Skip to main content
own2pwn

EASM

Automated Pentest (PTaaS)

An attacker's reconnaissance, automated and replayed continuously without taking prod down.

An attacker doesn't test your surface once a year. The automated pentest replays their reconnaissance continuously: more than 240 detection modules run over every exposed asset, correlate CVEs by banner and version, prioritise with CISA KEV (flaws with confirmed exploitation in the wild) and EPSS (the probability of being exploited within 30 days). Non-intrusive by design, adjustable from 1 to 1000 req/s, no exploitation replayed. It isn't a human pentester, it's their reconnaissance put on a loop.

Free account, hosted in the EU, domain verification required
detection modules on every asset
240+
per-host rate, production-safe
1 to 1000 req/s
replayed continuously, not a yearly audit
24/7

Features

What automated pentesting replays on your scope.

More than 240 detection modules on every pass

TLS, HTTP headers, DNS and email (SPF/DKIM/DMARC), secret and Git repo exposure, open cloud buckets, admin interfaces, CMS and frameworks. Every exposed asset runs through the same battery of checks as an attacker's reconnaissance, on every scan, without you writing a single rule.

CVE correlation by banner and version

Detected versions and banners are matched against known CVEs, with strict matching to limit false positives. You don't get a dump of the entire CVE catalogue: only what actually matches the service as it responds on the network.

Prioritisation by real exploitability

300 findings are useless without an order of treatment. Prioritisation draws on CISA KEV (what is actively exploited in the wild) and EPSS scores (probability of exploitation): the exposed admin console ranks above the ordinary service on 443. You handle what matters first.

Automated pentest pricing.

Discovery

€0

  • Automated Pentest module included in the EASM offering
  • In plain terms: the perimeter of a single domain name, 25 exposed assets at most.
  • 10 scans / mo
  • Multi-source discovery + more than 240 detection modules
  • CVE correlation and prioritisation by real exploitability
  • 2 AI-native validations / mo
  • Email alerts, 1 user
  • Free, no time limit and no credit card
Start for free
Recommended

Pro

€99 / mo

  • In plain terms: 5 domain names, 250 tracked exposed assets, 5 people on the account.
  • 100 scans / mo
  • 30 AI-native validations / mo
  • HMAC-signed webhooks (Slack, Teams, Discord, PagerDuty)
  • Jira, GitHub, GitLab, Slack integrations
  • PDF and CSV exports, API access (5 keys)
Subscribe

For businesses only, a company identifier is asked at the next step.

Business

€299 / mo

  • In plain terms: 15 domain names, 1,000 tracked exposed assets, no cap on scans.
  • 100 AI-native validations / mo
  • SSO, RBAC and role management
  • SIEM connector, custom integrations
  • Email support, prioritised handling
Subscribe

For businesses only, a company identifier is asked at the next step.

Enterprise

On request

  • In plain terms: the perimeter you set in the contract, no cap on domains or validations.
  • SSO / SAML, SCIM provisioning
  • Enhanced AI validation (extended reasoning)
  • GDPR-compliant DPA, master agreement and NIS2 guidance
  • A single point of contact: the pentester who runs it
Talk to a pentester

VAT not applicable (art. 293 B of the French tax code)

How it works

From setup to the first alert.

  1. 01

    You enter a domain

    A single root domain name in, for example acme.com. No agent to install, no IP range to provide, no cloud access to connect. The scan starts right away and stays bounded to the domains you declare: no reckless attribution to assets that aren't yours.

  2. 02

    More than 240 modules run over every asset

    On every exposed asset, the detection battery fires: TLS, HTTP headers, DNS and email, secret exposure, cloud misconfig, service fingerprints, CVEs by banner and version. It's the reconnaissance an attacker would run by hand, executed at scale and hands-off. The rate is capped per host (1 to 1000 req/s), redirects are cut, the anti-SSRF guard is active: nothing is exploited, nothing is broken.

  3. 03

    Correlation, dedup and prioritisation

    Detected vulnerabilities are matched against the CVE catalogue by banner and version, deduplicated, then prioritised with CISA KEV and EPSS. The graph links assets and findings to reconstruct attack paths and compute a blast radius. You get a list ordered by real exploitability, not a raw export where the exposed admin console drowns under a hundred cosmetic findings.

  4. 04

    Replayed continuously, alert on the first change

    Scans run periodically and on demand, with change detection: a new CVE on an exposed service, a port that opens, a finding that appears or is resolved. The alert lands the same day in Slack, Teams, Jira, GitHub, GitLab, PagerDuty or an HMAC-signed webhook. Your surface is tested continuously, not once between two audits.

