BreakMesh – Vulnerability Simulator & Cyber Range

Going further

Fully automated · no human tester

Prove which weaknesses are real

Standard checks identify weaknesses. This goes a step further and safely attempts them, so you know which ones a real attacker could use — not just which ones look risky. It is performed entirely by software, which is why it is fast enough to repeat.

Because it is more intrusive than a standard scan, nothing runs until you sign a short agreement setting out what may be tested and for how long. It is a separate product from the standard packages, and it is disabled until you enable it.

12 Pentest Basic active probes
9 Pentest Advanced active probes
100% automated No human pentester in the loop
Signed SOW + RoE Required before any probe runs

What this is

The testing is performed by software, not a person. Some providers sell a security specialist who spends a week examining your systems by hand; this is not that. Ours runs automatically, within the limits and time window you agree in advance. That makes it far cheaper and repeatable, but it will not improvise the way a person can.

100% automated

Every probe is executed by BreakMesh's engine — no manual, hands-on testing.

No human pentester in probe execution

No person manually runs exploitation commands against your systems during the engagement.

Consent-gated

Probes run only after you explicitly authorize the engagement.

Signed SOW + Rules of Engagement

A Statement of Work and Rules of Engagement are signed before any probe executes.

Time-bounded

Every engagement runs within a fixed, approved time window — not indefinitely.

Scope-restricted

Probes are hard-limited to the targets and URLs approved in the engagement scope.

Request-budget controls

Each engagement has a per-scan request budget so probing stays bounded and predictable.

Emergency pause

An engagement can be paused immediately if needed, at any point during the time window.

Evidence-backed

Confirmed findings include a CVSS score, vector, and the exact request/response as proof.

OAST confirmation where supported

Selected probe classes (e.g. SSRF, XXE) use out-of-band callbacks to confirm exploitability.

The two levels

You can run either on its own, or both together, depending on your plan.

Pentest Basic

12active probes

Consent-gated active probes for selected OWASP vulnerability classes including SQL injection, XSS, XXE, path traversal, authentication bypass, IDOR and broken function-level authorization (OWASP A01–A07).

Signed SOW + RoE Explicit consent
  • SQL Injection (Error-Based)Injection
  • SQL Injection (Boolean-Blind)Injection
  • XSS — ReflectedInjection
  • XSS — StoredInjection
  • XXE InjectionInjection
  • Path TraversalAccess Control
  • Open Redirect (Active)Redirect
  • Auth Bypass ProbesAuthentication
  • IDOR (Two-Account)Access Control
  • Broken Function Auth (Active)Access Control
  • HTTP Parameter Pollution (HPP)Injection
  • NoSQL InjectionActive Probe

Pentest Advanced

9additional active probes

Additional active probes covering command injection, SSRF, unsafe deserialization, file-upload bypass, mass assignment, header injection and selected business-logic risks (OWASP A03–A10).

Signed SOW + RoE Explicit consent
  • Command Injection (Timing)Injection
  • SSRF (Callback)SSRF
  • Header InjectionInjection
  • File Upload BypassFile Handling
  • API Mass AssignmentAccess Control
  • Insecure Deserialization (Timing)Deserialization
  • Business Logic — Price ManipulationBusiness Logic
  • HTTP Request Smuggling / Desync ReadinessProtocol
  • Web Cache Poisoning ReadinessProtocol

From signing the agreement to getting your results

01

Choose Basic or Advanced

Select the engagement type based on the vulnerability classes you need confirmed.

02

Sign SOW + Rules of Engagement

Review and sign the Statement of Work and Rules of Engagement covering scope, targets and time window.

03

Automated probes run within scope

BreakMesh's engine runs the approved probes, bounded by request budget, scope and the time window — with emergency pause available throughout.

04

Review evidence-backed findings

Confirmed findings include CVSS scores, request/response proof, and remediation guidance.

Performed entirely by software

There is no call to book and no consultant's availability to work around. The software carries out the whole engagement, within the limits you set.

Starts when you are ready

It begins as soon as you approve the limits, with no scheduling delay.

No manual testing

Every test is selected and assessed by the software, not by a person at a keyboard.

Repeatable

Run it again after a fix and you can confirm whether the fix worked, because nothing else changed.

Evidence captured automatically

Whenever something is confirmed, the exact exchange that proved it is stored with the result.

Evidence, not inference

When we report a confirmed issue, we include the exact exchange that proved it, so whoever resolves it can reproduce it themselves.

  • An industry-standard severity score for every confirmed finding
  • The exact request we sent and the response your site returned
  • For some classes, evidence that your server contacted us when it should not have
  • Affected URL, parameter and probe category
  • Remediation guidance mapped to the finding

Illustrative example

SSRF (Callback) — Confirmed

CVSS 8.6 · Out-of-band callback received

POST /api/v1/fetch-preview HTTP/1.1
Host: app.example-target.com
Content-Type: application/json

{"url": "http://<oast-callback-id>.breakmesh-oast.io/probe"}

HTTP/1.1 200 OK
X-Callback-Received: true

Structure and formatting shown for illustration only — your report contains findings from your own approved engagement.

Plan availability

Pentest Basic and Pentest Advanced are add-ons on top of the standard security & assurance packages — availability depends on your plan.

Business

  • Pentest Basic included
  • 2 active validation engagements/month

Agency

  • Pentest Basic included
  • 5 active validation engagements/month

Enterprise

  • Pentest Basic included
  • Pentest Advanced included
  • 15 active validation engagements/month

See full plan comparison →

How this fits with the standard packages

Standard BreakMesh packages

  • Non-destructive, read/observe/controlled-request checks
  • Designed for frequent, recurring assessment
  • Included on every plan from Free upward
  • No signed authorization required beyond target verification

Questions

Frequently asked questions

Is a human pentester involved in running the probes?

No. Every probe is dispatched and evaluated by BreakMesh's engine. No person manually runs exploitation commands against your systems during the engagement.

What's included in Pentest Basic?

12 active probes covering OWASP A01–A07: SQL injection, XSS, XXE, path traversal, open redirect, auth bypass, IDOR and broken function-level authorization.

What's included in Pentest Advanced?

9 additional probes for OWASP A03–A10: command injection, SSRF, insecure deserialization, file-upload bypass, mass assignment, header injection and selected business-logic risks.

Is signed authorization required before any probe runs?

Yes. A Statement of Work and Rules of Engagement covering scope, targets and time window must be signed before any Active Pentest probe executes.

How are exploitable findings confirmed?

Selected probe classes such as SSRF and XXE use out-of-band (OAST) callbacks to confirm exploitability. Confirmed findings include a CVSS score and the request/response used as proof.

Can an engagement be stopped once it starts?

Yes. An engagement can be paused immediately at any point during the approved time window.

Does Active Pentest replace a manual penetration test?

Active Pentest provides automated active validation for supported vulnerability classes. It does not replace manual, human-led penetration testing for scope or vulnerability classes outside its supported probes.

Ready when you are

Review pricing, then start your first engagement.

Compare Business, Agency and Enterprise coverage, then create an account to sign your SOW and Rules of Engagement.