Authorized web security assessment

Know what is exposed. Know what to fix next.

RunPenTest.com brings external attack-surface checks, application findings, evidence, and remediation priorities into one understandable security workspace.

Private beta is underway

Public accounts, sign-in, and public scanning are not enabled on this site.

Security posture Example
82/100
High
Known vulnerable componentEvidence and affected endpoint captured
Open
Medium
Security policy not enforcedPrioritized configuration guidance
Open
Fixed
Session protection improvedVerified in the latest assessment
Closed
TransportTLS and certificate health
ApplicationOWASP-oriented web checks
ExposureKnown CVEs and risky services
ResponsePrioritized remediation
Latest private-beta capabilities

Move from public exposure to evidence-backed decisions.

RunPenTest combines authorized assessment, customer-supplied evidence, and clear assurance labels without pretending automated testing is a human pentest.

MITRE ATT&CK® is used for defensive relevance mapping. A mapping never claims that attacker activity occurred.

01

Bounded reconnaissance

Opt in on verified public targets to check a fixed list of common TCP ports plus bounded DNS and RDAP context—never arbitrary ranges, credentials, brute force, or exploitation.

02

Imported network evidence

Bring authorized Nmap XML or supported JSON into the workspace. We parse and report the inventory without contacting the imported hosts.

03

Corroborated findings

Track validation sources and automatically corroborate exact cross-engine matches while preserving every analyst decision.

04

Adversary relevance

Use conservative MITRE ATT&CK® and Cyber Kill Chain mappings for defensive prioritization—not as a claim that attacker activity occurred.

05

Live assessment log

Follow queue position, retained lifecycle events, engine progress, cancellations, retries, and safe failure details from one activity timeline.

06

Analysis-ready reports

Export network inventory, evidence confidence, methodology, limitations, and automated-versus-manual disclosure in PDF, HTML, JSON, CSV, SARIF, or JUnit.

Controlled by design

Assessment begins with authorization.

Active testing is reserved for verified targets and constrained by an explicit traffic policy. Public marketing traffic never enters the assessment system.

  1. 1
    Verify the target

    Prove control using DNS, a verification file, or an approved site tag.

  2. 2
    Define safe scope

    Set approved hosts, paths, exclusions, rate limits, and assessment depth.

  3. 3
    Review evidence

    See progress, findings, coverage, and supporting technical evidence in one place.

  4. 4
    Fix and verify

    Assign remediation, document decisions, and reassess to confirm the outcome.

Executive assessment reportRunPenTest.com
B
Overall posture

Risk is manageable, with focused remediation required.

Useful beyond the security team

Reports for remediation, leadership, and audit conversations.

Technical evidence and management-level analysis are presented together, with clear disclosure of what was automated, what was manually reviewed, and what remained outside scope.

  • Executive posture and material-risk summary
  • Technical findings with reproducible evidence
  • Prioritized remediation roadmap
  • Coverage, limitations, and methodology disclosure
  • PDF, HTML, JSON, CSV, SARIF, and JUnit formats
Launching carefully

RunPenTest.com is currently available only through a controlled private beta.

This public site is informational. It does not accept credentials, create accounts, look up assessments, or initiate security testing.