checks are all separate tools, cross-checking results and setting priorities becomes manual work for your staff, and it stops working when those people change.
Concept
Protect and inspect.
Keep both running without stopping.
Security is not something you do once and finish. The things you need to protect keep growing, environments change every day, and new vulnerabilities are disclosed daily. CyberForces puts services that “protect” by stopping attacks and services that “inspect” by finding weaknesses first on a single foundation. It is a platform for keeping the cycle of find, verify, fix and protect running without stopping. Its scope will not stop at public web and cloud; we are expanding it to cover enterprise cybersecurity as a whole.
“Protect” and “inspect” on one foundation
When defense and inspection live in separate tools, protection falls behind in the gap before a weakness found in inspection is fixed, and what is happening on the defense side does not inform inspection. With CyberForces, you see the results of both in the same console and decide your next move.
AI handles day-to-day operations
Finding WAF false blocks, running penetration tests, filtering out false positives in static analysis, judging whether a defacement is real. AI takes on work that has consumed experts' time, so people can focus on decisions and improvement. For automation that affects production, you can choose the level for each feature.
Expand your coverage on one foundation
Every service can be contracted individually and added to the same account and console. Start with protecting your public web, or start with checking your cloud configuration. Wherever you begin, services you add later appear on the same screen, and services in new areas join the same foundation.
For executives and business owners
See the status on one screen
Your team sees the state of defenses, environment configuration and weaknesses found in inspections in the same console. Even as your coverage grows, there is no need to gather numbers from multiple tools for every report.
From annual checks to always-on
Instead of confirming security only at the time of an assessment or audit, you can move to a setup that keeps tracking daily changes. Incident response can also start from identifying the scope of impact.
Start where you need, step by step
There is no need to cover every area from day one. Start where the risk is highest and expand as you confirm the results. Contracts are per service, and services in new areas can be added to the same foundation.
Platform
How the platform is built
CyberForces arranges services with different roles on top of a single unified console. It currently offers 3 areas, “Web Security”, “Cloud Security” and “Security Inspect”, and each connects to your environment with the minimum permissions it needs. Services in new areas will also join this same structure.
Unified console
All services on one screen with one account. Adding services does not add more logins or more permission management.
- Single sign-on (one account for all services)
- Permission management by organization (tenant) and group
- Role-based access control, such as view-only or able to run
- Japanese / English display switching
- ASMFind
- Threat intelligenceKnow
- WAAPStop
- Defacement detectionNotice
- AutoPentestPenetration testing
- SASTCode assessment
- Mobile App AssessmentApp assessment
- LLM FirewallLLM protection
- MalScanFile inspection
Your environment
Each service connects with only the permissions it needs. Current connection targets fall roughly into these 3 types.
Public websites and APIs
Register domains or URLs, or connect to AWS WAF (WAAP). Defacement detection and ASM can start with external observation alone.
Cloud accounts
For AWS, a mostly read-only IAM role is created with CloudFormation. Some services also support Azure, Google Cloud and OCI.
Applications and source code
Upload source code zip files or repositories, or mobile app binaries. The penetration test runtime is launched inside your AWS environment.
- Connection methods and permissions differ by service. They are described under “Targets and delivery” on each service page.
- We are expanding the covered areas step by step. Services in new areas are added to the same console and the same account.
How it fits together
Find, verify, fix and protect
Weaknesses found by inspection stay covered by defenses until they are fixed. Combine services to keep this cycle running.
Find
Continuously identify externally visible assets, cloud misconfigurations and vulnerabilities.
ASM / Cloud SecurityVerify
Verify, using an attacker's methods, whether the weaknesses found can really be exploited.
AutoPentestFix
Turn code, dependency and configuration issues into fixes, highest priority first.
SAST / SCA / CSPMProtect and monitor
Until fixes are in, the WAF stops attacks, and you notice defacement and suspicious operations right away.
WAAP / Defacement detection / CSEM
↻ Re-test after fixes, then the next cycle
AI in operations
The work AI does
AI in CyberForces is not there for show. We place it where operations run short of hands. Here is what it does in each service.
Compiles proposed exclusions for false blocks every day and estimates the impact of rule changes in advance. AI summarizes each day's situation in a briefing.
