Methodology
Published methods, applied the same way every run.
An autonomous tester has one advantage a human cannot match: it performs the same methodology on the first engagement and the fiftieth.
Which standards does an engagement follow?
The engagement structure follows PTES, the web and API testing follows the OWASP Web Security Testing Guide, the technical process follows NIST SP 800 115, and severity is scored with CVSS v4.0.
- OWASP WSTG
- The web and API test cases, from information gathering through to business logic.
- OWASP Top 10
- Used to organise findings for a reader, not as the test plan.
- PTES
- The engagement structure: pre-engagement, intelligence, threat modelling, analysis, exploitation, reporting.
- NIST SP 800 115
- The technical process for planning, executing and reporting a security assessment.
- CVSS v4.0
- Severity scoring, with the vector recorded so the score can be checked.
Every standard above is published by its own organisation and can be read without going through us. A vendor that describes its methodology only in its own words is asking you to take the coverage on faith.
Read the coverage record.
It tells you which classes actually ran.