Your external perimeter, on the roadmap.
Rift ships today as a web application pentester that reasons from your source code. Agent-driven external network testing, enumerating and pressure-testing your perimeter, is what we build next. Here is the plan and how to get on the early list.
Network penetration testing is not available yet. Rift's shipping product is web application penetration testing. This page describes what we plan to build.
External testing, the way an outsider works
The plan: give Rift a seed domain, let agents map the surface and pressure-test what they find, on repeat.
External perimeter, agent-driven
Planned: enumerate subdomains, exposed services, ports, and TLS posture from a single seed, then test the surface for real, reachable weaknesses.
Attack-path proof
Planned: chain a low-severity exposure into demonstrated impact and hand you the path, not just a port scan with a PDF.
Surface-change awareness
Planned: notice when new assets appear so a re-run picks them up, instead of waiting for the next scheduled review.
Scope you can budget
Planned: countable, per-asset scoping so you can size an engagement without a sales call.
What perimeter testing will cover
The coverage we're working toward for external network testing. None of this ships yet; today Rift tests web applications from source.
- ✓Subdomain & DNS enumeration, including wildcards
- ✓Port and exposed-service discovery
- ✓TLS / certificate posture and expiry
- ✓Default credentials & exposed admin interfaces
- ✓Cloud-edge misconfigurations and forgotten hosts
External first, then internal
The build order
External perimeter testing comes first, then agent-driven internal and lateral-movement testing. Tell us about your attack surface and we'll bring you in as each lands.
Want perimeter testing when it lands?
Tell us about your external surface and we'll bring you in as soon as network testing is ready.