Applications and targets
A pentest application is your declaration that you may authorize active testing. Under it you define targets: the host and endpoints to test. Optionally attach API documentation, credentials, and source repositories.Domain verification is mandatory
A target cannot run until you prove you control the domain. Amnify gives your organization a unique value. Publish it as a DNS TXT record on the name it shows, or as plain text at the well known URL it shows, then check.Choosing the run
Two independent choices.Quick
The highest impact, most commonly exploited ways in: broken authentication and access control, injection, remote code execution, server side request forgery, exposed secrets. Light traffic, low cost. It will not chain small issues into one attack path.
Deep
Audit ready. Everything in Quick plus the full exposed surface, per role access control, business logic and race conditions, file upload abuse, prompt injection, and chained attack paths. Every severity, at higher traffic and cost.
How a run works
A run moves through four phases: surface mapping, discovery, validation, and, in a white box run, a fix that is re-tested. Only validated results become findings: a working, minimal, non destructive proof of concept, or for a known vulnerable dependency, its version independently confirmed as present. In a white box run, Amnify also patches the cause and re-runs the proof to show it is gone.Scheduling
Daily, weekly or monthly, per combination of engagement and package. A target can hold up to six schedules, one per combination, each pausable.Penetration tests and scans never overlap on the same scope. Different scopes can run at the same time.