security
Mar 31, 2026
By Teun
AWS Security Agent adds on-demand penetration testing
AWS Security Agent now offers on-demand penetration testing across AWS, Azure, GCP, and on-premises environments. The service combines SAST, DAST, and pen testing to validate vulnerabilities and generate remediation pull requests.
AWS has made its Security Agent on-demand penetration testing service generally available, moving the product out of preview and into a fuller launch. The company says the system is designed to autonomously test applications running on AWS, Azure, Google Cloud Platform, other cloud providers, and on-premises environments.
The pitch is straightforward: use software to do a job that usually takes a human pentester time to set up and run. Penetration testing, or pen testing, is the practice of simulating attacker behavior to see whether an application can actually be exploited, not just whether it looks misconfigured on paper.
According to AWS, the agent combines several security techniques in one workflow. Those include static application security testing, or SAST, which examines source code without running it; dynamic application security testing, or DAST, which checks a live application from the outside; and penetration testing methods that try to confirm whether a suspected issue is real.
AWS says the service also uses application context from code, documentation, and threat models. That context matters because security tools often produce noisy results when they only see one layer of an application, especially in larger systems where an issue in one service may or may not matter in the full path to production.
One of the main claims from AWS is that the tool can reduce false positives. In security testing, a false positive is a finding that looks like a vulnerability but turns out not to be exploitable in practice, which is a common source of wasted time for security teams and developers.
The company also says the service can shorten testing timelines from weeks to days. That reflects a long-running pain point in application security, where teams often wait for a scheduled assessment window, then wait again for results, then wait again for retesting after fixes are made.
AWS is positioning the agent as more than a scanner. After findings are confirmed, the company says it can generate remediation pull requests, which are code changes proposed through a version-control workflow such as Git. In practice, that means a finding can move from security review into a developer-visible change request without as much manual handoff.
The multicloud angle is also notable. AWS says the service can test environments beyond AWS itself, including Azure, GCP, and on-premises systems, which makes it relevant for organizations that split workloads across several platforms instead of standardizing on one cloud.
The general availability launch puts AWS into a growing group of vendors trying to automate more of application security testing. The trend is part of a broader push to use AI-assisted systems to triage findings, connect them to code context, and speed up the gap between detection and fix.
For teams that already use CI/CD pipelines, the appeal is less about replacing security staff and more about reducing the amount of manual coordination between testing, validation, and remediation. AWS is now offering the service as a product customers can use without treating it as an early-stage experiment.