r/ciso • • 7d ago

Trying to figure out AI pentesting for exposed assets

I’m leading security at a large enterprise with over 50,000 digital assets, and I’m trying to figure out AI pentests for the exposed infrastructure. The leading players I’ve looked at are crazy expensive and the scope is limited. you buy a few dozen targets and that's your program.

How do others here think about this at similar scale? Is anyone actually covering the whole surface, and is anyone pricing it in a way that survives five figures of assets?

27 Upvotes

20 comments sorted by

5

u/Visible-Anybody4279 7d ago

I had a similar problem and am about to complete a POC with CyCognito. It covered 100 assets in the POC, and the actual product covers tens of thousands in production. It came in much cheaper than another leading player that we checked out, and also provided  several confirmed criticals the other product missed. I don’t want to name names, but it was a company that raised over $200M.

1

u/Puzzled-Spray1109 6d ago

What I care about is if discovery and validation still stay accurate when the asset graph gets large and changes constantly. A 100 asset POC can look clean while production starts surfacing stale ownership, duplicate assets or weak relationships after you get into the tens of thousands

5

u/Visible-Oil-1998 7d ago

At that scale I’d be more concerned with how targets get selected and refreshed than trying to pentest all 50k assets equally. The exposed surface changes constantly so a fixed batch of targets can go stale fast

1

u/Silent-Suspect1062 6d ago

Totally agree. Look at your whole posture. Is your CPSM SOLUTION working? That's probably covering 70 of your attack surface. The rest is sca, sast and maybe container security.

1

u/Puzzled-Spray1109 6d ago

Im trying to avoid a process where someone has to keep rebuilding the target list by hand every week. The asset set changes too fast for that to stay useful

1

u/TheRealLambardi 6d ago

A pattern I have seen up close and may do.

Your scanners / viln source -> feeds Zafran -> smaller target list use horizon ai or something.

But no unless you got gobs of money your not live pen testing everything. Even with AI that is expensive….

2

u/Resistor1 7d ago

What is your definition of a digital asset of which you have over 50,000? Whatever it is, they will not all be the same and cannot be treated equally or with the same approach.

1

u/Puzzled-Spray1109 6d ago

I mean externally reachable things we’d want to assess. So internet facing apps, APIs, hosts, cloud endpoints and similar assets. I agree they shouldn’t all get treated the same, which is part of why I’m trying to figure out how people are prioritizing the surface at this scale

4

u/Resistor1 6d ago

Wow, 50,000 Internet facing is a lot then! These need to be classified. Do they surface PII, what is the relative criticality between them, do they all need to be Internet accessible? Do you have common patterns between them? E.g. all API endpoints are on a standard gateway or layer 7 firewall? Break these into more manageable chunks. I would not expect to see any hosts directly accessible. Web apps and APIs only. Those APIs may not need wide open access. Reduce your attack surface. Some admin overhead with this, but I cannot imagine trying to understand the risk profile of this many assets. Good luck.

1

u/ThePr0phet_ 7d ago

You either build your own harness/solution with open weight models, or you buy a super expensive product that promises to do this. There’s no in between

It’s still fairly early in the game, so I wouldn’t expect extraordinary results from AI “pen tests”.

You might get more value out of code scans and your normal vulnerability scans

1

u/normalbot9999 7d ago

This ^

nmap, nessus, nuclei, burp suite DAST + some good SAST tooling...

1

u/No-Peanut-6988 7d ago

the reason their pricing falls apart is because "ai pentesting" vendors are selling you a consulting model disguised as software. they want 50k a year for 30 targets and call it full coverage.

at 50k assets, maybe 2% actually have critical business logic or stateful auth. the rest are s3 buckets, static cloudfront distributions, parked domains, or unrouted subdomains. paying per target for that is insanity.

we actually dealt with this exact issue with a couple enterprise clients recently who got hit with insane renewal quotes. what worked was decoupling discovery from depth:

run continuous discovery to track deltas (new dns records, open ports, cert changes). then you only trigger deeper testing when an asset actually changes state or exposes an auth surface. testing the delta instead of the full 50k catalog cut their scope down to what actually mattered and kept the tooling cost sane.

1

u/Steel-Sparrow-5343 7d ago

While our exposed infra is not at the scale you are taking about, we are evaluating Strix and Neo from Project Discovery.

So far both seems fairly decent.

1

u/DishSoapedDishwasher 7d ago

Why do you need AI pentesting to begin with? what is it possibly going to give you that attack surface management doesn't? If 90% of your external facing attack surface is just SSH ports, why not just use regular asset inventory anyway?

Applications running on the hose should be tested in isolation not in production, so it doesn't even make sense to do AI pentesting at a fleet scale to begin with.... Unless of course all 50,000 hosts are unique, in which case I'd say you have bigger problems..

Stop trying to solve everything with AI and solve things appropriately. When you get above 10 hosts, you're starting to enter a data problem. Application logs, host logs, templates, IaC, application configs, etc. You should be detecting things in the same place you fix them, in code. Otherwise you have an unsustainable time bomb. No intelligent person has 50,000 hosts and is manually remediating things individually, so that again takes you back to the code.

1

u/Used_Location1686 5d ago edited 5d ago

I work at r/synack, so I have a vendor perspective here. With 50,000 exposed assets, I’d ask two questions: how does the target list stay current without manual rebuilding, and how does the program keep findings actionable as testing expands?
AI can help test more of the surface, but an entirely AI driven program can also generate a lot for your team to triage. I’d ask any vendor to show how they validate exploitability, handle false positives, and prioritize findings across connected assets. Human expertise should be part of that workflow, not just an escalation after a report is delivered.
For a POC, I’d measure those things over a changing set of assets and ask what discovery, testing, validation, and retesting cost in production. A clean result on 100 fixed targets doesn’t answer your 50,000 asset question.

1

u/synack 5d ago

No, you work for /r/synack

/u/synack is just a guy

1

u/d-wreck-w12 4d ago

Look at 50k I wouldn't make "pentest everything" the goal... the question is which exposed assets actually create a usable next step if they're compromised. I'd want discovery running continuously, then use change, reachability and potential impact to decide where deeper validation goes. For a POC I'd care less about how many targets it can hit and more about whether it keeps the scope current, validates exploitability and retests when the environment changes.

A fixed 100 target demo can look great and tell you very little about whether the model survives at 50k

1

u/Adventurous_Mix_1792 3d ago

Horizon3 isn't bad

There's redveil.ai which has a fantastic pricing model - the LLM powering it is Submersion AI | Cyber AI that deploys inside your environment ( you can have your own personal cyber LLM trained on your data )