Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI-assisted penetration testing: are your coverage and findings improving?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: Time-boxed testing now depends as much on machine-assisted discovery depth as on human exploitation skill, according to TENZAI. Markus Alliance says Tenzai helped it achieve 5x penetration testing efficiency, 4x higher attack surface coverage, and doubled engagement capacity by automating reconnaissance, discovery, mapping, and attack chaining across application tests.

NHIMG editorial — based on content published by TENZAI: Markus Alliance achieves 5x penetration testing efficiency with Tenzai

By the numbers:

  • According to Markus Alliance, one engineer would typically reveal 20-25% of the attack surface in a week of discovery work for a large application.

Questions worth separating out

Q: How should security teams use AI-assisted penetration testing without losing trust in the results?

A: Use AI-assisted testing to widen discovery, then force a human validation step before any output becomes a confirmed finding.

Q: Why does broader attack surface coverage matter in application security programmes?

A: Broader coverage matters because time-boxed tests always leave some paths unexplored, and the missed paths are often where privilege boundaries, hidden APIs, and exposed secrets sit.

Q: What do security teams get wrong about AI-generated penetration testing findings?

A: The main mistake is treating AI output as proof rather than as a lead.

Practitioner guidance

  • Re-baseline discovery coverage metrics Measure how much of the application attack surface is actually being mapped during the first phase of testing, including endpoints, APIs, user roles, and hidden workflows.
  • Separate AI-generated leads from confirmed findings Require a handoff step where human testers validate exploitability, business impact, and access scope before a finding is treated as actionable.
  • Route exposed secrets into identity remediation When testing reveals secrets, admin paths, or privilege shortcuts, send the issue to the teams that own authentication, authorisation, and secret handling.

What's in the full report

TENZAI's full case study covers the operational detail this post intentionally leaves for the source:

  • How the hybrid workflow is structured between autonomous discovery and human exploitation review
  • Examples of follow-on use with Ask Tenzai and Burp Suite extension workflows
  • The engagement model that supported a new low-touch penetration testing tier
  • Customer-facing transparency details showing how actions and findings were traced during testing

👉 Read TENZAI's case study on hybrid AI-assisted penetration testing efficiency →

AI-assisted penetration testing: are your coverage and findings improving?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

Hybrid testing changes the unit of security work, but not the need for human judgment. AI-assisted reconnaissance can compress discovery from days into hours, yet the decisive security value still comes from skilled testers interpreting what the machine finds. That matters because automated breadth without human validation can produce noisy coverage rather than actionable risk reduction. Practitioners should treat AI as a discovery multiplier, not as an authority on exploitability.

A question worth separating out:

Q: How can organisations prioritise penetration testing when applications outnumber testers?

A: Focus on the applications and interfaces most likely to expose privileged access, sensitive data, or business-critical workflows, then use assisted discovery to broaden the first pass. That approach preserves depth where it matters while reducing time spent on repetitive reconnaissance. The key is to align test effort with risk, not with application count.

👉 Read our full editorial: Hybrid AI-assisted penetration testing changes application risk coverage



   
ReplyQuote
Share: