Automated network penetration testing
Test whether an intruder could reach your critical systems. AutoAttack runs an autonomous campaign inside your network, follows the access it gains and reports whether it reached the objective you set.
Start a free network testChoose the access you need to protect.
An internal network penetration test starts from a position you authorize. You can begin without credentials or supply an account to test what a compromised identity could reach. The campaign attempts supported techniques against the systems in scope and uses its results to choose further tests.
- Directory control
- Could a foothold lead to Domain Admin? Test Active Directory takeover from the starting access you choose.
- Sensitive data
- Could an intruder read a named database or file share? Set a data-access objective and agree on the evidence needed.
- Backup systems
- Could an intruder administer the backup server? Test the access that exposes your backups as part of ransomware readiness.
The internal network testing guide works through the starting position, authorized ranges and evidence for a hypothetical finance-share assessment.
Run one temporary container.
Deploy from a dedicated Linux host with full root access, rootful Docker and network access to your authorized targets. The deployment host needs outbound HTTPS to AutoAttack. Target computers do not need a persistent testing agent.
Choose a host on the network segment you want to assess. An employee-network test and a server-network test can expose different routes. Set scope, exclusions and permissions before deployment, then use the Docker command from your campaign page.
Follow the access that reached your objective.
The campaign report connects access gains with the recorded steps that enabled them. Inspect the evidence and recommended fix beside each step, then use the route to decide which exposure or permission to address.
After a network or permission change, create a fresh campaign with the starting position and scope needed to test the affected access. Keep those conditions with the result when reviewing it with the system owner.
The report-reading guide explains that handoff. The published benchmarks show recorded campaigns with their test conditions and methods.
Review a free campaign before subscribing.
The free report shows the access gained, technique and weakness labels, and consistent anonymous target names. A subscription reveals the target identities, captured evidence and recommended fixes, and includes unlimited campaigns and agents.
Annual pricing in USD uses the hosts discovered across your campaigns. Each rate applies only to hosts in its band. Every paid band includes the same features, and discovery has no host cap.
| Hosts discovered | Per host / year |
|---|---|
| 1–100 | $49 |
| 101–500 | $34 |
| 501–2,500 | $19 |
| 2,501–10,000 | $9 |
| 10,001+ | Contact sales ↗ |
Put your network access to the test.
Choose an objective and review the authorized scope before running your campaign.
Start a free network test