Overview
Pentest-Tools.com helps security professionals find, validate, and communicate vulnerabilities faster and with greater confidence whether they are internal teams defending at scale, MSPs juggling clients, or consultants under pressure.
With comprehensive coverage across network, web, API, and cloud assets, and builtin exploit validation, it turns every scan into credible, actionable insight.
Trusted by over 2,000 teams in 119 countries and used in more than 6 million overall scans and 650,000 internal scans annually, it delivers speed, clarity, and control without bloated stacks or rigid workflows.
PentestTools.com VPN agent (internal scanning)
The VPN Agent enables our cloud based product to securely access your private Azure infrastructure so you can run internal vulnerability scans and penetration tests in minutes. No need to deploy and maintain complex on premise scanners.
Key Benefits
- Complete visibility: Extend your vulnerability assessments beyond the perimeter to cover internal servers, endpoints, and services in Azure.
- Secure by design: All scans are tunneled through the VPN Agent with no inbound firewall changes required.
- Unified view: Run the same PentestTools.com tools for both external and internal testing, managed from a single interface.
- Fast deployment: Launch in minutes and start scanning immediately, without manual setup.
Features
- Discover missing security patches and outdated network services across internal hosts.
- Detect open ports and misconfigured services that expose critical business assets.
- Find high risk vulnerabilities, weak credentials, and privilege escalation paths.
- Combine internal and external scans for a complete view of your attack surface.
- Integrate results via API for automation and reporting.
Highlights
- Complete visibility: Extend your vulnerability assessments beyond the perimeter to cover internal servers, endpoints, and services in Azure.
- Secure by design: All scans are tunneled through the VPN Agent with no inbound firewall changes required.
- Unified view: Run the same Pentest-Tools.com tools for both external and internal testing, managed from a single interface.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
Pentest-Tools.com guarantees money back for all plans purchased from our website. Please check our full refund policy here: https://support.pentest-tools.com/account-and-billing/request-refund
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Regenerate VPN Agent certificates.
Additional details
Usage instructions
Please check our detailed step-by-step article on how to integrate Pentest-Tools.com into AWS: https://support.pentest-tools.com/aws-cloud-vpn-agent
Other relevant resources about Pentest-Tools.com: https://pentest-tools.com/features/internal-network-scanning https://pentest-tools.com/features/attack-surface https://support.pentest-tools.com/how-to-scan-an-internal-network-using-open-vpn https://support.pentest-tools.com/internal-network-scan-vpn-agent
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products

Customer reviews
Automated security scans have streamlined compliance reporting and support continuous protection
What is our primary use case?
Our primary use case for Pentest-Tools.com is automated web application, external and internal network vulnerability scanning. Specifically, white-box testing for our internet-facing systems, endpoints, and databases. As a part of our SOC 2 compliance requirements, we run automated external scans on a weekly basis to detect open ports, exposed access, and security weaknesses such as XSS or SQL injection before they can be exploited.
What is most valuable?
The standout feature of Pentest-Tools.com is definitely the reporting system. Generating clean, professional, and easy-to-understand reports is effortless. Additionally, the scheduled automated scanning for external access and web applications gives us continuous visibility without heavy operational overhead.
The balance between accessibility and depth in Pentest-Tools.com is very underrated. Command-line tools such as Nmap , Gobuster, or Metasploit are powerful, but extracting readable reports from them takes a lot of manual effort. Pentest-Tools.com bridges that gap perfectly by giving non-security specialists full pentesting and reporting capabilities right out of the box.
Pentest-Tools.com has positively impacted our organization by streamlining our vulnerability management workflow significantly. By running weekly automated external scans, our DevOps team gets immediate visibility into new vulnerabilities without spending hours configuring or maintaining other tools. It also made preparing compliance evidence, such as SOC 2 external scan samples, friction-free.
What needs improvement?
Pentest-Tools.com could improve with deeper native integrations with modern CI/CD pipelines and developer platforms such as Jira or GitHub Actions for automated issue tracking and remediation workflows.
Further expanding Pentest-Tools.com API capabilities for custom webhooks and automated target asset discovery as cloud environments scale up dynamically could be beneficial.
