Case Study - Automated Penetration Testing (Prove It, Don’t List It)

Scanner: 0 critical. Our automated chain: tenant A admin → tenant B invoices. With screenshots.

ILLUSTRATION — FULL-CYCLE LOOP
🛰️
DISCOVER
🔍
SCAN
💥
EXPLOIT
📸
EVIDENCE

Safe-by-default: scoped, rate-limited, staging-first, kill-switch, full audit log

Client Context

B2B SaaS — multi-tenant HR/payroll, 800 corporate tenants, weekly deploys, SOC 2 Type II audit in 8 weeks. Annual manual pentest left 11 months uncovered.

Challenge

Need penetration-grade proof between annual tests: combine discovery, scanning, exploitation validation, and evidence collection automatically — without disrupting production or drowning engineers in false positives.

Scope - Snipeyes Automated Penetration Testing

  • Continuous discovery of tenants’ attack surface + change-triggered test runs
  • Safe exploitation validation (tenant-isolated test accounts, read-only proof where possible)
  • Evidence collection: request/response, screenshots, logs, CVSS + exploitability note
  • Output: validated vulnerabilities & evidence only — unvalidated items stay in triage queue, never in board report

Key Findings (redacted)

  • CRITICAL chain: Invitation link enumeration → forced tenant join → IDOR on /invoices/{uuid} → cross-tenant PII + salary export (validated with 2 test tenants)
  • HIGH: Password reset token not bound to user → account takeover within 15-min window
  • Scanner had missed both (logic + chaining); 28 validated findings from 400+ raw signals

Outcome

  • Tenant isolation rewritten + invitation entropy + reset binding — retest chain fully blocked, evidence archived for auditor
  • SOC 2 CC7 evidence accepted, release cadence kept (tests run per deploy, block only on validated critical)
  • Manual annual pentest now focuses on deep logic; automation covers regression

Relevance for you: If you ship weekly but test yearly — automate the prove-it loop in between.