Learn more →AutoPentestAn AI agent carries out reconnaissance, enumeration and verification the way an attacker would, and compiles the findings into a report. Every command it runs is logged.
Learn more →SASTReads static analysis findings in the context of the code and removes those that cannot actually be exploited before reporting.
Learn more →Mobile App AssessmentAI reviews the analysis tool output from the OWASP MASVS perspective and organizes the items that need checking.
Learn more →Defacement detectionImage recognition AI compares page changes and suppresses alerts for those it can judge to be normal updates. When it cannot decide, it errs on the safe side.
Learn more →CSPM / CSEMAI explains what detected misconfigurations and events mean and how to address them. The AI runs on your Amazon Bedrock.
Learn more →AI proposes and summarizes; people decide
Actions that affect production are, by default, reviewed before they are applied. In WAAP, you can choose “Off / Suggest / Auto” for each feature.
What was done is recorded
What AI proposed and executed is recorded and can be reviewed later.
AI can run under your control
AI in Cloud Security runs on your Amazon Bedrock, and you manage its usage fees and model selection.
Trust by design
Built securely, because it is a security product
Analysis runs inside your cloud
The AutoPentest execution environment, WAAP log analysis, the SCA scanner and more run inside your cloud account. Log and image contents are not taken out; CyberForces receives only findings and aggregate values.
Only authorized targets are inspected
Penetration tests are limited to the hosts and networks registered as in scope, and commands aimed outside that scope are blocked. ASM active checks run only against targets for which ownership and impact have been confirmed and agreed to.
Least-privilege integration
Integration with your environment goes through an IAM role created with CloudFormation. An external ID pins the caller, and only the permissions each feature needs are granted.
Every operation is logged
Audit logs record who ran or changed what, and when. Group-based permission management lets you separate people who can only view from people who can execute.
Classmethod Group
The Classmethod Group handles everything,
from development to operation and sales
CyberForces is a service developed, operated and sold entirely by the Classmethod Group, an AWS Premier Tier Services Partner, the highest AWS partner tier. You get the expertise built through cloud implementation and operations support, together with the development capability of the group's dedicated security company, as a single service.
Built by a dedicated security company
Development is handled by Classmethod Security, Inc. (founded in 2019), the group's dedicated security company. It holds a patent on a method for detecting fraudulent access requests, and designs and implements its detection engines, use of AI and automation in-house. Results of joint research with a university are also incorporated into the products.
Top-tier AWS partner
Classmethod has been continuously certified as an AWS Premier Tier Services Partner since 2015. It received the AWS “Consulting Partner of the Year – Japan” award in 2026 (second consecutive year, fifth time overall), and the “Global SI Partner of the Year” award in 2022.
Extensive support record
Technical support for more than 5,600 companies and more than 40,000 AWS accounts. Classmethod has the largest number of AWS Certification holders among AWS partners in Japan.
Information security certifications
Certified to ISO/IEC 27001, 27017, 27701 and 20000-1, with a SOC 2 Type 1 report.
The group's specialist team supports you hands-on
We do not just hand over a tool. Classmethod, which has supported cloud implementation and operations, and Classmethod Security, a dedicated security company, work together within the same group. From consultation before adoption until operations are established, you have one point of contact.
Contact usBefore adoption
We listen to your systems and challenges and propose which service to start with. We can also advise on your AWS environment as a whole.
During adoption
We help with initial setup, including connection steps, how to define scope, and notification design.
In operation
You can consult the security specialist team on prioritizing findings and how to proceed with remediation.
FAQ
FAQ
Is it worth it if we already have a WAF or vulnerability assessments?
Yes. WAAP connects your existing AWS WAF as is and automates its operation. For assessments, you can use AutoPentest and SAST to fill the gaps between annual expert assessments.
Can a small team run it?
Findings come with severity and remediation steps, and settings such as WAF exclusions can be applied in one click. You can consult the Classmethod Group's specialist team on initial setup and on interpreting results.
Do we need to adopt every service?
No. Services can be contracted individually, so you can start with what you need and add more later. Added services appear in the same console.
Tell us what you need to protect
Tell us about your systems and challenges, and we will propose the right combination of services. Demos are available on request.