What makes PentestOps different

Start here. The full capability list further down is the detail behind these five.

Safe automated exploitation, with evidence

A detected vulnerability is a hypothesis. PentestOps tests it. The Auto Exploitation Framework runs safe, auditable proof-of-exploit against confirmed findings, and a strategy engine picks the best technique for each one rather than firing everything at everything. Phased chains turn a single weak credential into a demonstrated pivot, so your team prioritises on validated impact instead of a raw severity list. Every action is gated by per-tenant Rules of Engagement that stop activity outside authorised assets, and every step leaves a full evidence trail.

Self-hosted AI by default

PentestOps AI runs on infrastructure Extranet Systems operates, so your scan data is not sent to third-party model providers to get analysed. It handles vulnerability analysis, context-aware risk scoring, attack-chain prediction, business impact analysis and executive report drafting. External providers can be enabled per tenant if you want them, but that is a decision you make, not the default you inherit.

An outbound-only on-premise agent

Internal testing usually arrives with a VPN, a jump host and a firewall change request. The PentestOps agent is a single container, RPM or DEB package that dials out over TLS 443 through a reverse tunnel. It deploys in about 5 minutes and needs 0 inbound firewall rules, with no listener for anyone to find. Discovered credentials are redacted before findings ship, so they never leave the agent in plaintext, and updates run in operator-controlled change windows you can freeze indefinitely.

Attack-path and technique mapping

Findings are correlated, not just counted. CVE correlation, CVSS v3.1 scoring, exploit availability and CISA KEV prioritisation feed a picture of how an attacker moves from an exposed service to a privileged account. That matters most in Active Directory environments, where a handful of individually unremarkable issues chain into domain compromise, and it is what turns a long backlog into a short list of things that actually change your risk.

A compliance reporting engine, not a PDF export

Findings are automatically mapped to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes. Those are the frameworks your findings map to in reports; they are not a claim that anyone is certified against them. Output covers executive summary, technical detail, captured evidence and prioritised remediation, in multiple formats including PDF, CSV and JSON/API.

See it against your own attack surface

Run a free demo scan against a domain you own, or start a 7-day trial on any tier. A card is required to start your trial and is only charged after it ends, unless you cancel first.

Full platform capabilities

The complete toolkit behind those five differentiators, from perimeter recon through cloud posture to reporting and multi-tenancy.

External & Internal Scanning

24+ external recon modules and 18+ internal modules running through a reverse SOCKS5 tunnel from your on-prem agent. Stealth and custom profiles for noise-sensitive environments.

  • Fast port discovery + deep service enumeration
  • Service version + WAF detection
  • SSL/TLS, DNS, subdomain, email-security audit
  • Stealth, balanced, and aggressive profiles

Vulnerability Detection

Automated vulnerability scanning with CVE correlation and CVSS scoring for accurate risk assessment.

  • CVE database integration
  • CVSS v3.1 scoring
  • False positive reduction
  • Exploit availability check

Web & API Testing

OWASP Top 10 + API Top 10 coverage with template based detection, custom checks, and live findings streamed to the dashboard as they are discovered.

  • SQLi, XSS, SSRF, IDOR, auth bypass
  • REST + GraphQL API security
  • M365 / Azure AD audit
  • Real-time WebSocket finding stream

Asset Inventory & AI Discovery

Continuous asset inventory with AI-powered classification, bulk CSV/XLSX import, agent-based LAN discovery, and 7-day re-verification lifecycle. Drift ledger captures every change.

  • AI asset classification + criticality
  • Multi method LAN discovery via on prem agent
  • Cloud sync (AWS, Azure, GCP, M365)
  • Drift detection + change ledger

Cloud Security (CSPM)

800+ automated security checks across AWS, Azure, and GCP. Credential-based API auditing with continuous misconfiguration detection.

  • AWS: 572 checks across 83 services
  • Azure: 165 checks across 20 services
  • GCP: 100 checks across 13 services
  • ECR/ACR/GCR container image CVE scanning
  • CIS Benchmarks for AWS / Azure / GCP (Prowler) and Kubernetes node + control-plane (kube-bench)
  • 8 compliance reporting frameworks (OWASP, PCI-DSS, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001), plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes

Infrastructure Assessment

Deep infrastructure security testing across Active Directory, container, and Kubernetes environments. Kubernetes auditing is fully agentless: onboard a cluster by pasting a kubeconfig, with no permanent agent or DaemonSet to install.

  • Active Directory enumeration + privilege escalation paths
  • Agentless Kubernetes via kubeconfig: GKE (incl. Autopilot), EKS (incl. Fargate), AKS, OpenShift, k3s, on-prem
  • API posture audit (kubeaudit): RBAC, securityContext, privileged pods, capabilities, network policy, image provenance
  • Node + control-plane CIS Kubernetes Benchmark via a short-lived, auto-cleaned in-cluster job (kube-bench)
  • On fully-managed clusters (Autopilot, Fargate), node CIS routes through the cloud configuration audit while API posture still runs
  • Docker / container image security scanning

Compliance Reporting

Generate compliance-ready reports for major frameworks with detailed evidence and remediation guidance.

  • OWASP Top 10 mapping
  • PCI-DSS v4.0 mapping
  • NIST 800-53 controls
  • SOC2, HIPAA, GDPR
  • ISO 27001, SMB1001

Analytics & Trending

Track security posture over time with scan comparisons and remediation velocity metrics.

