Pentest-Tools.com VPN agent (internal scanning) logo

    Pentest-Tools.com VPN agent (internal scanning)

    Securely scan internal and private networks in your Azure Cloud with the Pentest-Tools.com VPN Agent for comprehensive vulnerability assessments and penetration tests.

    Ratings and reviews

    4.8
    107 ratings
    3 star
    2 star
    1 star
    86%
    14%
    0%
    0%
    0%
    0 AWS reviews
    |
    107 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (107)
    Brad L.

    Easy Website Setup and Internal Pen Testing with Plug-ins

    Reviewed on Jul 16, 2026
    Review provided by G2
    What do you like best about the product?
    We use the product as part of a cyber package for our customers. It's quite easy to add the customer's website or to perform an internal pen test using their plug-ins.
    What do you dislike about the product?
    I haven't found any really. It suits our needs
    What problems is the product solving and how is that benefiting you?
    It helps us mostly with website and application pen tests.
    Remko S.

    Easy to Use, Fast Scans, and Responsive Support

    Reviewed on Jul 16, 2026
    Review provided by G2
    What do you like best about the product?
    Easy-to-use interface—within minutes, you’ll understand where to click and how to start your scans. The tool is responsive and scans quickly. The pricing is competitive. Support is also fast when contacting the Pentest-Tools team.
    What do you dislike about the product?
    The scheduling options for scans are unfortunately limited. Right now, they can only be set to run weekly or monthly. One customer needs scans every two weeks on the same day of the week, so I have to manually add and schedule them each time.
    What problems is the product solving and how is that benefiting you?
    Consistent reports that every employee in our company can reproduce. The reports are also easy to read, even for less technical customers.
    Computer Software

    Easy to Use, Complete Product with Excellent Support

    Reviewed on Jul 15, 2026
    Review provided by G2
    What do you like best about the product?
    Easy to use, complete product with excellent support.
    What do you dislike about the product?
    Perhaps a lower price of the product for a lower tier.
    What problems is the product solving and how is that benefiting you?
    Fixing security vulnerabilities of the web apps we build for our customers
    Jason O.

    Easy-to-Use Interface with Great Tooling at a Good Price

    Reviewed on Jul 12, 2026
    Review provided by G2
    What do you like best about the product?
    Easy to use interface with good tooling for a good price.
    What do you dislike about the product?
    There are some inconsistencies in the UI but nothing unmanageable
    What problems is the product solving and how is that benefiting you?
    It is part of our monthly internal penetration testing workstream. It does this job very well.
    Filip N.

    Powerful Tool

    Reviewed on Jul 11, 2026
    Review provided by G2
    What do you like best about the product?
    Complexity of the software and simple setup
    What do you dislike about the product?
    None. All features work well, and we can see everything that’s necessary.
    What problems is the product solving and how is that benefiting you?
    Keeps eye on our connection.
    Insurance

    Cost-Effective, Accurate, and Fast—Easy Setup and Smooth Integrations

    Reviewed on Jul 02, 2026
    Review provided by G2
    What do you like best about the product?
    Great tool—cost-effective and accurate, and the speed is a nice bonus as well. It’s easy to find what you need and set up a test. The integrations are simple to set up and maintain, and the onboarding process was straightforward.
    What do you dislike about the product?
    I don’t have any dislikes. Everything works exactly as described, and I haven’t run into any issues so far.
    What problems is the product solving and how is that benefiting you?
    We needed a cost-effective way to monitor our code environment and stay on top of threats and emerging exploits, and this helped us do that.
    SangramGupta

    Platform has strengthened attack surface visibility and vulnerability validation but needs better remediation tracking

    Reviewed on Jun 12, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Pentest-Tools.com is primarily utilizing the tool for vulnerability assessment, external attack surface analysis, and security validation activities. The platform is useful for my project for quickly identifying security weaknesses in internal-facing, internet-facing, and externally-facing assets and supporting pen testing workflows without any kind of extensive setup or infrastructure.

