100% automated
Every probe is executed by BreakMesh's engine — no manual, hands-on testing.
Going further
Fully automated · no human testerStandard checks identify weaknesses. This goes a step further and safely attempts them, so you know which ones a real attacker could use — not just which ones look risky. It is performed entirely by software, which is why it is fast enough to repeat.
Because it is more intrusive than a standard scan, nothing runs until you sign a short agreement setting out what may be tested and for how long. It is a separate product from the standard packages, and it is disabled until you enable it.
The testing is performed by software, not a person. Some providers sell a security specialist who spends a week examining your systems by hand; this is not that. Ours runs automatically, within the limits and time window you agree in advance. That makes it far cheaper and repeatable, but it will not improvise the way a person can.
Every probe is executed by BreakMesh's engine — no manual, hands-on testing.
No person manually runs exploitation commands against your systems during the engagement.
Probes run only after you explicitly authorize the engagement.
A Statement of Work and Rules of Engagement are signed before any probe executes.
Every engagement runs within a fixed, approved time window — not indefinitely.
Probes are hard-limited to the targets and URLs approved in the engagement scope.
Each engagement has a per-scan request budget so probing stays bounded and predictable.
An engagement can be paused immediately if needed, at any point during the time window.
Confirmed findings include a CVSS score, vector, and the exact request/response as proof.
Selected probe classes (e.g. SSRF, XXE) use out-of-band callbacks to confirm exploitability.
You can run either on its own, or both together, depending on your plan.
Pentest Basic
12active probes
Consent-gated active probes for selected OWASP vulnerability classes including SQL injection, XSS, XXE, path traversal, authentication bypass, IDOR and broken function-level authorization (OWASP A01–A07).
Pentest Advanced
9additional active probes
Additional active probes covering command injection, SSRF, unsafe deserialization, file-upload bypass, mass assignment, header injection and selected business-logic risks (OWASP A03–A10).
Select the engagement type based on the vulnerability classes you need confirmed.
Review and sign the Statement of Work and Rules of Engagement covering scope, targets and time window.
BreakMesh's engine runs the approved probes, bounded by request budget, scope and the time window — with emergency pause available throughout.
Confirmed findings include CVSS scores, request/response proof, and remediation guidance.
There is no call to book and no consultant's availability to work around. The software carries out the whole engagement, within the limits you set.
It begins as soon as you approve the limits, with no scheduling delay.
Every test is selected and assessed by the software, not by a person at a keyboard.
Run it again after a fix and you can confirm whether the fix worked, because nothing else changed.
Whenever something is confirmed, the exact exchange that proved it is stored with the result.
When we report a confirmed issue, we include the exact exchange that proved it, so whoever resolves it can reproduce it themselves.
Illustrative example
SSRF (Callback) — Confirmed
CVSS 8.6 · Out-of-band callback received
POST /api/v1/fetch-preview HTTP/1.1
Host: app.example-target.com
Content-Type: application/json
{"url": "http://<oast-callback-id>.breakmesh-oast.io/probe"}
HTTP/1.1 200 OK
X-Callback-Received: true
Structure and formatting shown for illustration only — your report contains findings from your own approved engagement.
Pentest Basic and Pentest Advanced are add-ons on top of the standard security & assurance packages — availability depends on your plan.
Business
Agency
Enterprise
Standard BreakMesh packages
Active Pentest
Questions
No. Every probe is dispatched and evaluated by BreakMesh's engine. No person manually runs exploitation commands against your systems during the engagement.
12 active probes covering OWASP A01–A07: SQL injection, XSS, XXE, path traversal, open redirect, auth bypass, IDOR and broken function-level authorization.
9 additional probes for OWASP A03–A10: command injection, SSRF, insecure deserialization, file-upload bypass, mass assignment, header injection and selected business-logic risks.
Yes. A Statement of Work and Rules of Engagement covering scope, targets and time window must be signed before any Active Pentest probe executes.
Selected probe classes such as SSRF and XXE use out-of-band (OAST) callbacks to confirm exploitability. Confirmed findings include a CVSS score and the request/response used as proof.
Yes. An engagement can be paused immediately at any point during the approved time window.
Active Pentest provides automated active validation for supported vulnerability classes. It does not replace manual, human-led penetration testing for scope or vulnerability classes outside its supported probes.
Ready when you are
Compare Business, Agency and Enterprise coverage, then create an account to sign your SOW and Rules of Engagement.