Automated penetration testing, Penetration Testing

Cobalt wants to make pentesting a 24-hour security cycle

Cobalt has launched an autonomous pentesting service designed to help security teams test more applications without waiting for quarterly or annual assessments. Cobalt Autonomous Pentest uses AI to handle reconnaissance, run tests, and explore possible attack paths, while human pentesters oversee each engagement.

The service is built into the Cobalt Offensive Security Platform for organizations with more applications than traditional testing programs can cover. As development teams release software faster, security teams have less time to identify exploitable weaknesses before code reaches production.

Human oversight is part of the test

Gunter Ollmann, CTO at Cobalt, told MSSP Alert that autonomous testing should not be seen as a fully hands-off process.

“I do think there’s a misconception that autonomous pentesting means taking humans out of the process, but we certainly don’t see it that way,” Ollmann said. “AI is very good at reconnaissance, testing, and exploring potential attack paths, but you still need experienced pentesters making decisions about where to look, validating what’s exploitable, and understanding what actually matters to the customer.”

Cobalt’s AI engine handles reconnaissance, attack sequencing, test execution and evidence gathering. A human pentester reviews the engagement before testing begins, checks the scope and directs the test.

“The human pentester is involved from the very start of the process,” Ollmann said. “They review the engagement before testing begins and make sure the scope is correct. While some organizations opt to review the findings themselves, in most cases, the pentesters also validate findings before anything reaches the customer.”

That review is meant to reduce false positives and make sure customers receive findings tied to real, exploitable risk.

Findings delivered within 24 Hours

Cobalt says customers can receive validated findings within 24 hours. Each finding includes supporting evidence, reproduction steps and remediation guidance.

Results can be sent to Jira, GitHub, Slack, and more than 50 other development and security tools. That allows teams to move issues into the systems they already use to track and fix vulnerabilities.

Ollmann said customers should measure the service by testing speed, application coverage, and whether vulnerabilities are found early enough to be fixed during development.

“Customers can measure how quickly they receive validated findings, how much more of their application portfolio they’re able to test, and whether security issues are being identified early enough to fit into normal development cycles,” he said. “If they’re finding more real vulnerabilities and fixing them before software ships, that’s a meaningful improvement.”

The system draws on 13 years of Cobalt pentesting data, including more than 10,000 critical and high-severity findings. Cobalt uses that data to help guide testing priorities and attack-path exploration.

Where autonomous testing fits

Cobalt expects organizations to use autonomous testing for applications that change often and need regular security checks. This could help teams expand testing across applications that may not receive a full manual pentest every year.

“Different applications need different levels of testing,” Ollmann said. “Autonomous Pentest is a great fit for applications that change often and need consistent security validation. Most organizations have too many applications to assess with traditional pentests alone, so this gives them a practical way to increase coverage and test continuously.”

Human-led pentesting will still be used for business-critical systems, complex business logic, major architectural changes and compliance-driven assessments.

“Human-led pentesting is still the right approach for business-critical applications, complex business logic, significant architectural changes, and compliance-driven assessments,” Ollmann said. “Those are the engagements where experienced pentesters add the most value because they’re thinking like an attacker rather than following a predefined path.”


Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds