Listing Thumbnail

    Pentest-Tools.com VPN agent (internal scanning)

     Info
    Deployed on AWS
    AWS Free Tier
    Securely scan internal and private networks in your Azure Cloud with the Pentest-Tools.com VPN Agent for comprehensive vulnerability assessments and penetration tests.
    4.8

    Overview

    Pentest-Tools.com  helps security professionals find, validate, and communicate vulnerabilities faster and with greater confidence whether they are internal teams defending at scale, MSPs juggling clients, or consultants under pressure.

    With comprehensive coverage across network, web, API, and cloud assets, and builtin exploit validation, it turns every scan into credible, actionable insight.

    Trusted by over 2,000 teams in 119 countries and used in more than 6 million overall scans and 650,000 internal scans annually, it delivers speed, clarity, and control without bloated stacks or rigid workflows.

    PentestTools.com VPN agent (internal scanning)

    The VPN Agent enables our cloud based product to securely access your private Azure infrastructure so you can run internal vulnerability scans and penetration tests in minutes. No need to deploy and maintain complex on premise scanners.

    Key Benefits

    • Complete visibility: Extend your vulnerability assessments beyond the perimeter to cover internal servers, endpoints, and services in Azure.
    • Secure by design: All scans are tunneled through the VPN Agent with no inbound firewall changes required.
    • Unified view: Run the same PentestTools.com tools for both external and internal testing, managed from a single interface.
    • Fast deployment: Launch in minutes and start scanning immediately, without manual setup.

    Features

    • Discover missing security patches and outdated network services across internal hosts.
    • Detect open ports and misconfigured services that expose critical business assets.
    • Find high risk vulnerabilities, weak credentials, and privilege escalation paths.
    • Combine internal and external scans for a complete view of your attack surface.
    • Integrate results via API for automation and reporting.

    Highlights

    • Complete visibility: Extend your vulnerability assessments beyond the perimeter to cover internal servers, endpoints, and services in Azure.
    • Secure by design: All scans are tunneled through the VPN Agent with no inbound firewall changes required.
    • Unified view: Run the same Pentest-Tools.com tools for both external and internal testing, managed from a single interface.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Ubuntu 22.04 LTS

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pentest-Tools.com VPN agent (internal scanning)

     Info
    Pricing and entitlements for this product are managed through an external billing relationship between you and the vendor. You activate the product by supplying a license purchased outside of AWS Marketplace, while AWS provides the infrastructure required to launch the product. AWS Subscriptions have no end date and may be canceled any time. However, the cancellation won't affect the status of the external license.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Vendor refund policy

    Pentest-Tools.com guarantees money back for all plans purchased from our website. Please check our full refund policy here: https://support.pentest-tools.com/account-and-billing/request-refund 

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    Regenerate VPN Agent certificates.

    Support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.8
    111 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    86%
    14%
    0%
    0%
    0%
    0 AWS reviews
    |
    111 external reviews
    External reviews are from G2  and PeerSpot .
    Melina Souza

    Automated security scans have streamlined compliance reporting and support continuous protection

    Reviewed on Jul 30, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Our primary use case for Pentest-Tools.com  is automated web application, external and internal network vulnerability scanning. Specifically, white-box testing for our internet-facing systems, endpoints, and databases. As a part of our SOC 2 compliance requirements, we run automated external scans on a weekly basis to detect open ports, exposed access, and security weaknesses such as XSS or SQL injection before they can be exploited.

    What is most valuable?

    The standout feature of Pentest-Tools.com  is definitely the reporting system. Generating clean, professional, and easy-to-understand reports is effortless. Additionally, the scheduled automated scanning for external access and web applications gives us continuous visibility without heavy operational overhead.

    The balance between accessibility and depth in Pentest-Tools.com is very underrated. Command-line tools such as Nmap , Gobuster, or Metasploit  are powerful, but extracting readable reports from them takes a lot of manual effort. Pentest-Tools.com bridges that gap perfectly by giving non-security specialists full pentesting and reporting capabilities right out of the box.

    Pentest-Tools.com has positively impacted our organization by streamlining our vulnerability management workflow significantly. By running weekly automated external scans, our DevOps team gets immediate visibility into new vulnerabilities without spending hours configuring or maintaining other tools. It also made preparing compliance evidence, such as SOC 2 external scan samples, friction-free.

    What needs improvement?

    Pentest-Tools.com could improve with deeper native integrations with modern CI/CD pipelines and developer platforms such as Jira  or GitHub Actions  for automated issue tracking and remediation workflows.

    Further expanding Pentest-Tools.com API capabilities for custom webhooks and automated target asset discovery as cloud environments scale up dynamically could be beneficial.

    For how long have I used the solution?

    I have been using Pentest-Tools.com tools since October 2020, so for nearly six years now.

    What do I think about the stability of the solution?

    Pentest-Tools.com is very stable.

    What do I think about the scalability of the solution?

    Pentest-Tools.com scalability is effective as it scales smoothly as our external target inventory grows. Adding new domains, subdomains, and IP endpoints for scheduled weekly scans is simple.

    How are customer service and support?

    Pentest-Tools.com customer support is prompt, helpful, and technically accurate whenever we needed assistance with platform features or scan behavior. I would rate Pentest-Tools.com customer support a 10.

    Which solution did I use previously and why did I switch?

    We evaluated legacy scanners such as Nessus, Acunetix , and Netsparker  before choosing Pentest-Tools.com because it offered better ease of use, superior reporting for non-security specialists, and significantly lower overhead costs.

