Set the scope and access
List the approved public or private targets, test credentials, IP allowlisting, and prohibited actions. Internal testing requires a Casco agent in the customer cloud environment.
Casco discovers hosts and services within the approved scope, tests public targets or reachable private networks, and confirms exploitable vulnerabilities without destructive or resource-exhaustion actions. Customers receive a pentest report and console findings with reproduction scripts.
Network pentesting checks approved public or private network assets for exploitable services, weak authentication, segmentation failures, lateral movement, and privilege paths. Internal testing requires a Casco agent in the customer cloud environment. Casco can run the same scope again on a schedule and retest findings after a fix.
How Casco tests
Scroll through the four parts of the test. The diagram shows what Casco has at each point, what it checks next, and what it records.
List the approved public or private targets, test credentials, IP allowlisting, and prohibited actions. Internal testing requires a Casco agent in the customer cloud environment.
Casco identifies hosts, services, exposed interfaces, and reachable network segments within the public targets or private environment in scope.
Casco tests exposed services, authentication, segmentation, lateral movement, and privilege paths. Cloud identity testing requires the corresponding accounts and permissions.
Customers receive a pentest report and console findings with reproduction scripts. Casco can retest fixes without destructive or resource-exhaustion actions.
Pentest deliverables
The report lists the approved targets, starting access, confirmed vulnerabilities, prohibited actions, and recommended fixes.
Learn more
See how Casco records source IPs, request IDs, and network activity during a test.
Read the sourceCompare network scanning, manual testing, and Casco agent testing.
Read the sourceReview Casco's penetration testing accreditation and supervised testing option.
Read the sourceChecks included when applicable
The findings depend on whether the test is external or internal, which targets and credentials are provided, and which private assets the Casco agent can reach. Destructive and resource-exhaustion actions are excluded.
Related testing
Frequently asked questions
AI network pentesting uses software agents to discover approved hosts and services, run permitted security tests, and choose the next test from the result. Casco reports vulnerabilities it can reproduce.
Yes. External testing covers approved public targets and discovered assets. Internal testing uses a Casco agent in the customer cloud environment to reach approved private targets.
At minimum, Casco needs IP allowlisting and test credentials. Internal testing also requires a Casco agent in the customer cloud environment.
Customers receive a pentest report and access to console findings with complete reproduction scripts. Casco can automatically retest a finding after a fix.
Casco does not perform destructive actions or resource-exhaustion testing. Any additional restrictions are written into the rules of engagement.
Yes, when the Casco agent can reach the approved segments and the required test credentials are available.
Only when the accounts, test identities, permissions, and directory environment are included. Network access alone does not include cloud identity or directory testing.
Yes. Casco can run an approved scope on a schedule and automatically retest findings after a fix.
Yes. The pentest report and Casco console include complete reproduction scripts for network findings.