Benefits

What automated validation changes in your triage.

01

An attacker's reconnaissance, on a loop

A human pentest photographs your security at a single point in time. The next day, a deploy puts a CVE back online and the photo is stale. The automated pentest replays the reconnaissance and detection part of an attacker continuously: more than 240 modules run over every exposed asset, on every scan. The subdomain that exposes an admin console after an update, the service whose version becomes vulnerable to a CVE published yesterday, the bucket left open by mistake: they surface on the next pass, not at the next yearly audit.

02

Triaged noise, not a CVE dump

Throwing 300 findings over the wall with no order of treatment just moves the problem onto your team. Every exposed service is correlated to CVEs by banner and version, with strict matching to cut false positives, then prioritised with CISA KEV and EPSS: what is actively exploited goes ahead of the theoretical. The attack graph links assets together and computes a blast radius per finding, to see which exposure actually leads somewhere. We don't promise zero false positives. We save you the triage.

03

A test that doesn't take prod down

The reason many teams only test once a year is fear of breaking something. The automated pentest removes that brake: no exploitation replayed, redirects disabled, three-layer anti-SSRF guard, rate adjustable from 1 to 1000 req/s per host. You add it to your perimeter without negotiating a maintenance window. A single root domain in, no agent to install, no cloud access to connect. Data hosted in the EU, under European law, designed by an OSWE-certified pentester.

Overview

The platform in pictures.

A large volume of findings sorted by severity, produced by the automated detection modulesThe volume the automated modules put out, sorted by severity. You read top to bottom, not line by line.
Detail of a finding: CVE prioritisation with CISA KEV context and EPSS scoreA finding in detail: correlated CVE, CISA KEV context and EPSS score. The actively exploited flaw comes before the theoretical high CVSS.
Automated scans, scheduled and on demandAutomated scans scheduled or launched by hand. The test replayed continuously, not once a year.

Why own2pwn

Why this is neither a vulnerability scanner nor a human pentest.

Automated is not a human pentester

Let's be clear about what you're buying. The automated pentest replays an attacker's reconnaissance and detection at scale: it finds, correlates and prioritises, without ever exploiting for real. It doesn't replace the judgement of a human who chains minor vulnerabilities into a full compromise, tests business logic or writes a bespoke attack scenario. That's our pentests, a separate offering run by an OSWE-certified pentester. The automated test covers the surface continuously; the human goes deep on what deserves it.

Designed by an OSWE-certified pentester

The detection logic follows what an attacker enumerates first, not a generic checklist copied from a framework. Prioritisation reflects real exploitability: an exposed admin console ranks ahead of a high CVSS hidden behind a WAF. It is an offensive method turned into SaaS, not a dashboard dreamed up by marketers.

Production-safe, by design

No exploitation replayed, three-layer anti-SSRF guard, rate adjustable from 1 to 1000 req/s per host, redirects disabled. The test slots into your perimeter without coordinating a maintenance window with the ops team. That's what lets you replay it continuously instead of waiting for the yearly slot where everyone holds their breath.

AI to triage, not to chat

No chatbot. AI is used to rank more than 240 detection modules by real risk: CVE correlation, CISA KEV and EPSS prioritisation, deduplication, attack-path reconstruction. Optional and quota-limited, an AI-native validation (the AI-Native Pentest module) tries to confirm the exploitability of a critical finding inside an ephemeral sandbox. It is bounded AI, not a human, and we don't promise zero false positives.

Frequently asked questions

Your questions about automated pentesting.

How is this different from a real human pentest?

The automated pentest replays an attacker's reconnaissance and detection at scale: it enumerates your surface, runs more than 240 modules over every asset, correlates CVEs and prioritises by exploitability. It doesn't do what a human does best: chain three minor vulnerabilities into a full compromise, understand your business logic, bypass a protection with a bespoke scenario, write a contextualised report. That's our pentest offering, run by hand by an OSWE-certified pentester. The two are complementary: the automated test covers the whole surface continuously, the human goes deep on what deserves it. One doesn't replace the other.

How is it different from a classic vulnerability scanner?

A scanner like Nessus or OpenVAS starts from a list of IPs you feed it and tests vulnerabilities on them: it only sees what you declare. The automated pentest starts from a single root domain, first discovers the assets nobody inventoried (forgotten subdomains, staging online, cloud buckets), then runs more than 240 modules on them, correlates CVEs and prioritises with KEV and EPSS. Above all, it replays the whole thing continuously and alerts you on the first change, instead of producing a report frozen on a given day.

