pentest.core, Semi-Automated Penetration Testing

Semi-automated penetration testing for hardware and embedded systems, with comprehensive reporting. pentest.core executes the attack scripts against your target, streams the run as it happens, validates what comes back, and pulls every result into a single report, from a test library you extend with your own cases.

Repeatable Testing, Without the Manual Overhead

Manual penetration testing is thorough, but slow to repeat, because every regression means setting the whole thing up by hand again. pentest.core takes over the mechanical parts. It deploys the test scripts, runs them remotely against your target, and captures the output the same way every time.

The result is faster turnaround on each run, results you can reproduce across builds, and engineers free to focus on the findings that actually need human judgement, rather than the plumbing.

What pentest.core Does

Automated Attack Execution

Deploys the attack scripts to your target and runs them on its own, the same way on every run.

Live Test Monitoring

Streams each test as it executes, so you watch the run happen rather than wait for it to finish.

Result Validation

Checks what came back against the expected outcome, and flags what failed and why.

Unified Reporting

Pulls every result into one prioritised, severity-rated report, mapped to your compliance evidence.

Extensible Test Library

Ships with a maintained set of test cases and takes your own, so coverage grows with your product.

How pentest.core Runs a Test

  1. Configure

    Select the target, the attack category and the test campaign for the assessment.

  2. Execute

    pentest.core automatically runs pre-built attack scripts from the centralised attack knowledge base.

  3. Validate

    Automated results are reviewed, with optional manual validation to improve the accuracy of the assessment.

  4. Analyse

    Execution results are stored, correlated and analysed to identify vulnerabilities and security findings.

  5. Report

    Generate unified reports with test results, evidence, remediation guidance and export options.

Where pentest.core Fits

pentest.core is part of security.core's Testing Layer, alongside fuzz.core. What it finds flows on to be prioritised, then fixed.

1

Testing Layer

pentest.core runs the tests and captures the evidence.

2

threat.core

Findings gain outside threat context and get prioritised.

3

Remediation

You fix what matters most, in priority order.

What you get

  • Automated pen-test runs
  • Captured output for every build
  • Pass/fail summaries
  • Unified, severity-rated reports
  • Evidence mapped to UN R155/R156 & ISO/SAE 21434

Want a human-led, exploratory pen test in our lab instead? See our Penetration Testing service

pentest.core, Common Questions

No. It automates the repeatable mechanics, like configure, execute, validate, analyse and report, so our testers can spend their time on the exploratory, judgement-heavy work. The two run side by side.

Hardware and embedded systems, including ECUs, gateways, telematics units and connected components, through SSH script deployment and remote execution.

A prioritised, severity-rated report with the findings and their compliance mapping, not raw logs you have to wade through yourself.

Yes. The reports are structured as evidence aligned to UN R155/R156 and ISO/SAE 21434.

Put pentest.core to Work on Your Target

Book a lab session and we'll run pentest.core against your ECU, gateway or connected system, then hand you back a clear, prioritised, compliance-mapped report.