Pentest-Tools.com VPN agent (internal scanning)
Continuous testing has strengthened our cloud app security and improved compliance evidence
What is our primary use case?
I use Pentest-Tools.com on the website to scan environments that are currently on the cloud for vulnerabilities. A friend of mine developed an application and wanted me to test if there were gaps and bugs in it before deployment. We had both the mobile and web versions, so I used Pentest-Tools.com to scan the application and website.
How has it helped my organization?
Pentest-Tools.com has always helped us to know what to do next and the best practices that need to be implemented. It has also helped us to ensure that we are compliant with the standards defined by CIS benchmark and some of the ISO standards that have been defined.
Pentest-Tools.com was able to help us determine and identify gaps that were open, especially for validation. It has also helped us to detect if there should be updates and those updates were not properly implemented within the environment. It has automatically captured evidence of APIs, request response that are simple, screenshots, credentials, and all of that. Pentest-Tools.com has really helped us to be able to provide solid evidence for remediation.
What is most valuable?
The best feature is the ability for Pentest-Tools.com to give continuous vulnerability detection and autonomous AI pentesting, which I was able to utilize. I used the free version rather than the paid version.
I am satisfied with the two daily free scans that I have always been given each time I visit the site. I am fine with the governance and security.
What captured me is the reports, the get-ready reports for SOC 2, ISO 27001, its compliance needs, the ability to discover complex or multiple step vulnerabilities, and its scalability on demand.
What needs improvement?
I would love to have more daily free scans since this is helping me as an individual. My major suggestion is that if more daily free scans could be provided, I would appreciate that.
For how long have I used the solution?
I started using Pentest-Tools.com this year.
What do I think about the stability of the solution?
Pentest-Tools.com is very stable.
What do I think about the scalability of the solution?
Pentest-Tools.com handles scalability perfectly.
How are customer service and support?
The customer service team has not given me any reason to complain.
What other advice do I have?
Pentest-Tools.com is almost perfect. I would advise those who want to use it to take full advantage of it because it handles security testing, network testing, vulnerabilities for applications, and API endpoints. Pentest-Tools.com is an entirely wholesome solution that helps with everything in one suite instead of getting two applications doing the same thing. I give this product a rating of nine out of ten.
Automated security scans have streamlined compliance reporting and support continuous protection
What is our primary use case?
Our primary use case for Pentest-Tools.com is automated web application, external and internal network vulnerability scanning. Specifically, white-box testing for our internet-facing systems, endpoints, and databases. As a part of our SOC 2 compliance requirements, we run automated external scans on a weekly basis to detect open ports, exposed access, and security weaknesses such as XSS or SQL injection before they can be exploited.
What is most valuable?
The standout feature of Pentest-Tools.com is definitely the reporting system. Generating clean, professional, and easy-to-understand reports is effortless. Additionally, the scheduled automated scanning for external access and web applications gives us continuous visibility without heavy operational overhead.
The balance between accessibility and depth in Pentest-Tools.com is very underrated. Command-line tools such as Nmap, Gobuster, or Metasploit are powerful, but extracting readable reports from them takes a lot of manual effort. Pentest-Tools.com bridges that gap perfectly by giving non-security specialists full pentesting and reporting capabilities right out of the box.
Pentest-Tools.com has positively impacted our organization by streamlining our vulnerability management workflow significantly. By running weekly automated external scans, our DevOps team gets immediate visibility into new vulnerabilities without spending hours configuring or maintaining other tools. It also made preparing compliance evidence, such as SOC 2 external scan samples, friction-free.
What needs improvement?
Pentest-Tools.com could improve with deeper native integrations with modern CI/CD pipelines and developer platforms such as Jira or GitHub Actions for automated issue tracking and remediation workflows.
Further expanding Pentest-Tools.com API capabilities for custom webhooks and automated target asset discovery as cloud environments scale up dynamically could be beneficial.
For how long have I used the solution?
I have been using Pentest-Tools.com tools since October 2020, so for nearly six years now.