Is the scan intrusive? Can it break my production?

No, it's non-intrusive by design. No exploitation replayed, no destructive payload, redirects disabled, three-layer anti-SSRF guard, per-host rate capped and adjustable from 1 to 1000 req/s. You can add it to your perimeter without coordinating a maintenance window with the ops team. The only piece that actively tests exploitability is the optional AI-native validation: it is manual, reserved for critical findings on a verified domain, quota-limited, and its tooling runs inside an isolated ephemeral sandbox. It never fires on its own.

How often is my perimeter tested?

You schedule periodic scans (cron) and trigger on-demand scans from the interface or the API. On every pass, you get the delta: a new CVE on an exposed service, a port that opens, a finding resolved. Volumes depend on the plan: 10 scans a month on Discovery, 100 on Pro, unlimited on Business and Enterprise. You track your usage in real time.

How do you limit false positives?

CVE correlation is done by banner and version with strict matching: we don't flag a CVE just because a port responds, but because the detected service actually matches the vulnerable version. KEV and EPSS prioritisation then pushes what is actively exploited to the top, so the residual noise stays at the bottom of the pile. We don't promise zero false positives, no automated tool honestly can. On a critical finding, the optional AI-native validation can try to confirm exploitability to remove the doubt.

Does it cover cloud assets (AWS, Azure, GCP)?

Yes. Public S3 buckets, Azure Blob Storage, GCP Storage, exposed instances, subdomains pointing to a CDN or a cloud host. Dedicated modules check storage ACLs and metadata leaks (cloud SSRF). If a cloud asset is reachable from the Internet and tied to your domain, it surfaces in the inventory and runs through the detection battery like any other asset.

Is it billed on top of EASM?

No. The automated pentest is the detection engine of the EASM platform, it is included in the offering, from the free Discovery plan. You don't pay for a separate piece: discovery, detection across more than 240 modules, CVE correlation and KEV/EPSS prioritisation are all part of the same subscription. Only the volumes (scans, assets, AI validations) scale with the plan.

Where is my data hosted?

Hosting in the EU, under European law. Your inventory data and findings stay isolated per account (strict per-tenant database partitioning), with secrets masked before they are written. No reselling, no sharing with third parties, no use to train external models. Handing the mapping and testing of your attack surface to a US vendor exposes you to extraterritorial access requests, at odds with GDPR and NIS2: we keep hosting in the EU.

Is there a minimum term, and how do I cancel?

No minimum term. The subscription is monthly or annual (annual works out at ten months paid), renewed tacitly at each due date, and you cancel it at any time, with no justification to give: either you do it yourself from your billing area, or you write to contact@own2pwn.fr and the answer comes within 24 hours. No notice period to serve: cancellation takes effect at the end of the current billing period, and you keep access until then. In return, that period is not refunded pro rata. That is not a sales promise, it is article 7 of the terms of sale.

Do I need a credit card for the free plan?

No. The Discovery plan opens from the sign-up form, with no payment method: no card to enter, no counter starting after fourteen days. It is not a trial but a free plan with no time limit and its own quotas (1 domain, 25 tracked assets, 10 scans per month). The Automated Pentest module is included in it, not sold separately. A card only comes into play if you move to a paid plan, and payment happens on own2pwn.fr, by card only.

How long between payment and actual access?

Access opens immediately after the payment is validated. In practice: as soon as the payment is confirmed, the subscription is attached to your account and the plan quotas apply, with no manual step in between. If you subscribe without an own2pwn account yet, the payment creates one and you get an email to set your password: access is live as soon as that is done. If anything gets stuck, write to contact@own2pwn.fr, the answer comes within 24 hours.

Can I change plan mid-subscription?

Yes, and without starting over: the account, the domains you declared and the scan history stay in place, only the quotas change. Modules are never billed separately: Automated Pentest comes with the EASM subscription, so changing plan moves the quotas of every module at once. You request the change by email to contact@own2pwn.fr, stating the plan you want and the date it should take effect; the answer comes within 24 hours. What is settled on the billing side is that the period already paid for is not refunded pro rata (article 7 of the terms of sale); the exact amount and the effective date of the new plan are confirmed to you in writing before anything is validated.

Are findings linked together, or surfaced in bulk?

Assets and findings are linked together (shared certificates, DNS, cloud relationships) to reconstruct exploitation chains. You see the graph, follow the paths ranked by severity, and measure the blast radius of a finding across the rest of your surface.

Want findings sorted by exploitability?

The module runs on a verified domain. For a hands-on engagement, a pentester replies within 24 hours.