What is Automated Penetration Testing?

vPenTest is an automated network penetration testing platform that combinesthe knowledge, methodology, processes, and toolsets of a hacker into a single,deployable SaaS platform for organizations of all sizes. vPenTest allowsorganizations to perform a penetration test within their environment at any giventime, satisfying both compliance requirements as well as meeting security bestpractices. This platform is developed and maintained solely by Vonahi Securityand is based on a framework that continuously improves over time.

 

Traditionally, organizations have to face several challenges when seeking apenetration test, including availability, experience and background, as well as lowquality deliverables that fail to effectively communicate the critical issues andremediation strategies that organizations need to adhere to in order to reducetheir overall cyber risk. Through several years of experience, certifications, industrycontributions including numerous tools, vPenTest solves a critical need fororganizations in an ever-changing threat landscape.

No more scheduling conflicts.

A full-blown penetration test — whenever you need, as often as you need.

Built on a framework and methodology that evolve with industry threats.

Backed by 10+ years of experience from OSCP, CISSP, CEH, and OSCE-certified consultants.

VALIDATED
BY EXPERTS

Combining the knowledge, skills, logic, and toolsets of numerous consultants into one, vPenTest provides consistent, high-quality results to satisfy organizational security requirements.

REAL-TIME
ACTIVITY TRACKING

An essential part of risk assessment is the ability to detect and respond to malicious activity.
vPenTest creates a separate log file for every single action performed, allowing you to correlate its activities with your monitoring and logging systems.

MEET COMPLIANCE
& BEST PRACTICES

By being able to perform a quality network penetration test whenever and as often as needed, your organization continuously meets security best practices and compliance regulations.

Our Automated Penetration Test Methodology

vPenTest combines multiple traditional methodologies into an automated process for consistent, high-value results.

EGRESS FILTERING TESTING
Automatically tests outbound traffic controls. Unrestricted outbound access can allow attackers to exfiltrate data using unmonitored ports.

AUTHENTICATION ATTACKS
When user credentials are found, vPenTest validates them and determines where they are most useful — simulating attacker privilege escalation.

PRIVILEGE ESCALATION & LATERAL MOVEMENT
Using valid credentials, vPenTest identifies valuable systems through multiple methods, including Vonahi’s own Leprechaun tool, which locates sensitive targets.

DATA EXFILTRATION
Simulates the unauthorized transfer of confidential data, logging the activity to help the organization tighten data-leak defenses.

SIMULATED MALWARE
With elevated access, vPenTest uploads simulated malware to test the effectiveness of endpoint anti-malware controls.

TIMELY REPORTING
Within 48 hours after the test, vPenTest generates an executive summary, technical report, and vulnerability report. These detailed deliverables help network staff verify findings and cross-reference with existing monitoring controls.

Assessment Capabilities

We offer two automated penetration testing services to strengthen your security program.

INTERNAL NETWORK PENTEST

Using a device connected to your internal network, this test discovers vulnerabilities within the internal environment — simulating a malicious insider or compromised system.

EXTERNAL NETWORK PENTEST

Assuming the role of an attacker from the public Internet, this test identifies security flaws such as patching, configuration, and authentication issues.