Case Study - Automated Penetration Testing (Prove It, Don’t List It)
Scanner: 0 critical. Our automated chain: tenant A admin → tenant B invoices. With screenshots.
DISCOVER
SCAN
EXPLOIT
EVIDENCE
Safe-by-default: scoped, rate-limited, staging-first, kill-switch, full audit log
Client Context
B2B SaaS — multi-tenant HR/payroll, 800 corporate tenants, weekly deploys, SOC 2 Type II audit in 8 weeks. Annual manual pentest left 11 months uncovered.
Challenge
Need penetration-grade proof between annual tests: combine discovery, scanning, exploitation validation, and evidence collection automatically — without disrupting production or drowning engineers in false positives.
Scope - Snipeyes Automated Penetration Testing
- Continuous discovery of tenants’ attack surface + change-triggered test runs
- Safe exploitation validation (tenant-isolated test accounts, read-only proof where possible)
- Evidence collection: request/response, screenshots, logs, CVSS + exploitability note
- Output: validated vulnerabilities & evidence only — unvalidated items stay in triage queue, never in board report
Key Findings (redacted)
- CRITICAL chain: Invitation link enumeration → forced tenant join → IDOR on
/invoices/{uuid}→ cross-tenant PII + salary export (validated with 2 test tenants) - HIGH: Password reset token not bound to user → account takeover within 15-min window
- Scanner had missed both (logic + chaining); 28 validated findings from 400+ raw signals
Outcome
- Tenant isolation rewritten + invitation entropy + reset binding — retest chain fully blocked, evidence archived for auditor
- SOC 2 CC7 evidence accepted, release cadence kept (tests run per deploy, block only on validated critical)
- Manual annual pentest now focuses on deep logic; automation covers regression
Relevance for you: If you ship weekly but test yearly — automate the prove-it loop in between.