OFICIAL AWS What's New Software · Aug 06, 2026

AWS Security Agent now supports email-based MFA for penetration testing

In brief · 4 sentences
Based on AWS What's New · Aug 06, 2026

AWS Security Agent now supports penetration testing for applications using email-based MFA, expanding automated security testing coverage for login flows that rely on one-time codes or verification links.

Key points
·
Main topic: aWS Security Agent now supports email-based MFA for penetration testing.
·
Category affected: software.
·
The information comes from an official source.
·
The next step is to watch availability, pricing and real-world impact.

The useful question is what changes for users, developers or buyers, and whether the announcement stays industry context or becomes something people can actually use.

AWS Security Agent, part of AWS Continuum, has introduced support for penetration testing applications that use email-based multi-factor authentication (MFA). Previously, automated pentesting excluded such applications because the agent lacked a method to intercept email-delivered one-time codes or verification links. This update addresses that gap, enabling broader coverage for customers testing applications with email-based authentication flows. The feature integrates with existing email providers, allowing MFA emails to be forwarded to a unique address generated by the agent for each credential. During a pentest, the agent reads the forwarded message and submits the code or link to complete authentication, without storing email account credentials to maintain privacy. This capability complements existing support for time-based one-time password (TOTP) methods, providing a unified solution for testing applications across multiple MFA approaches.

AWS Security Agent generates a unique forwarding address for each credential, enabling customers to route their application’s MFA emails directly to the agent using a forwarding rule configured in their email provider. The agent then automatically extracts and submits the one-time code or verification link during penetration testing, eliminating the need for manual intervention. This process ensures that automated security assessments can proceed without requiring access to the user’s email account, reducing operational overhead while preserving security protocols.

The new feature is available in all AWS Regions where AWS Security Agent is supported, expanding its utility for customers conducting security testing across global deployments. AWS emphasizes that the implementation maintains a strong privacy posture by avoiding the storage of email account credentials, aligning with best practices for secure penetration testing. Customers can now test applications with email-based MFA alongside those using TOTP, streamlining the assessment of diverse authentication mechanisms within a single framework.

To implement this feature, customers must configure their email provider to forward MFA messages to the unique address generated by AWS Security Agent. The agent processes these messages in real time during pentesting, submitting the required authentication details to complete the login flow. AWS provides documentation in the Security Agent User Guide and product page to guide users through setup and configuration, ensuring a smooth integration with existing testing workflows.

Original source → Deals on Clipraptor.com →
Extracted signals · detected in the story
AWS Security AgentMFAAWS ContinuumPreviouslyDuringTOTPAWS RegionsAWS Security Agent User Guide.