AWS Continuum Adds Credential Testing and Domain Suggestions
Cloud

AWS Continuum Adds Credential Testing and Domain Suggestions

AWS Continuum for penetration testing now supports credential tests and accessible-domain suggestions before a test runs. Teams can validate login credentials and review in-scope URL suggestions during setup, before a full test cycle begins.

2 min read
Back to News
TL;DR
  • -AWS Continuum for penetration testing now supports credential tests and accessible-domain suggestions before a penetration test runs.
  • -During login, the service captures every accessible domain and surfaces those domains as in-scope URL suggestions for scope review.
  • -AWS says the release makes it easier to configure an accurate network scope from the start and can reduce misconfiguration and wasted test cycles.

What Changed

AWS Continuum for penetration testing now supports credential tests and accessible-domain suggestions before a penetration test runs. Developers and security teams can use both features during test setup.

AWS describes Continuum for penetration testing as a frontier agent. The service offers customized, on-demand penetration tests with real exploitability testing. The new release focuses on two parts of setup: checking login credentials and finding the domains those credentials can reach.

Before the release, finding all the URLs reached by an application required manual effort. Authentication failures could remain hidden until a full test cycle had finished.

How Credential Testing Works

AWS Continuum authenticates into the application exactly as a real user would. This gives the service a chance to check the credentials before the real penetration test starts.

AWS says users can validate the credentials before the real test begins. A team can see whether the login works while it is still setting up the test. If the login needs attention, the issue appears before a full test cycle is complete.

How Domain Suggestions Work

During login, AWS Continuum captures every accessible domain reached in that login. It surfaces those domains as in-scope URL suggestions. The user can review the suggestions while setting the network scope.

Users can review accessible domains before the real test begins. They can confirm that the agent covers the right endpoints. The review brings the login result and the proposed scope into the same setup stage.

Accessible domains are returned when the credential test succeeds. They are also returned when the test fails or times out. A failed or timed-out credential test can still give the team domain information to review.

Why the Change Matters

AWS says the release makes it easier to configure an accurate network scope from the start. The company says earlier credential and domain checks can reduce misconfiguration and wasted test cycles. The key change is timing: teams receive the credential result and domain suggestions before the full test runs, with both available in the same configuration stage.

Availability

AWS states the capability is available wherever AWS Continuum for penetration testing is supported. AWS has not enumerated specific regions; the announcement links to the AWS Continuum product page for details.

Sources and supporting resources
Next
SAP-Commissioned IDC Study Reports 368% ROI for Integration Suite

Get Business Technology Updates

Practical guidance on complex operations, integration, portals, analytics, automation, custom software, trusted records, and fit-for-purpose engineering.

No spam. Unsubscribe anytime.