---
title: "Create an Autonomous Pentest"
description: "This guide explains how to set up and launch a new autonomous penetration test for your web assets."
canonical_url: "https://docs.cobalt.io/articles/create-an-autonomous-pentest-V36zZ0UPeU"
md_url: "https://docs.cobalt.io/articles/create-an-autonomous-pentest-V36zZ0UPeU.md"
---
# Create an Autonomous Pentest

This guide explains how to set up and launch a new autonomous penetration test for your web assets.

## Prerequisites

* An active account with payment processing enabled
* Autonomous Pentest enabled (Contact your CSM for details)
* Externally facing web application
* Small to medium asset (fewer than 25 pages)
* Up to 2 roles under test
* Authentication via username/password, without MFA or magic link

## Steps

1. From your dashboard, click **Create Pentest**.
2. Choose **Start from Scratch**, select **Cobalt**, and pick a **Web Asset** from the dropdown menu.

   ![Create New Pentest](https://docs.cobalt.io/api/attachments.redirect?id=9bce4b40-4fa0-4574-b1d8-c1fe0221555b " =655x403")
3. Click **Confirm** to proceed.
4. In the **Overview** section, select your test goals. Note that Compliance Audit is not available for autonomous tests. Click **Autonomous** and ensure **Web** is selected. Click **Continue**.

   ![Autonomous Pentest Creation - Overview](https://docs.cobalt.io/api/attachments.redirect?id=3ad8a921-d939-49d5-85ff-6c5a2596c1ae " =1926x1274")
5. Review your pre-filled **Asset Details** and click **Continue**.
6. In **Pentest Details**, define your overall objectives, such as an OWASP top 10 review. Fill in any exclusions, select your environment type and data types, and complete the web specifications questionnaire. Click **Continue**.
7. On the **Access Instructions** page, click **Add Credential Set** to provide login details for the testing agent. Enter the role, username, and password, then click **Save**. The system will validate these automatically. Click **Continue**.

   ![Add Credentials](https://docs.cobalt.io/api/attachments.redirect?id=950f9ad1-4cfb-4010-bde2-9ef5a2d28dbe " =660x707")
8. In the **Scope & Test Period** section, estimate your user roles and dynamic pages using the sliders. Select your **Start Date** and click **Continue**.
9. On the **Preparation** screen, check the boxes to confirm testers have access, IPs are allowlisted, and your team is ready.
10. Click **Save & Exit** to check that the credentials are validated, or click **Launch Pentest** to complete the setup.

## Expected Result

A new autonomous pentest will be created and scheduled to begin on your specified start date.

## Troubleshooting

**Q: Why can't I select other asset types or APIs?** A: Currently, only web assets are supported for autonomous pentesting. Other types may be added in the future.

**Q: My credentials are showing as invalid.** A: Double-check that you have entered the correct username and password, and verify that the listed IP addresses have been allowlisted on your network.