    How was the initial setup?

    My experience with Pentest-Tools.com pricing, setup cost, and licensing is excellent. When we evaluated competitors such as Acunetix  or Netsparker , pricing was significantly higher and tied to multi-year locks or rigid target numbers. Pentest-Tools.com provided a much more flexible and cost-effective license model with zero initial setup friction.

    What about the implementation team?

    Pentest-Tools.com basically provides the reports and we act on them. We did not integrate Pentest-Tools.com tools directly with other tools.

    What was our ROI?

    We have seen a return on investment with Pentest-Tools.com, as the ROI comes directly from the time saved by our engineering team, such as saving several hours per week on reporting and manual triage and avoiding high license fees for legacy enterprise scanners while fulfilling our SOC 2 external scanning requirements. I would say that we have saved roughly four to six hours per week compared to manually running open-source toolkits, aggregating results, and writing reports manually. Over a year, this translates to over 200 hours of engineer time saved.

    What's my experience with pricing, setup cost, and licensing?

    My experience with Pentest-Tools.com pricing, setup cost, and licensing is excellent. When we evaluated competitors such as Acunetix or Netsparker, pricing was significantly higher and tied to multi-year locks or rigid target numbers. Pentest-Tools.com provided a much more flexible and cost-effective license model with zero initial setup friction.

    Which other solutions did I evaluate?

    We evaluated other options including Netsparker, Intruder , Nessus, and Acunetix before choosing Pentest-Tools.com.

    What other advice do I have?

    The user experience for non-security specialists using Pentest-Tools.com is excellent. If you have a lean DevOps or IT team that needs robust security scanning and professional reporting for compliance or vulnerability management without spending weeks learning CLI security tools or paying exorbitant enterprise fees, Pentest-Tools.com is easily one of the best SaaS solutions available.

    Pentest-Tools.com documentation and training resources are very helpful and easy to go through for onboarding.

    Pentest-Tools.com has very solid AI capabilities that meet our requirements for secure asset handling, safe target validation, and reliable report management required for internal audits and SOC 2 evidence. Pentest-Tools.com is pretty much safe and reliable regarding its AI capabilities and the accuracy and reliability of output.

    I don't integrate Pentest-Tools.com tools directly with other tools we have. Instead, we run it against our main app and extract information to use separately elsewhere.

    Pentest-Tools.com performs effectively as it scales smoothly as our external target inventory grows. Adding new domains, subdomains, and IP endpoints for scheduled weekly scans is simple, so it works great.

    When we formerly evaluated the enterprise solutions back in 2021, our challenge was the need to have an automated and user-friendly tool that any SysOps or DevOps personnel could operate without needing dedicated full-time security engineers. Crucially, we needed a tool that turned raw scan data into clear, actionable security reports. After reviewing Pentest-Tools.com's ease of use and reporting capabilities compared to the high cost and complexity of the other alternatives, we decided to officially adopt it. If you are in a similar situation, Pentest-Tools.com is the tool for you.

    I rate this tool a 9 overall.

    Reagan R.

    Accurate APIs That Power Our Pen Testing Across All SaaS Apps

    Reviewed on Jul 24, 2026
    Review provided by G2
    What do you like best about the product?
    I use their APIs in my platform for pen testing, and I really like the accuracy of the results. We use it across all of our SaaS apps.
    What do you dislike about the product?
    There's Nothing I Dislike...............
    What problems is the product solving and how is that benefiting you?
    Our challenge was having to use multiple platforms to run pen-testing, but Pentest-Tools brings all of that together in one platform.
    Airlines/Aviation

    A Swiss Army Knife for Quick and Deep Security Assessments

    Reviewed on Jul 22, 2026
    Review provided by G2
    What do you like best about the product?
    Swiss army knife tool for quick and deep security assessments.
    As an 5 years active user of the platform I could certainly certify that pentest-tools.com it is a great tool for quick assessments of public facing systems. The added value came also from the fact that the internal systems can be assessed too via the VPN appliance.
    What do you dislike about the product?
    Nothing which I can dislike for this service.
    What problems is the product solving and how is that benefiting you?
    Swiss army knife tool for quick and deep security assessments
    Anonymous

    Fairly Priced and Efficient Vulnerability Scanner

    Reviewed on Jul 21, 2026
    Review provided by G2
    What do you like best about the product?
    I believe the pricing is very fair compared to the alternates out there. And the report is in a format that works for my customers. I love the automation part of the app also. We can schedule weekly or daily scans of our tools, which means our high-priority targets are put into scheduled tasks, allowing us to get scheduled reports and check for vulnerabilities without having to manually check them. The initial setup was really straightforward.
    What do you dislike about the product?
    I believe the interface can become more useful. It's great, but there is room for improvement.
    What problems is the product solving and how is that benefiting you?
    I use Pentest-Tools.com for automated vulnerability scanning, web application security testing, and generating reports for clients. It helps identify risks quickly and offers scheduling for scans, reducing manual work.
    Brad L.

    Easy Website Setup and Internal Pen Testing with Plug-ins

    Reviewed on Jul 16, 2026
    Review provided by G2
    What do you like best about the product?
    We use the product as part of a cyber package for our customers. It's quite easy to add the customer's website or to perform an internal pen test using their plug-ins.
    What do you dislike about the product?
    I haven't found any really. It suits our needs
    What problems is the product solving and how is that benefiting you?
    It helps us mostly with website and application pen tests.
    View all reviews