CHAPTER 12

Penetration Testing

Penetration testing is already well suited to be automated. The earliest scanners from CyberCop and ISS were pointed at a target IP address range and let run. Each of the 65,535 TCP ports would be scanned on each IP address in a range. As the payment card industry released requirements for frequent pentests, there was a flood of services offering continuous pentesting. There are 318 pentesting products from 214 vendors in the IT-Harvest Dashboard.

But pentesting encounters decision points where a human is often called in. There may be an exploitable misconfiguration or vulnerability that requires a custom exploit. This is where AI can play a role by making those decisions.

Here are the pentesting solutions that are AI-first:

CompanyCountryInvestment ($M)Employees
TheoriUSA$15.2M76
CybralUSA-53
ETHIACKPortugal$4.56M52
Ridge SecurityUSA$1M43
Novee SecurityIsrael-41
TuskiraUSA$30.5M41
TenzaiIsrael$75M36
DreadnodeUSA$14M21
SxipherUSA-17
VulneticUSA-13
JedsecUSA-12
OFFENSAIUSA-11
Repello AIUSA$2.5M11
RunSybilUSA-11
MenayaUSA-7
UprootSecurityUSA-7
GhostEyeUSA$0.5M4
ScourNomadCroatia-1
Veria LabsUSA-0