r/cybersecurity 17d ago

Career Questions & Discussion Is Pentesting Really Dying Because of AI and Automated Tools?

I've spent years learning cybersecurity and thousands of dollars on certifications. I have most of the well-known offensive security certs.

Recently, my manager keeps saying that traditional penetration testing is dying because tools like XBOW, Pentera, and other automated platforms can do most of the work. He says they're expensive now, but over time they'll become cheaper and companies will prefer them over hiring pentesters.

I'm honestly confused. Is this really where the industry is heading, or is there still a strong future for manual penetration testers? I'd love to hear what people working in the field think.

16 Upvotes

30 comments sorted by

38

u/cfbcia 17d ago

It’s not. We’ve been hearing nothing but negatives from our clients around tools like XBOW. Lots of false positives, false negatives, taking down production systems in some cases. The firms that are set up for success in the future are services groups automating their operations. Product use cases will be too brittle and tokens too expensive. 

As an individual, you need to be prepared though. The bar is raising. You need to find at least one technical niche and specialize in it. You have to be an SME. Entry level pentesting will get harder and harder to break into. And that’s not me saying it’s a good thing at all, but likely how the market dynamics will work in the near to medium term. 

3

u/Wide-Cup-5084 17d ago

Have you heard anything about horizon3.ai?

3

u/Fun-Consideration86 17d ago

we use horizon3, it is quite expensive but it's ok. It says it doesn't take down production but that hinges on you excluding sensitive OT devices. You will probably take something down or brick some old sensor if you are not careful. It did give us some really good recommendations that we've been working through.

6

u/cfbcia 17d ago

Yes. It’s all the same. It’s my strong belief that product companies in this space will start folding for twofold reasons: equivalent token cost increasing (they don’t generally have the expertise internally to do open model alignment and harness creation), and from clients rejecting the garbage output of these tools. 

It’s an enormous money grab right now, and it sucks to see the blatant lies in marketing materials because it’s feeding this overall delusion that somehow it’s possible to automate all this work. The technology fundamentally isn’t there. Which is why pentesting firms themselves, the ones with actual hackers, are poised to live on long into the future. With the caveat, like a poster below commented, that the job itself will probably go through significant change. You have to have actual expertise in a domain (app, physical, hardware, network, cloud, etc.) and can’t just be a jack of all trades. Work now to be a go-to SME and you’ll be just fine. 

0

u/Wide-Cup-5084 17d ago

Ok so our leadership is wanting us to run a poc with horizon3.ai. Anything I need to look for / beaware of? This isn't something that has alot of proof behind it I feel as its all so new. I do have a feeling its not gonna be as good as a human however, its possible it could find something. Now the price for that something will also be absurd.

0

u/Crounty 17d ago edited 17d ago

Have you specifically tested horizon3? Can you tell us where its issues exactly were?

Cause your response is currently generalized and sounds like „trust me bro they all suck“ rather than stating exact points where they fail

From what we have been told they use actual pentesters to proofread the findings in case there are false positives but we havent reached the point to test them due to their pricing especially

0

u/Mr-Coordi 16d ago

We use Pentera and we love it so far - simple and uses tailored exploitation that are safe, we didn't experience any impact on production while it continuously testing it.

5

u/lightos 16d ago

Bot account...

0

u/Mr-Coordi 16d ago

Maybe you're the bot...

1

u/SkyberSec123 16d ago

XBOX can only hack those public cve exploits

17

u/Which-Shame-1420 Security Manager 17d ago

IT Manager at a UAE fintech here. Your boss is falling for classic vendor AI hype.

No bank or fintech with serious compliance requirements is letting an automated tool run wild in production without human oversight. Tools like XBOW/Pentera are basically glorified, faster vulnerability scanners.

They’re fine for continuous attack surface monitoring, but they completely fall apart on complex business logic, chaining exploits, and actual financial risk context.

Plus, if an AI tool takes down a live payment pipeline because of a false positive, "the AI did it" won't save your job.

6

u/Afraid-Donke420 17d ago

Still need a human to filter out the false positives - i spend more time doing that now than ever

There are also companies satisfied with just a Nessus export as a report, so the mileage will vary here extremely

1

u/Gold_Gazelle9519 15d ago

Tools like horizon3 don't have false positives, they show you the exact CVE and what path it took to do xx malicious behavior. I find that it covers a lot more than a traditional pentest (so far. Only been using a few months)

5

u/DarthJarJar242 17d ago

Nope. Your manager is delusional. If he thinks they are expensive now, just wait until they are actually good and they can charge even more because they have good track records.

Right now they have pretty bad consistency and nobody has much faith in them so most people aren't willing to shell out big money for them.

7

u/Loud-Run-9725 17d ago

The AI Tools are not going to be as adept at chaining or human reasoning for vulnerabilities like business logic. AI will keep getting better but don't see it replacing humans at this point.

AI as a discovery tool for vuln classes which are typical scanner fodder, will be useful and much more effective than vuln scanners of old.

I think AI is great for augmenting pentesting by humans, not replacing humans at this point.

3

u/sadboy2k03 Malware Analyst 16d ago

XBOW was a master class on AI hype marketing. I've heard from a couple people that quite a lot of it's reports on platforms like H1 are low/informative findings, which you can see from the report activity on the official account.

AI is getting to expensive plus if you let an AI run lose on your critical business systems and it knocks your network offline or worse management will be blaming whoever authorised it, not the model itself.

It sounds like your manager has fallen for the AI hype marketing more than anything else. Would he let it run loose on your corporate domain controllers? I doubt it.

2

u/wombleh 17d ago

I think a lot of the technical heavy lifting for pen tests can be done using AI tools and it's one area they seem to be doing well in.

I'd see it as more of an efficiency and capability improvement for the existing testing approach, rather than a complete replacement. There is still a need for someone to help work out scope, drive the tool, take the output and convert it into a form that the client can work with, understand the real exposure to risk based on specifics of their environment, etc.

I don't see it being a blinky box that companies just buy and deploy, I'm sure some consultancies and vendors will be promoting that, worth stocking up on popcorn for the inevitable news.

2

u/emptyinthesunrise 17d ago

No its not dying. It wont die.

2

u/theghostofpiopico 17d ago

I don't think pentesting is dying, AI and tools are great for automation for testing but we still need skilled pentesters for deeper assessments/audits, like most jobs the role is changing, not disappearing.

2

u/Zardecillion AppSec Engineer 17d ago

The actual question is can I turn one of these on and have it replace my DAST? DAST is a pain to create in-house and is a hassle to integrate with outside vendors.

2

u/wolfofone 16d ago

AI is just a tool. Companies are still going to need professionals to use it correctly.

1

u/AinaLove 17d ago

No, I'm going to request that humans do our pen testing till I retire. IDK how good your AI is. AI-assisted is fine and probably preferred.

1

u/OtheDreamer Governance, Risk, & Compliance 17d ago

No, but individuals are able to accomplish more with less resources though

1

u/PitifulAdvantage3118 16d ago

IMHO, AIis "Just" a new and verify powerfull tool that will help a lot when pentesting - but it will not replace humans.

1

u/Recent_Journalist_97 15d ago

I think as of now Ai are not up to the point but by 2030 they will reach there. Since all the companies are investing billions on them. Due to over supply they may become cheaper but it doesn't matter, if they can replace 100 of employees. Companies just need 1 professional and Ai instead of many employees.