    The types of assets I am focusing on are both internal assets and external assets. For internal assets, I have used vulnerability management solutions, carried out vulnerability assessments, and gathered vulnerability details so that I can prioritize the vulnerabilities. For external assets or internet-facing assets, the criticalities of the vulnerabilities are very severe, and that is why a pen test is required to showcase the exploitation of the vulnerabilities and also to create a pen test report, which demonstrates how external attacks can happen on those assets. For that purpose, I have used Pentest-Tools.com.

    Apart from vulnerability assessments, I also focus on network security validation, web application security testing, and reconnaissance and asset discovery, which have all been accomplished using that tool.

    What is most valuable?

    The best features that Pentest-Tools.com offers include vulnerability scanning, which I have used extensively. The platform provides scanning using useful templates for all assets, whether internal or external-facing. Additionally, it can deliver external attack surface visibility, allowing me to get proper visibility of the assets and identify potential exposures of risks in the external attack surface. Furthermore, I have included some web applications in my project scope, and the platform offers useful web application testing capabilities that can help identify common application security weaknesses and follow the OWASP Top 10 to identify vulnerabilities and weaknesses, which are the primary use cases I have utilized in my project using that tool.

    Pentest-Tools.com has positively impacted my organization in two significant ways. First, asset discovery and reconnaissance help provide all of the weaknesses and data of the applications under CMDB, as well as the state of the applications or servers in scope, which is very useful when preparing a plan for a vulnerability assessment. Second, exposure management or external attack surface management is valuable for external assets or internet-facing assets, helping gather all the vulnerabilities and weak points while providing a comprehensive report that assists the remediation team in acting on the vulnerabilities as soon as possible.

    What needs improvement?

    Pentest-Tools.com could improve in a couple of areas. First, the reporting flexibility could be enhanced. Second, there should be additional automation for remediation tracking since it currently lacks automation for this, requiring me to track remediations manually using the reports. Third, deeper integration with vulnerability management workflows could be beneficial, as I should have more options for integrating the tool with other security pen testing or application scanning tools.

    Regarding Pentest-Tools.com's AI capabilities, I believe there should be proper boundaries managed by their team in terms of governance and security, especially when the tool provides false positive vulnerabilities. These should also be detected on the governance side and resolved within the tool rather than manually, indicating an area for improvement in governance and compliance.

    In terms of the accuracy and reliability of Pentest-Tools.com's AI-generated output, I feel it can provide comprehensive output and reports. However, as it is AI-generated, the pentester or user should thoroughly check and validate the output before presenting it to stakeholders or the remediation team.

    For how long have I used the solution?

    I have used Pentest-Tools.com for almost one year for an offensive security project.

    What do I think about the stability of the solution?

    In my experience, Pentest-Tools.com is quite stable, and I have had a good experience using the tool without any significant downtime or reliability issues.

    What do I think about the scalability of the solution?

    Pentest-Tools.com's scalability is impressive. It has handled more than 50,000 assets effectively, and although I am unsure how it will perform with an asset count exceeding 100,000 or 200,000, my experience indicates that it is quite good and scalable.

    How are customer service and support?

    I have not worked on the implementation side of Pentest-Tools.com, but I have contributed from the operations perspective. Regarding customer support, I have reached out to them for assistance with some false positive issues, and they have been very cooperative and supportive in resolving those issues, indicating a good and helpful customer support experience.

    Which solution did I use previously and why did I switch?

    I have used many solutions for various project engagements, including Qualys, Tenable, Rapid7, and InsightVM, but I have not changed anything. The decision to adopt Pentest-Tools.com was based on customer requirements, leading to the implementation of this tool in my project.

    Which other solutions did I evaluate?

    I have not evaluated any other options before choosing Pentest-Tools.com, as it was the client's expectation for me to adopt this tool.

    What other advice do I have?

    My advice for others considering Pentest-Tools.com is that if you are working in vulnerability management or any kind of offensive security project with numerous internet-facing applications alongside internal applications, and you want to highlight the risks in real-time, you can adopt this tool to protect your organization and focus on managing the risks effectively. I would rate Pentest-Tools.com a seven out of ten based on my experience with various vulnerability solutions. I choose a seven because Pentest-Tools.com is pretty good, but there are some flaws, such as the integration issues and the lack of automation for remediation tracking, which lead me to reduce three points from a perfect score of ten.

    Vivek B.