What do I think about the stability of the solution?
Pentest-Tools.com is very stable.
What do I think about the scalability of the solution?
Pentest-Tools.com scalability is effective as it scales smoothly as our external target inventory grows. Adding new domains, subdomains, and IP endpoints for scheduled weekly scans is simple.
How are customer service and support?
Pentest-Tools.com customer support is prompt, helpful, and technically accurate whenever we needed assistance with platform features or scan behavior. I would rate Pentest-Tools.com customer support a 10.
Which solution did I use previously and why did I switch?
We evaluated legacy scanners such as Nessus, Acunetix, and Netsparker before choosing Pentest-Tools.com because it offered better ease of use, superior reporting for non-security specialists, and significantly lower overhead costs.
How was the initial setup?
My experience with Pentest-Tools.com pricing, setup cost, and licensing is excellent. When we evaluated competitors such as Acunetix or Netsparker, pricing was significantly higher and tied to multi-year locks or rigid target numbers. Pentest-Tools.com provided a much more flexible and cost-effective license model with zero initial setup friction.
What about the implementation team?
Pentest-Tools.com basically provides the reports and we act on them. We did not integrate Pentest-Tools.com tools directly with other tools.
What was our ROI?
We have seen a return on investment with Pentest-Tools.com, as the ROI comes directly from the time saved by our engineering team, such as saving several hours per week on reporting and manual triage and avoiding high license fees for legacy enterprise scanners while fulfilling our SOC 2 external scanning requirements. I would say that we have saved roughly four to six hours per week compared to manually running open-source toolkits, aggregating results, and writing reports manually. Over a year, this translates to over 200 hours of engineer time saved.
What's my experience with pricing, setup cost, and licensing?
My experience with Pentest-Tools.com pricing, setup cost, and licensing is excellent. When we evaluated competitors such as Acunetix or Netsparker, pricing was significantly higher and tied to multi-year locks or rigid target numbers. Pentest-Tools.com provided a much more flexible and cost-effective license model with zero initial setup friction.
Which other solutions did I evaluate?
We evaluated other options including Netsparker, Intruder, Nessus, and Acunetix before choosing Pentest-Tools.com.
What other advice do I have?
The user experience for non-security specialists using Pentest-Tools.com is excellent. If you have a lean DevOps or IT team that needs robust security scanning and professional reporting for compliance or vulnerability management without spending weeks learning CLI security tools or paying exorbitant enterprise fees, Pentest-Tools.com is easily one of the best SaaS solutions available.
Pentest-Tools.com documentation and training resources are very helpful and easy to go through for onboarding.
Pentest-Tools.com has very solid AI capabilities that meet our requirements for secure asset handling, safe target validation, and reliable report management required for internal audits and SOC 2 evidence. Pentest-Tools.com is pretty much safe and reliable regarding its AI capabilities and the accuracy and reliability of output.
I don't integrate Pentest-Tools.com tools directly with other tools we have. Instead, we run it against our main app and extract information to use separately elsewhere.
Pentest-Tools.com performs effectively as it scales smoothly as our external target inventory grows. Adding new domains, subdomains, and IP endpoints for scheduled weekly scans is simple, so it works great.
When we formerly evaluated the enterprise solutions back in 2021, our challenge was the need to have an automated and user-friendly tool that any SysOps or DevOps personnel could operate without needing dedicated full-time security engineers. Crucially, we needed a tool that turned raw scan data into clear, actionable security reports. After reviewing Pentest-Tools.com's ease of use and reporting capabilities compared to the high cost and complexity of the other alternatives, we decided to officially adopt it. If you are in a similar situation, Pentest-Tools.com is the tool for you.
I rate this tool a 9 overall.
Accurate APIs That Power Our Pen Testing Across All SaaS Apps
A Swiss Army Knife for Quick and Deep Security Assessments
As an 5 years active user of the platform I could certainly certify that pentest-tools.com it is a great tool for quick assessments of public facing systems. The added value came also from the fact that the internal systems can be assessed too via the VPN appliance.