  • Scan-over-scan comparison
  • Trend & SLA analysis
  • Executive dashboards
  • Custom metrics & alerts

Continuous Monitoring (EASM)

Agentless External Attack Surface Management with HMAC-signed log shipping, change and drift alerting, and continuous re-checks of your perimeter between scheduled scans.

  • Drift & asset-change alerts + email + webhook
  • Customer log shipper (HMAC-signed ingest)
  • 24/7 monitoring of public assets
  • Slack-compatible incident webhooks

Auto Exploitation Framework

Safe, auditable proof of exploit on confirmed findings. The strategy engine auto picks the best technique per finding; chained pipelines turn one weak credential into a full pivot.

  • Credential brute force, VPN, network device, container
  • Phased exploit chains with evidence carry over
  • Per tenant Rules of Engagement gates
  • Full evidence trail + audit log

AI Guided Remediation

Per finding AI remediation with clear explanation, validated fix steps, and one click playbook deployment via the on prem agent for SSH managed targets.

  • Context aware risk + business impact scoring
  • Auto generated patch ready playbooks
  • SSH key discovery + safe execution
  • Roll back on validation failure

MSP & Multi-Tenancy

Run an MSP practice on isolated per-tenant Kubernetes namespaces with custom domains, custom SSL, Okta SSO, GitOps provisioning, and per-tenant pricing tiers.

  • Per-tenant namespace + DB isolation
  • Custom & auto-managed SSL (ACME)
  • Tenant SSO (Okta) for Pro & Enterprise
  • Fleet orchestrator + force-update agents

Platform Security

ISO/IEC 27001:2022 certified and built to SOC 2-aligned controls, with encrypted secrets injection, encryption at rest, RBAC, MFA, and a full audit trail of every scan, exploit, and config change.

  • Encrypted secrets vault with dynamic injection
  • JWT + session bound auth, MFA
  • Per IP login rate limiting
  • 365-day audit-log retention

Frequently Asked Questions

What does the platform actually test?

Full-stack coverage in one platform: 24+ external recon modules and 18+ internal modules, web application and API testing across the OWASP Top 10 and API Top 10 (REST and GraphQL), identity testing including Active Directory and M365, 800+ automated cloud checks across AWS, Azure, GCP and M365, and agentless Kubernetes auditing. Pick the scope you care about from the solutions library, or read how the phases fit together in our methodology.

How does safe automated exploitation work?

Once a finding is confirmed, the strategy engine selects the technique most likely to prove it and executes that attempt under per-tenant Rules of Engagement. Scope enforcement stops any activity against assets you have not authorised, and chained pipelines can show how one weak credential becomes a pivot deeper into the network. Each step carries its own evidence into the report, so prioritisation is based on proof rather than a severity score alone. See attack path validation.

Where does the AI run, and is my scan data sent to a third party?

PentestOps AI is self-hosted by default. It runs on infrastructure Extranet Systems operates, so findings, evidence and scan data are not handed to a third-party model provider. External model providers can be enabled per tenant if you prefer, entirely at your discretion. The AI handles vulnerability analysis, context-aware risk scoring, attack chain prediction, business impact analysis, executive report drafting and per-finding remediation guidance. More detail on AI penetration testing.

Do cloud and Kubernetes auditing require an agent?

No. Cloud posture auditing runs from read-only credentials you issue for AWS, Azure, GCP or M365, and covers configuration, IAM, storage and network checks against provider baselines and CIS Benchmarks. Kubernetes auditing is fully agentless via a customer-supplied read-only kubeconfig, with no permanent agent and no DaemonSet to install: an API posture review runs on every cluster and node-level CIS checks run as a short-lived, auto-cleaned in-cluster job. See Kubernetes security testing.

What is Continuous Monitoring, and how is it different from a scan?

Continuous Monitoring is agentless External Attack Surface Management. It re-checks your public footprint between scheduled scans, tracks drift through a full change ledger, and raises real-time alerts for new or missing assets and unauthorised change, with HMAC-signed log shipping for your own pipeline. A scan is a deep assessment at a point in time; monitoring is the always-on layer between those scans. It is an Enterprise capability, described further under EASM.

What do the reports include, and can I get the data out?

Reports pair an executive summary with technical detail, captured evidence and prioritised remediation, and map findings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes. Multiple formats are available including PDF, CSV and JSON/API, and drift, asset-change and incident events can be pushed to email or a Slack-compatible webhook so findings reach the systems your team already watches.

Is every feature available on every plan?

No, capability scales with the tier. Starter covers external, internal, web application and API testing with basic compliance reporting. Professional adds cloud auditing, AI-guided remediation, full compliance reporting, scheduled scans, scan comparison, integrations and team management on an isolated workload. Enterprise adds email and M365 auditing, advanced exploitation, continuous monitoring, SSO, custom retention and data-residency options, and an on-premise deployment option. Current inclusions are on the pricing page.

How is this different from a vulnerability scanner?

A scanner tells you a weakness may exist. PentestOps confirms whether it is genuinely exploitable in your environment, captures the evidence, and shows the chain an attacker would follow, then hands your team validated remediation steps rather than a raw severity list. Prioritisation uses CVSS v3.1 alongside exploit availability and CISA KEV status so the queue reflects real-world risk. The comparison page sets out where we sit against validation platforms, scanners and human-led services.

Ready to secure your infrastructure?

Start a 7-day trial on any tier and run your first assessment against assets you own. A card is required to start your trial and is only charged after it ends, unless you cancel first.

Start 7-day trial Compare plans Talk to sales

Want the deeper background first? Read our methodology, see how PentestOps compares, or browse the Knowledge Centre.