AI is playing an increasingly important role in pentesting. From reporting to analyzing vulnerabilities, smart models can support pentesters with time-consuming and repetitive tasks. At the same time, this development also brings new risks. Many AI solutions run entirely in the cloud, causing sensitive client information to end up with external providers. For Remco van der Meer, ethical hacker at Warpnet, that was reason to take a different approach. Instead of public AI platforms, he is developing a fully local AI environment where all data remains within their own infrastructure. In this article, he explains what the proper use of AI can mean for the future of pentesting.
A local server is a must
According to Remco, using a local solution is an absolute must. “Many AI solutions within security run entirely in the cloud. We cannot use those for our work domain. During a pentest, you work precisely with sensitive internal information from clients. You don't want that data being sent to an external (foreign) AI provider. That's why I chose a local solution at a data center within the Netherlands.”
The current environment is currently running within a data center in Amsterdam. In the long term, Warpnet will fully transition to its own hardware. Instead of using external AI services, the AI models will then run locally on dedicated servers. The environment is also designed so that different components of the system are isolated from each other and data is stored and transmitted encrypted.
AI as support of the pentester
Besides the importance of a local server, human control remains an important part of the process. AI supports the pentester, but does not completely take over the work. According to Remco, the greatest added value at the moment lies in reporting, analysis, and internal controls. “We currently use AI mainly as support for the pentester, not as a replacement. You can think of it a bit like an extra junior colleague alongside the experienced pentester. It helps, for example, with reports, risk analyses, or structuring information, but ultimately human validation is still necessary.”
During pentests, consultants work with fixed templates and extensive notes. That information can then be loaded into the AI system, after which draft texts and risk analyses are automatically generated. According to Remco, the quality of the input is crucial in this regard. “It really stands or falls with the quality of your notes during a pentest. We already work with fixed templates and structured documentation. As a result, you can use that information effectively within AI. Based on that, the system can, for example, generate draft texts or risk assessments that the pentester then continues to work on.”
In addition to reporting, Warpnet is also investigating how AI can be combined with automated scanners that check systems for vulnerabilities. Such scanners often generate large amounts of technical information that must be assessed manually. AI can help determine more quickly which findings are truly relevant. “We find the combination of automated scanners with AI to be an interesting area. Traditional scanners often provide a lot of output without context. AI can help to better understand what is relevant within the scope of a specific environment. This allows you to prioritize faster and review more efficiently.”
Still under full development
Warpnet is already conducting the AI pentest in practice, while the optimization of the test to achieve even better results is well underway. “Parts of the solution that emerged from the initial practical test are now being deployed in recent pentests. At the same time, the project is still developing rapidly. It actually started as an experiment last year and has since been expanded further."
According to Remco, the future of AI within penetration testing currently lies primarily in support and efficiency. Repetitive tasks, reporting, and internal controls lend themselves well to automation, while interpretation and decision-making remain with the pentester. Especially within security environments, AI is therefore not just about speed, but above all about control. That is why one principle is central to the development of the platform: security first.
Curious about what an AI pentest can yield for your organization? Get in touch!