AWS Continuum now supports credential testing and accessible domain suggestions
AWS Continuum for penetration testing now supports credential testing and domain suggestions, streamlining test configuration and reducing manual effort for developers and security teams.
AWS Continuum for penetration testing introduces credential testing and accessible domain suggestions to enhance security workflows. Developers and security teams can now validate login credentials before initiating a penetration test, ensuring authentication works as expected. The feature captures all domains accessed during login, providing in-scope URL suggestions to reduce manual configuration. This addresses a common pain point where authentication failures were only detected after completing a full test cycle, wasting time and resources.
Previously, identifying all URLs an application interacts with required manual effort, often leading to misconfigured test scopes. With this update, AWS Continuum automatically authenticates into applications, mirroring real user behavior to capture accessible domains. Users can review these domains, validate credentials, and confirm coverage before the penetration test begins, improving accuracy and efficiency. The feature operates regardless of whether credential testing succeeds, fails, or times out, ensuring comprehensive visibility.
The new capability is now available in all regions where AWS Continuum for penetration testing is offered. It is designed to integrate seamlessly into existing security workflows, reducing the risk of misconfiguration and wasted test cycles. By surfacing accessible domains upfront, teams can focus on high-value testing rather than troubleshooting authentication issues. The feature is detailed in updated documentation and the AWS Continuum product page.
This enhancement builds on AWS Continuum’s existing on-demand, customized penetration testing capabilities. It specifically targets the challenges of test configuration and scope definition, which previously required significant manual intervention. By automating credential validation and domain discovery, the update aims to improve the reliability and efficiency of penetration testing processes. Teams can now ensure their tests cover the correct endpoints from the outset.