For how long have I used the solution?
I have been using Pentest-Tools.com tools since October 2020, so for nearly six years now.
What do I think about the stability of the solution?
Pentest-Tools.com is very stable.
What do I think about the scalability of the solution?
Pentest-Tools.com scalability is effective as it scales smoothly as our external target inventory grows. Adding new domains, subdomains, and IP endpoints for scheduled weekly scans is simple.
How are customer service and support?
Pentest-Tools.com customer support is prompt, helpful, and technically accurate whenever we needed assistance with platform features or scan behavior. I would rate Pentest-Tools.com customer support a 10.
Which solution did I use previously and why did I switch?
We evaluated legacy scanners such as Nessus, Acunetix , and Netsparker before choosing Pentest-Tools.com because it offered better ease of use, superior reporting for non-security specialists, and significantly lower overhead costs.
How was the initial setup?
My experience with Pentest-Tools.com pricing, setup cost, and licensing is excellent. When we evaluated competitors such as Acunetix or Netsparker , pricing was significantly higher and tied to multi-year locks or rigid target numbers. Pentest-Tools.com provided a much more flexible and cost-effective license model with zero initial setup friction.
What about the implementation team?
Pentest-Tools.com basically provides the reports and we act on them. We did not integrate Pentest-Tools.com tools directly with other tools.
What was our ROI?
We have seen a return on investment with Pentest-Tools.com, as the ROI comes directly from the time saved by our engineering team, such as saving several hours per week on reporting and manual triage and avoiding high license fees for legacy enterprise scanners while fulfilling our SOC 2 external scanning requirements. I would say that we have saved roughly four to six hours per week compared to manually running open-source toolkits, aggregating results, and writing reports manually. Over a year, this translates to over 200 hours of engineer time saved.
What's my experience with pricing, setup cost, and licensing?
My experience with Pentest-Tools.com pricing, setup cost, and licensing is excellent. When we evaluated competitors such as Acunetix or Netsparker, pricing was significantly higher and tied to multi-year locks or rigid target numbers. Pentest-Tools.com provided a much more flexible and cost-effective license model with zero initial setup friction.
Which other solutions did I evaluate?
We evaluated other options including Netsparker, Intruder , Nessus, and Acunetix before choosing Pentest-Tools.com.
What other advice do I have?
The user experience for non-security specialists using Pentest-Tools.com is excellent. If you have a lean DevOps or IT team that needs robust security scanning and professional reporting for compliance or vulnerability management without spending weeks learning CLI security tools or paying exorbitant enterprise fees, Pentest-Tools.com is easily one of the best SaaS solutions available.
Pentest-Tools.com documentation and training resources are very helpful and easy to go through for onboarding.
Pentest-Tools.com has very solid AI capabilities that meet our requirements for secure asset handling, safe target validation, and reliable report management required for internal audits and SOC 2 evidence. Pentest-Tools.com is pretty much safe and reliable regarding its AI capabilities and the accuracy and reliability of output.
I don't integrate Pentest-Tools.com tools directly with other tools we have. Instead, we run it against our main app and extract information to use separately elsewhere.
Pentest-Tools.com performs effectively as it scales smoothly as our external target inventory grows. Adding new domains, subdomains, and IP endpoints for scheduled weekly scans is simple, so it works great.
When we formerly evaluated the enterprise solutions back in 2021, our challenge was the need to have an automated and user-friendly tool that any SysOps or DevOps personnel could operate without needing dedicated full-time security engineers. Crucially, we needed a tool that turned raw scan data into clear, actionable security reports. After reviewing Pentest-Tools.com's ease of use and reporting capabilities compared to the high cost and complexity of the other alternatives, we decided to officially adopt it. If you are in a similar situation, Pentest-Tools.com is the tool for you.
I rate this tool a 9 overall.
Accurate APIs That Power Our Pen Testing Across All SaaS Apps
A Swiss Army Knife for Quick and Deep Security Assessments
As an 5 years active user of the platform I could certainly certify that pentest-tools.com it is a great tool for quick assessments of public facing systems. The added value came also from the fact that the internal systems can be assessed too via the VPN appliance.