Brand logo of nubesti
  • Home
  • AI Red Team
    • Autonomous Agents

      After KYC and authorization, agents can run scheduled assessments on assets you designate.

    • MITRE ATT&CK mapping

      Testing workflows mapped to MITRE ATT&CK techniques. Mapping is not a claim that every technique ran.

    • OWASP mapping

      Checks mapped to OWASP risk classes, with evidence a reviewer can accept or reject.

    • Integration

      Connect seamlessly with your existing tools and workflows.

    Experience AI Red Team Testing

    See how our autonomous AI agents identify vulnerabilities in your systems.

    Book a Demo
  • Resources
    • Trust Center
    • Methodology
    • Pricing
    • FAQ
    • Blog
  • Contact
    • french
    • spanish
    • portuguese
  • Sign in
  • french
  • spanish
  • portuguese
Sign in
  1. Home
  2. /
  3. Methodology

Methodology

How autonomous testing is supposed to work.

This describes the intended testing loop. It is not a benchmark and it does not claim complete ATT&CK coverage or a published accuracy rate.

Nubesti LLC Β· Delaware, United States
  1. 01

    Define authorized scope

    The customer verifies assets and authorization. KYC must be complete and paid.

  2. 02

    Autonomous reconnaissance

    Nubesti maps the authorized attack surface β€” not the open internet.

  3. 03

    Attack simulation and validation

    Agents test exploitable paths inside that scope and keep evidence.

  4. 04

    Evidence

    Each finding should include technical context a reviewer can accept or reject.

  5. 05

    Remediation

    Recommendations or draft fixes when available. Drafts are a starting point.

  6. 06

    Retest

    The same finding can be tested again after a change.

Autonomous testing

After a customer verifies assets and authorization, Nubesti can run repeatable test playbooks against that scope without waiting for a quarterly manual pentest. Humans still define scope, pay for KYC, can halt jobs, and decide what to patch.

The loop

  1. Authorized scope β€” only listed assets
  2. Reconnaissance β€” map the authorized attack surface
  3. Testing and validation β€” probe exploitable paths; prefer evidence over scanner noise
  4. Evidence β€” findings should include technical context a reviewer can replay or reject
  5. Remediation β€” recommendations or draft fixes when the product can produce them; drafts are a starting point, not a guarantee
  6. Retest β€” the same finding can be tested again after a change

Mapping, not β€œfull coverage”

Workflows can be mapped to MITRE ATT&CK techniques and to OWASP risk classes. Mapping is not the same as exercising every technique in the matrix. Reports should show which mapped techniques ran and which did not.

Severity

Severity is contextual. Where a Risk Index or CVSS-like score appears in the product, treat it as decision support for a change window β€” not as a legal rating or a promise of completeness.

False positives

We aim to reduce noise with exploitability checks and evidence. We do not claim zero false positives or a public 99% accuracy figure.

Brand logo of nubesti

Nubesti LLC provides continuous autonomous security testing against customer-authorized assets. Tests require paid KYC.

  • linkedin

Product

  • Platform
  • Methodology
  • Pricing
  • Demo

Trust

  • Trust Center
  • Platform security
  • Customers
  • Vulnerability disclosure

Legal

  • Legal center
  • Privacy
  • DPA
  • Subprocessors
  • Legal notice
  • About
  • Legal
  • Privacy Policy
  • Legal Notice
  • Β© 2026 Nubesti LLC
  • All rights reserved