VI · EN
Get a consultation098.169.1103
Back to Products
// IN-HOUSE PROJECT · TECHSHIELD LABS

RiskForge — automated pentest, real risk.

BETA · AUTOMATED PENTEST PLATFORM

RiskForge is an automated penetration testing platform researched and built by the TechShield team, giving organisations a continuous view of their attack surface and a clear answer to which vulnerabilities are genuinely exploitable.

Instead of handing over another list of alerts, RiskForge maps your assets, simulates exploitation within an authorised scope, chains findings into paths toward critical assets and produces reports backed by evidence and per-issue remediation guidance.

05
Automated stages
09
Capability modules
10+
OWASP risk categories
VI/EN
Report languages
— 01 / PROJECT OVERVIEW

Why we built
RiskForge

Manual pentesting goes deep but takes time and only captures a single moment. Systems change every week.

Most organisations run a penetration test once or twice a year, usually to satisfy an audit or a compliance requirement. Between those tests the infrastructure keeps moving: new services go live, new subdomains appear, new libraries land in the build — and the attack surface grows without anyone watching it.

Traditional vulnerability scanners have the opposite problem: they generate far more alerts than anyone can validate. Operations teams spend weeks filtering false positives while the genuinely exploitable risk sits somewhere in a list thousands of rows long.

RiskForge exists to close that gap. It automates the repeatable part of a penetration test — reconnaissance, testing, validation, scoring, reporting — so security specialists can spend their time where human judgement is required, and the business gets a continuously refreshed picture of its risk instead of an annual snapshot.

Project facts
Product name
RiskForge
Built by
TechShield — in-house team
Product type
Automated penetration testing platform
Status
Beta — early access open
Deployment model
SaaS on TechShield infrastructure; on-premise deployment available on request
Platform address
pentest.techshield.vn
Target scope
Web applications, APIs, network infrastructure and public-facing assets
Interface & report languages
Vietnamese and English
What makes it different
01

Validate first, alert second

Every finding is exploited within a controlled scope. If it cannot be exploited, it does not get reported as high risk.

02

Thinking in attack chains

Findings are not listed in isolation — they are chained into a route from entry point to critical asset.

03

Continuous, not periodic

Scheduled and event-driven scans surface new risk the moment the system changes.

04

Specialists behind the output

During beta, every result is reviewed by TechShield's pentest team before it reaches the customer.

— 02 / HOW IT WORKS

A full pentest cycle,
run end to end

Five consecutive stages that can run on a schedule or be triggered manually per project.

STEP / 01

Scope definition

You declare domains, IP ranges and API endpoints, and confirm authorisation to test. The scope is locked — RiskForge never touches an asset outside the list.

STEP / 02

Automated recon

Subdomains, open services, technologies, certificates and internet-exposed assets are enumerated to build a real map of the attack surface.

STEP / 03

Controlled exploitation

Safe exploitation playbooks confirm which vulnerabilities are real, remove false positives and capture proof of concept.

STEP / 04

Attack path & scoring

Validated findings are chained into attack paths, matched against CVE data and scored with CVSS to rank what to fix first.

STEP / 05

Reporting & retest

Technical and executive reports are generated with remediation guidance, followed by a retest to confirm the fixes hold.

Testing safety rules
  • Testing only ever runs against a scope the customer has declared and authorised in writing.
  • Disruptive techniques (DoS, large-scale brute force) are excluded from production runs.
  • Scan rate and testing windows are agreed with the operations team in advance.
  • Every testing action is logged so it can be reconciled later.
— 03 / CAPABILITIES

What RiskForge
does today

Nine capability groups running in the current beta.

RF.01

Attack surface management

Discovers subdomains, ports, services, technologies and shadow IT exposed to the internet, and tracks how they change over time.

RF.02

Web application testing

Covers the OWASP Top 10 risk categories: injection, broken authentication and access control, misconfiguration, SSRF, stored and reflected XSS.

RF.03

API testing

Tests REST and GraphQL against the OWASP API Security Top 10: BOLA, function-level authorisation, excessive data exposure, missing rate limits.

RF.04

Infrastructure & network testing

Reviews exposed services, software versions, TLS/SSL configuration, expiring certificates and internet-facing admin interfaces.

RF.05

CVE matching & CVSS scoring

Matches detected technologies against CVE databases, calculates CVSS v3.1 scores and assigns a severity rating.

RF.06

Attack path analysis

Builds a graph from entry point to critical asset and highlights the link to break first in order to cut the whole chain.

RF.07

Scheduled & event-driven scans

Run daily, weekly or monthly, or trigger after every release so new risk is caught as soon as the system changes.

RF.08

Risk operations centre

A dashboard covering findings by severity, detection trends over time, MTTR and the remediation status of every issue.

RF.09

Report export & handover

Exports OWASP/PTES-structured reports with proof of concept, evidence screenshots and remediation steps per finding.

— 04 / STANDARDS & METHODOLOGY

Aligned with
international standards

RiskForge's testing playbooks and report structure are built on widely adopted security frameworks.

STD
OWASP

OWASP Top 10

The ten most common web application risk categories, used as the classification frame for findings.

STD
API

OWASP API Security Top 10

The API-specific risk framework behind our REST and GraphQL testing playbooks.

STD
PTES

PTES

The Penetration Testing Execution Standard, shaping the seven-stage process and report structure.

