Bounded reconnaissance
Opt in on verified public targets to check a fixed list of common TCP ports plus bounded DNS and RDAP context—never arbitrary ranges, credentials, brute force, or exploitation.
RunPenTest.com brings external attack-surface checks, application findings, evidence, and remediation priorities into one understandable security workspace.
Public accounts, sign-in, and public scanning are not enabled on this site.
RunPenTest combines authorized assessment, customer-supplied evidence, and clear assurance labels without pretending automated testing is a human pentest.
MITRE ATT&CK® is used for defensive relevance mapping. A mapping never claims that attacker activity occurred.
Opt in on verified public targets to check a fixed list of common TCP ports plus bounded DNS and RDAP context—never arbitrary ranges, credentials, brute force, or exploitation.
Bring authorized Nmap XML or supported JSON into the workspace. We parse and report the inventory without contacting the imported hosts.
Track validation sources and automatically corroborate exact cross-engine matches while preserving every analyst decision.
Use conservative MITRE ATT&CK® and Cyber Kill Chain mappings for defensive prioritization—not as a claim that attacker activity occurred.
Follow queue position, retained lifecycle events, engine progress, cancellations, retries, and safe failure details from one activity timeline.
Export network inventory, evidence confidence, methodology, limitations, and automated-versus-manual disclosure in PDF, HTML, JSON, CSV, SARIF, or JUnit.
Active testing is reserved for verified targets and constrained by an explicit traffic policy. Public marketing traffic never enters the assessment system.
Prove control using DNS, a verification file, or an approved site tag.
Set approved hosts, paths, exclusions, rate limits, and assessment depth.
See progress, findings, coverage, and supporting technical evidence in one place.
Assign remediation, document decisions, and reassess to confirm the outcome.
Technical evidence and management-level analysis are presented together, with clear disclosure of what was automated, what was manually reviewed, and what remained outside scope.
This public site is informational. It does not accept credentials, create accounts, look up assessments, or initiate security testing.