Solutions / What we cover

Test your external or internal network.

Casco discovers hosts and services within the approved scope, tests public targets or reachable private networks, and confirms exploitable vulnerabilities without destructive or resource-exhaustion actions. Customers receive a pentest report and console findings with reproduction scripts.

Testing workflowApproved scope only
  1. 01Approved network scopeTargets, credentials, agent, and limits
  2. 02Discover hosts and servicesHosts, interfaces, and relationships
  3. 03Access and movement testsExposure, authentication, segmentation, and movement
  4. 04Report and retestingScripts, guidance, and current status
Hosts, services, credentials, and resultsApproved scope only

What is network pentesting?

Network pentesting checks approved public or private network assets for exploitable services, weak authentication, segmentation failures, lateral movement, and privilege paths. Internal testing requires a Casco agent in the customer cloud environment. Casco can run the same scope again on a schedule and retest findings after a fix.

How Casco tests

How Casco tests a network.

Scroll through the four parts of the test. The diagram shows what Casco has at each point, what it checks next, and what it records.

Test contextStep 01 / 04
Public targets
Private targets
Agent
Credentials
StageScope
Network scope recorded
01

Set the scope and access

List the approved public or private targets, test credentials, IP allowlisting, and prohibited actions. Internal testing requires a Casco agent in the customer cloud environment.

02

Discover hosts and services

Casco identifies hosts, services, exposed interfaces, and reachable network segments within the public targets or private environment in scope.

03

Test access and movement

Casco tests exposed services, authentication, segmentation, lateral movement, and privilege paths. Cloud identity testing requires the corresponding accounts and permissions.

04

Report and retest findings

Customers receive a pentest report and console findings with reproduction scripts. Casco can retest fixes without destructive or resource-exhaustion actions.

Pentest deliverables

What the network report contains.

The report lists the approved targets, starting access, confirmed vulnerabilities, prohibited actions, and recommended fixes.

  • Approved external or internal scope, starting access, and safety limits
  • Full pentest report with prioritized, confirmed findings
  • Console access to detailed findings and complete reproduction scripts
  • Remediation guidance and automatic retesting after fixes

Checks included when applicable

What Casco checks for.

The findings depend on whether the test is external or internal, which targets and credentials are provided, and which private assets the Casco agent can reach. Destructive and resource-exhaustion actions are excluded.

Exposed services and management interfaces
Weak credentials and authentication controls
Network segmentation weaknesses
Lateral movement and privilege paths
Exploitable service vulnerabilities
Unsafe cloud and private network boundaries

Frequently asked questions

Network pentesting questions, answered.

What is AI network pentesting?+

AI network pentesting uses software agents to discover approved hosts and services, run permitted security tests, and choose the next test from the result. Casco reports vulnerabilities it can reproduce.

Can Casco test both external and internal networks?+

Yes. External testing covers approved public targets and discovered assets. Internal testing uses a Casco agent in the customer cloud environment to reach approved private targets.

What access does Casco need for network pentesting?+

At minimum, Casco needs IP allowlisting and test credentials. Internal testing also requires a Casco agent in the customer cloud environment.

What does Casco deliver after a network pentest?+

Customers receive a pentest report and access to console findings with complete reproduction scripts. Casco can automatically retest a finding after a fix.

What network testing actions does Casco exclude?+

Casco does not perform destructive actions or resource-exhaustion testing. Any additional restrictions are written into the rules of engagement.

Can Casco test network segmentation and lateral movement?+

Yes, when the Casco agent can reach the approved segments and the required test credentials are available.

Does network pentesting include cloud identities?+

Only when the accounts, test identities, permissions, and directory environment are included. Network access alone does not include cloud identity or directory testing.

Can network pentesting run continuously?+

Yes. Casco can run an approved scope on a schedule and automatically retest findings after a fix.

Does Casco provide reproduction scripts for network findings?+

Yes. The pentest report and Casco console include complete reproduction scripts for network findings.

Scope a pentest for this system.

Book a demo