STD
NIST

NIST SP 800-115

NIST's technical guide to information security testing and assessment.

STD
MITRE

MITRE ATT&CK

The adversary tactics and techniques knowledge base, used to label each step in an attack path.

STD
CVSS

CVE & CVSS v3.1

Published vulnerability identifiers and the standard scoring scale for ranking severity.

RiskForge is a technical aid, not a replacement for expert judgement, and it does not issue compliance certification on its own. Its output can be used as technical evidence within ISO 27001, PCI DSS or internal audit documentation.

— 05 / WHO IT IS FOR

Who RiskForge suits
and when to use it

From in-house security teams to organisations with no dedicated security staff at all.

A good fit for

In-house security teams

Teams that need continuous attack surface coverage without the headcount to run manual pentests every month.

DevOps & engineering teams

Teams that want vulnerabilities surfaced right after each release, before an attacker finds them.

Organisations without security staff

Businesses that need a readable risk picture with a clear fix order and concrete remediation guidance.

Teams preparing for an audit

Organisations that need structured technical evidence for ISO 27001, PCI DSS or internal audit.

Typical use cases
UC.01

Pre go-live testing

Run the full cycle against staging before release day so vulnerabilities are stopped at the source.

UC.02

Continuous public asset monitoring

Schedule weekly scans across every public domain and IP, with alerts when new risk appears.

UC.03

Post-incident review

Re-assess the entire attack surface after an incident to confirm no similar entry point remains.

UC.04

Inherited system assessment

Quickly assess the risk level of a system taken over from another provider or acquired in a merger.

UC.05

Post-fix verification

Re-run testing against the same scope to prove a vulnerability has genuinely been closed.

UC.06

Compliance evidence

Generate periodic technical reports as evidence for your vulnerability management process.

— 06 / DELIVERABLES

What you
receive

Every testing cycle ends with a document set you can drop straight into a remediation plan.

Report structure
  1. 01Executive summary and risk heat map
  2. 02Scope, timeline and testing methodology
  3. 03Findings ranked by severity
  4. 04Technical detail and proof of concept per finding
  5. 05Attack path analysis and affected critical assets
  6. 06Remediation recommendations and a proposed fix roadmap
Handover package
DEL.01

Executive report

A leadership summary: overall risk level, the most severe findings and prioritised recommendations.

DEL.02

Technical report

Every finding in detail: description, severity, CVSS score, affected assets and reproduction steps.

DEL.03

Exploitation evidence (PoC)

Requests, responses, screenshots and logs proving the vulnerability is genuinely exploitable.

DEL.04

Remediation plan

Fix guidance per vulnerability, with a suggested order and an estimated level of effort.

DEL.05

Attack path diagram

A visual route showing how an attacker moves from entry point to critical asset.

DEL.06

Retest report

Results of the post-remediation run, confirming which issues are closed and which remain.

— 07 / STATUS & ROADMAP

Where RiskForge
stands today

The platform is in beta and is developed continuously alongside feedback from early-access customers.

SHIPPED

Recon & scanning core

Asset discovery, service scanning, technology fingerprinting and CVE matching are stable in production.

SHIPPED

Controlled exploitation

Validation playbooks across the OWASP Top 10, together with proof-of-concept capture.

IN PROGRESS

Attack path & advanced reporting

Completing the attack path graph, MITRE ATT&CK labelling and customer-branded report templates.

PLANNED

CI/CD integration & public API

Pipeline-triggered testing, alert webhooks and an API to sync findings into your ticketing system.

BETA

Join the beta programme

The beta programme is open to a limited number of organisations. Participants configure their scope together with TechShield's pentest team, receive expert-reviewed reports and feed directly into the product roadmap.

Request early access
— 08 / FAQ

Questions we
hear most often

If your question is not answered here, talk to the TechShield team directly.

FAQ.01

Does RiskForge replace manual penetration testing?

No. RiskForge automates the repeatable, time-consuming part of a pentest so it can run far more often, while the scenarios that require human reasoning — business logic flaws, process abuse, social engineering — still need a specialist. The most effective setup combines both: RiskForge running continuously, deep manual pentests on a periodic basis.

FAQ.02

Will testing disrupt our production systems?

Disruptive techniques such as DoS or large-scale brute force are excluded from production runs. Scan rate and testing windows are agreed with your operations team beforehand, and every action is logged so it can be reconciled.

FAQ.03

What do we need to prepare before starting?

An in-scope asset list (domains, IP ranges, API endpoints), written testing authorisation, a technical point of contact on your side and the permitted testing windows. For authenticated applications, add test accounts covering each user role.

FAQ.04

How is our data and testing output protected?

Results are stored on infrastructure operated by TechShield, scoped per project and shared only with the contacts you nominate. Organisations with stricter data requirements can discuss an on-premise deployment.

FAQ.05

How long does one testing cycle take?

It depends on scope size. A single web application typically completes within a few hours to a day; infrastructure spanning multiple IP ranges and hundreds of assets takes longer. The exact schedule is agreed during scope definition.

FAQ.06

How is it priced?

RiskForge is in beta, so pricing is built around each organisation's scope size and testing frequency. Contact TechShield for a consultation and a quote that fits your setup.

Want to see RiskForge
run against your systems?

Book a demo with TechShield's pentest team — we will configure a trial scope and walk you through every finding.

Accent color

Density