Detected country: US
logo
API Docs
‌
‌
‌
logo

Powered by

  • Home
  • Pentests
  • Create an Autonomous Pentest

Create an Autonomous Pentest

1min read

Share

This guide explains how to set up and launch a new autonomous penetration test for your web assets.

Prerequisites

  • An active account with payment processing enabled
  • Autonomous Pentest enabled (Contact your CSM for details)
  • Externally facing web application
  • Small to medium asset (fewer than 25 pages)
  • Up to 2 roles under test
  • Authentication via username/password, without MFA or magic link

Steps

  1. From your dashboard, click Create Pentest.

  2. Choose Start from Scratch, select Cobalt, and pick a Web Asset from the dropdown menu.

    Create New Pentest

  3. Click Confirm to proceed.

  4. In the Overview section, select your test goals. Note that Compliance Audit is not available for autonomous tests. Click Autonomous and ensure Web is selected. Click Continue.

    Autonomous Pentest Creation - Overview

  5. Review your pre-filled Asset Details and click Continue.

  6. In Pentest Details, define your overall objectives, such as an OWASP top 10 review. Fill in any exclusions, select your environment type and data types, and complete the web specifications questionnaire. Click Continue.

  7. On the Access Instructions page, click Add Credential Set to provide login details for the testing agent. Enter the role, username, and password, then click Save. The system will validate these automatically. Click Continue.

    Add Credentials

  8. In the Scope & Test Period section, estimate your user roles and dynamic pages using the sliders. Select your Start Date and click Continue.

  9. On the Preparation screen, check the boxes to confirm testers have access, IPs are allowlisted, and your team is ready.

  10. Click Save & Exit to check that the credentials are validated, or click Launch Pentest to complete the setup.

Expected Result

A new autonomous pentest will be created and scheduled to begin on your specified start date.

Troubleshooting

Q: Why can't I select other asset types or APIs? A: Currently, only web assets are supported for autonomous pentesting. Other types may be added in the future.

Q: My credentials are showing as invalid. A: Double-check that you have entered the correct username and password, and verify that the listed IP addresses have been allowlisted on your network.

Nested Articles

Launch a Saved Autonomous Pentest

Review a Closed Autonomous Pentest Report

Share