AWS Security Agent adds on-demand penetration testing

AWS Security Agent now offers on-demand penetration testing across AWS, Azure, GCP, and on-premises environments. The service combines SAST, DAST, and pen testing to validate vulnerabilities and generate remediation pull requests.

AWS Security Agent adds on-demand penetration testing

AWS has made its Security Agent on-demand penetration testing service generally available, moving the product out of preview and into a fuller launch. The company says the system is designed to autonomously test applications running on AWS, Azure, Google Cloud Platform, other cloud providers, and on-premises environments.

The pitch is straightforward: use software to do a job that usually takes a human pentester time to set up and run. Penetration testing, or pen testing, is the practice of simulating attacker behavior to see whether an application can actually be exploited, not just whether it looks misconfigured on paper.

⚡ New to this?

This is about an AI-driven security testing tool from AWS that can check apps for weaknesses without waiting for a person to run every test by hand. Pen testing means trying to break into software the way an attacker would, while SAST and DAST are two common ways to inspect code and running apps for flaws. Non-experts should care because faster, more automatic testing can help companies find security issues sooner, especially when their systems run across multiple clouds or on their own servers.

🦞 OpenClaw angle

For builders and self-hosters, the interesting part is the shift from point-in-time pen testing to continuous, context-aware validation. For IT and security teams, the combination of authenticated testing, multicloud coverage, and remediation pull requests could make it easier to fold security checks into CI/CD and reduce the backlog of untested apps.

According to AWS, the agent combines several security techniques in one workflow. Those include static application security testing, or SAST, which examines source code without running it; dynamic application security testing, or DAST, which checks a live application from the outside; and penetration testing methods that try to confirm whether a suspected issue is real.

AWS says the service also uses application context from code, documentation, and threat models. That context matters because security tools often produce noisy results when they only see one layer of an application, especially in larger systems where an issue in one service may or may not matter in the full path to production.

One of the main claims from AWS is that the tool can reduce false positives. In security testing, a false positive is a finding that looks like a vulnerability but turns out not to be exploitable in practice, which is a common source of wasted time for security teams and developers.

The company also says the service can shorten testing timelines from weeks to days. That reflects a long-running pain point in application security, where teams often wait for a scheduled assessment window, then wait again for results, then wait again for retesting after fixes are made.

AWS is positioning the agent as more than a scanner. After findings are confirmed, the company says it can generate remediation pull requests, which are code changes proposed through a version-control workflow such as Git. In practice, that means a finding can move from security review into a developer-visible change request without as much manual handoff.

The multicloud angle is also notable. AWS says the service can test environments beyond AWS itself, including Azure, GCP, and on-premises systems, which makes it relevant for organizations that split workloads across several platforms instead of standardizing on one cloud.

The general availability launch puts AWS into a growing group of vendors trying to automate more of application security testing. The trend is part of a broader push to use AI-assisted systems to triage findings, connect them to code context, and speed up the gap between detection and fix.

For teams that already use CI/CD pipelines, the appeal is less about replacing security staff and more about reducing the amount of manual coordination between testing, validation, and remediation. AWS is now offering the service as a product customers can use without treating it as an early-stage experiment.

Source: AWS Security Blog ↗

More from Security News