Start an Autonomous Pentest

Configure and launch an autonomous test against approved, non-business-critical assets with Savant Pathseeker. The test performs controlled, outside-in testing against internet-accessible domains, web apps, and APIs.

Before you begin: Assets must be Approved (see Discover Your Estate).

Steps

1. Confirm scope is safe to test

Before touching the platform: verify your approved scope has been reviewed (per Guide 1), avoid business-critical systems for initial tests, and confirm your primary point of contact is available during the test window. This is an autonomous agent – human oversight during the first run is essential.

Tip: This is a hard stop. Launch only after scope is confirmed. A red Stop Test button is available mid-run if anything unexpected occurs.

2. Navigate to Autonomous Tests

Go to the program where you want results to surface. Click the Autonomous Tests tab, then click New Autonomous Test.

3. Configure and launch the test

Provide a test name (and optional tags for tracking). Add targets using Asset Groups for bulk targeting or Add Targets to type individual approved assets. Choose whether to allow credentialed attacks – leave this off for your first test unless specifically scoped for it. On the review screen, confirm the approved assets in scope match your intent. Check the authorization checkbox, then click Agree and Launch Test.

4. Monitor test progress

Watch status and progress indicators in the platform during the run in the Activity tab. If anything appears unexpected – out-of-scope behavior, unexpected volume – click Stop Test immediately.

5. Review findings

When complete, open the Results tab. Navigate the sub-tabs for Executive Summary (Top Findings, Recommended Next Steps, Risk Summary) and Vulnerabilities (list of all findings). You can click on individual vulnerabilities to get details like Security Impact, Description, Attack Flow, and Evidence Packages (if available).

You have run a controlled autonomous pentest against your external assets.