What you are evaluating
Each module has its own authority question: network tests, cloud identity scope, and internet-surface assessment against owned properties only. Live exploits and BAS-style simulations both need authorization, change control, and stop conditions; neither is exempt.
A useful evaluation context
A plausible evaluation context is an organization that wants automated penetration testing and can staff change control, blast-radius limits, and cloud identity scope before any live exploit runs.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Agentless automated security validation through Core assessment of internal attack paths.
- Cloud and Surface modules for authorized cloud and internet-facing assessment.
- Resolve remediation orchestration that follows validated findings rather than scanner-only tickets.
Where it fits in the work
- Write an authorization that names modules, address ranges, cloud accounts, stop conditions, and the people who can halt a run.
- Execute only against owned lab or change-controlled systems; treat Surface assessment as EASM-like discovery of properties you own, not of the public internet at large.
- Use Resolve or your ticket system to assign a fix, then re-run the same scenario to verify close and retain evidence.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
In an isolated lab, authorize Pentera Core against planted vulnerable services you own. If Surface or Cloud modules are tested, point them only at lab domains and accounts. Set a stop condition if traffic leaves the lab range.
Evidence to look for
A planted exploitable condition is validated, a non-exploitable planted issue is not over-claimed, remediation is re-tested, and the run log shows no traffic outside the authorized range.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- What authorization, change-control, and kill-switch apply to this run, including tests that execute exploits?
- How is blast radius limited if a test succeeds farther than intended?
- Which cloud identity permissions does the Cloud module require, and who approves that scope?
Names you may encounter: Pentera Core · Pentera Surface · Pentera Resolve. Historical names do not establish current availability or feature equivalence.