    Easy to Use, Powerful Reporting Tool

    Reviewed on Nov 05, 2025
    Review provided by G2
    What do you like best about the product?
    I have been using Pentest-Tools.com for 1.5 years and find it immensely valuable for conducting penetration tests to identify system vulnerabilities and understand the mitigation processes. The tool efficiently provides comprehensive reports on all detected vulnerabilities in the system and environment, which aids in compliance with standard processes like ISO. I appreciate its straightforward process, making management easy even for someone who isn't a DevOps professional. Among its features, the website vulnerability scanner and network scan tools stand out due to their user-friendly, automated nature and the clarity of the reports they produce. Additionally, the dashboards and scheduling features are commendable for their ease of use. The initial setup was quite easy, which is a significant advantage. Overall, I rate it a 9 out of 10 on the likelihood of recommending it to others.
    What do you dislike about the product?
    I find that the scan test reports with Pentest-Tools.com sometimes take longer than expected, which can be a bit of a hassle when trying to work efficiently. Additionally, the lack of report customization is a drawback, as I am unable to edit reports, include or exclude specific findings, or apply whitelabeling and branding. Custom templates are also not available, which limits the flexibility and personalization of the reports.
    What problems is the product solving and how is that benefiting you?
    I use Pentest-Tools.com to identify vulnerabilities and ensure compliance with standards like ISO, benefiting from its ease of use, clear reports, and automated scanning features.
    Omar B.

    why i would recommend pen-test tools.com to small teams

    Reviewed on Oct 09, 2025
    Review provided by G2
    What do you like best about the product?
    Pentest-Tools.com has been a big part of our journey toward being fully ISO 27001 and GDPR audit-ready. The platform made vulnerability management much easier for us — from early discovery to detailed remediation reports that our auditors could directly reference. It saved us a lot of manual work and gave us a consistent, reliable way to demonstrate our security posture. Their support team deserves special credit, especially Victor, who has always been extremely responsive and patient whenever we needed clarification or extra help. It’s rare to find this level of personal support these days.

    I use Pentest-Tools.com on a monthly basis, and we have automated scans running across our key assets. It was surprisingly easy to set up assets, schedule recurring scans, and get valuable, audit-ready reports without needing extra manual effort. The results are reliable, easy to interpret, and have become part of our regular security rhythm. Overall, it’s a dependable platform backed by a team that genuinely cares about helping customers stay secure and compliant.
    What do you dislike about the product?
    If there’s one thing I’d change, it would be the user interface and navigation. While the tools themselves are excellent, the UX could be more intuitive when switching between scans, assets, and reports. I’d also love to see more integrations with GRC platforms, not just Vanta, so the results can fit more naturally into different compliance ecosystems. Adding some AI-assisted features for prioritizing vulnerabilities or generating remediation summaries would also make it even more powerful.
    What problems is the product solving and how is that benefiting you?
    We manage a high volume of RFPs and security questionnaires, many of which require current vulnerability scan reports as part of the due diligence process. Pentest-Tools.com has significantly streamlined this aspect of our workflow. It allows us to quickly produce reliable, professional reports that satisfy both client and auditor requirements, eliminating the need to perform manual scans for each request. The ability to schedule automated, recurring scans across our environments keeps our data consistently up to date. This not only supports our ISO 27001 and GDPR compliance efforts but also enables us to respond more rapidly to partner security assessments. As a result, it has become an essential tool for maintaining transparency and trust in all our engagements.
    Jasper S.

    Great tool with wide range of capabilities

    Reviewed on Sep 16, 2025
    Review provided by G2
    What do you like best about the product?
    It just works. The platform combines everything we need for pentesting (recon, scanning, exploit checks, reporting). No more switching between different tools. The interface is clear and easy to use. Reports look professional. Good to share without extra work.

    Scheduling scans saves a lot of time, and support is quick and helpful.
    What do you dislike about the product?
    The pricing feels high, especially if you have many assets or a small team. For complex web apps, some findings need extra manual work before they’re useful for developers. Nothing critical, but it can be annoying.
    What problems is the product solving and how is that benefiting you?
    It saves us a lot of time by automating vulnerability scans and reporting. Before we used multiple tools..that was time consuming.