OFICIAL AWS What's New

AWS Security Agent now supports email-based MFA for penetration testing

What happened
Based on AWS What's New · Aug 06, 2026

AWS Security Agent now supports penetration testing for applications using email-based MFA, expanding automated testing coverage beyond TOTP methods.

Key points
·
AWS Security Agent (now part of AWS Continuum ) now enables penetration testing of applications that use email-based multi-factor authentication (MFA) as part of their login flow.
·
Previously, applications requiring one-time codes or verification links sent by email the company is out of scope for automated pentesting because the agent had no mechanism to intercept those messages.
·
This launch broadens coverage for penetration testing customers whose target applications rely on email-based authentication.
·
To use this feature, AWS Security Agent generates a unique forwarding address per credential, allowing you to route your application's MFA emails directly to the agent using a forwarding rule in your existing email provider.

AWS Security Agent, now part of AWS Continuum, has introduced support for penetration testing applications that rely on email-based multi-factor authentication (MFA). Previously, automated penetration testing excluded such applications because the agent could not intercept one-time codes or verification links sent via email. The new capability addresses this gap by enabling testing for applications using email-based authentication flows. Customers can now assess security more comprehensively across diverse MFA methods. The feature is available in all AWS Regions where AWS Security Agent is supported.

To implement this feature, AWS Security Agent generates a unique forwarding address for each credential, allowing users to route their application's MFA emails directly to the agent. This is achieved by configuring a forwarding rule in the existing email provider. During a penetration test, the agent automatically reads the forwarded message and submits the one-time code or verification link to complete authentication. The process ensures that no email account credentials are stored, maintaining a strong privacy posture throughout the testing phase.

This capability complements the existing support for Time-based One-Time Password (TOTP) methods, providing customers with a unified solution for testing applications across multiple MFA authentication types. The integration simplifies the testing process by eliminating the need for manual intervention to handle email-based MFA flows. AWS Security Agent now offers broader coverage for penetration testing, accommodating a wider range of application security assessments.

The feature is now available in all AWS Regions where AWS Security Agent is supported. Customers interested in utilizing this capability can find additional details on the AWS Security Agent product page and the AWS Security Agent User Guide. The documentation provides step-by-step instructions for configuring email forwarding and conducting penetration tests with email-based MFA.

Original source → Deals on Clipraptor.com →