Home / Services / Security Inspect / AutoPentest
Security Inspect / AI-driven automated penetration testingPenetration testing when you need it,
as often as you need it.
AutoPentest is a penetration testing service in which AI agents examine your systems using the same steps as an attacker, automating everything from reconnaissance, enumeration and vulnerability verification to writing up findings in a report. The execution environment launches inside your AWS account, and guardrails block commands aimed outside the scope you register.
Challenges
Sound familiar?
Penetration tests are expensive and happen once a year
Expert penetration tests require budget and scheduling, so running one for every release isn't realistic.
Scan results alone don't show real severity
Among a large number of findings, you can't tell which are actually exploitable, so you can't set priorities.
No visibility into what happens during a test
With outsourced assessments, it's hard to confirm afterward what was done and how far it went.
Features
AutoPentest key features
01Automated, following an attacker's steps
AI agents move through reconnaissance, service enumeration, vulnerability verification and writing up findings automatically, following the same flow as a human tester.
02Profiles for each goal
Choose from Standard, Recon only, Web app, Internal Active Directory, Credential audit and Quick recon. You can also specify your own procedures.
03Broad service enumeration
Thoroughly examines exposed services, including HTTP, SSH, SMB, FTP, LDAP, Kerberos, RPC, WinRM and DNS.
04Areas behind login, too
Register test accounts in advance to include post-login screens and APIs in the test.
05Guardrails that enforce scope
Commands aimed at out-of-scope IPs or hosts are blocked before they run. If no scope is set, everything is denied, and the AI cannot change the settings.
06Every action recorded
Every command the AI attempts is recorded in the audit log. Track progress in real time in the console.
07Runs in your AWS
Test servers launch automatically in your AWS account and stop when the test ends. Traffic is outbound only, from the execution environment.
08Reports in Japanese and English
Get a report that organizes severity, reproduction steps and remediation for each finding, downloadable as a PDF. You can retest after fixing.
How it works
The same flow as a human tester,
driven automatically by AI
Unlike scanners that only match fixed patterns, AutoPentest decides its next move based on what it has found as the investigation proceeds. It digs into services using clues from reconnaissance, verifies whether weaknesses are really exploitable, and compiles the results into a report.
Reconnaissance
Uses port scans and DNS investigation to understand what is running on the target.
Enumeration
Examines each discovered service in detail, including its version, configuration and whether authentication is required.
Verification
Confirms whether known vulnerabilities and weak credentials can actually be exploited. Also tests post-login areas using registered accounts.
Reporting
Outputs a report in Japanese or English that summarizes severity, reproduction steps and remediation for each finding.
Safety by design
Even when AI is in charge,
it stays within scope
Because it automatically runs the same steps as an attack, the safety mechanisms matter most. AutoPentest enforces what may be executed independently of the AI's own judgment.
Scope check before execution
Right before the AI runs a command, the destination is checked against the registered scope and blocked if it is out of scope. If no scope is set, everything is denied.
The AI can't change it
Scope and guardrail settings cannot be changed by the AI. Attempted commands are recorded, including those that were blocked.
In your environment, only when needed
The execution environment launches in your AWS and stops when the test ends. There is no path for connecting to the execution environment from the outside.
Please note: The guardrails are a mechanism to prevent mistakes; they do not in principle prevent every possible bypass. When targeting production environments, we recommend running tests at times and with a scope chosen with the impact in mind.
Specifications
Scope and delivery
| Targets |
|
|---|---|
| Where it runs |
|
| AI models |
|
| Output |
|
| Pricing |
|
Please note: The guardrails are a mechanism to prevent mistakes; they do not in principle prevent every possible bypass. Findings, progress and records of executed commands are sent to CyberForces. When targeting production environments, we recommend running tests at times and with a scope chosen with the impact in mind.
Getting started
Getting started
Create the integration role
Use CloudFormation to create the integration role in your AWS.
Register the scope
Register the target hosts and networks and, if needed, credentials.
Run a test
Choose a profile and run. The execution environment launches automatically and stops when the test ends.
Review the report
Check the findings and reproduction steps, then retest after fixing.
FAQ
FAQ
Can it replace expert penetration testing?
Because it can be run repeatedly and often, it is well suited to filling the gaps between annual assessments. Some situations still call for an expert assessment, such as in-depth verification of business logic.
Where is test data stored?
The test execution environment and AI calls run inside your AWS account. Findings and reports are stored in CyberForces because they are managed in the console.
Works well with
AutoPentest — details and demo requests
Our team will explain deployment options and pricing for your environment.