RiskForge — automated pentest, real risk.
RiskForge is an automated penetration testing platform researched and built by the TechShield team, giving organisations a continuous view of their attack surface and a clear answer to which vulnerabilities are genuinely exploitable.
Instead of handing over another list of alerts, RiskForge maps your assets, simulates exploitation within an authorised scope, chains findings into paths toward critical assets and produces reports backed by evidence and per-issue remediation guidance.
Why we built
RiskForge
Manual pentesting goes deep but takes time and only captures a single moment. Systems change every week.
Most organisations run a penetration test once or twice a year, usually to satisfy an audit or a compliance requirement. Between those tests the infrastructure keeps moving: new services go live, new subdomains appear, new libraries land in the build — and the attack surface grows without anyone watching it.
Traditional vulnerability scanners have the opposite problem: they generate far more alerts than anyone can validate. Operations teams spend weeks filtering false positives while the genuinely exploitable risk sits somewhere in a list thousands of rows long.
RiskForge exists to close that gap. It automates the repeatable part of a penetration test — reconnaissance, testing, validation, scoring, reporting — so security specialists can spend their time where human judgement is required, and the business gets a continuously refreshed picture of its risk instead of an annual snapshot.
- Product name
- RiskForge
- Built by
- TechShield — in-house team
- Product type
- Automated penetration testing platform
- Status
- Beta — early access open
- Deployment model
- SaaS on TechShield infrastructure; on-premise deployment available on request
- Platform address
- pentest.techshield.vn
- Target scope
- Web applications, APIs, network infrastructure and public-facing assets
- Interface & report languages
- Vietnamese and English
Validate first, alert second
Every finding is exploited within a controlled scope. If it cannot be exploited, it does not get reported as high risk.
Thinking in attack chains
Findings are not listed in isolation — they are chained into a route from entry point to critical asset.
Continuous, not periodic
Scheduled and event-driven scans surface new risk the moment the system changes.
Specialists behind the output
During beta, every result is reviewed by TechShield's pentest team before it reaches the customer.
A full pentest cycle,
run end to end
Five consecutive stages that can run on a schedule or be triggered manually per project.
Scope definition
You declare domains, IP ranges and API endpoints, and confirm authorisation to test. The scope is locked — RiskForge never touches an asset outside the list.
Automated recon
Subdomains, open services, technologies, certificates and internet-exposed assets are enumerated to build a real map of the attack surface.
Controlled exploitation
Safe exploitation playbooks confirm which vulnerabilities are real, remove false positives and capture proof of concept.
Attack path & scoring
Validated findings are chained into attack paths, matched against CVE data and scored with CVSS to rank what to fix first.
Reporting & retest
Technical and executive reports are generated with remediation guidance, followed by a retest to confirm the fixes hold.
- —Testing only ever runs against a scope the customer has declared and authorised in writing.
- —Disruptive techniques (DoS, large-scale brute force) are excluded from production runs.
- —Scan rate and testing windows are agreed with the operations team in advance.
- —Every testing action is logged so it can be reconciled later.
What RiskForge
does today
Nine capability groups running in the current beta.
Attack surface management
Discovers subdomains, ports, services, technologies and shadow IT exposed to the internet, and tracks how they change over time.
Web application testing
Covers the OWASP Top 10 risk categories: injection, broken authentication and access control, misconfiguration, SSRF, stored and reflected XSS.
API testing
Tests REST and GraphQL against the OWASP API Security Top 10: BOLA, function-level authorisation, excessive data exposure, missing rate limits.
Infrastructure & network testing
Reviews exposed services, software versions, TLS/SSL configuration, expiring certificates and internet-facing admin interfaces.
CVE matching & CVSS scoring
Matches detected technologies against CVE databases, calculates CVSS v3.1 scores and assigns a severity rating.
Attack path analysis
Builds a graph from entry point to critical asset and highlights the link to break first in order to cut the whole chain.
Scheduled & event-driven scans
Run daily, weekly or monthly, or trigger after every release so new risk is caught as soon as the system changes.
Risk operations centre
A dashboard covering findings by severity, detection trends over time, MTTR and the remediation status of every issue.
Report export & handover
Exports OWASP/PTES-structured reports with proof of concept, evidence screenshots and remediation steps per finding.
Aligned with
international standards
RiskForge's testing playbooks and report structure are built on widely adopted security frameworks.
OWASP Top 10
The ten most common web application risk categories, used as the classification frame for findings.
OWASP API Security Top 10
The API-specific risk framework behind our REST and GraphQL testing playbooks.
PTES
The Penetration Testing Execution Standard, shaping the seven-stage process and report structure.
NIST SP 800-115
NIST's technical guide to information security testing and assessment.
MITRE ATT&CK
The adversary tactics and techniques knowledge base, used to label each step in an attack path.
CVE & CVSS v3.1
Published vulnerability identifiers and the standard scoring scale for ranking severity.
RiskForge is a technical aid, not a replacement for expert judgement, and it does not issue compliance certification on its own. Its output can be used as technical evidence within ISO 27001, PCI DSS or internal audit documentation.
Who RiskForge suits
and when to use it
From in-house security teams to organisations with no dedicated security staff at all.
In-house security teams
Teams that need continuous attack surface coverage without the headcount to run manual pentests every month.
DevOps & engineering teams
Teams that want vulnerabilities surfaced right after each release, before an attacker finds them.
Organisations without security staff
Businesses that need a readable risk picture with a clear fix order and concrete remediation guidance.
Teams preparing for an audit
Organisations that need structured technical evidence for ISO 27001, PCI DSS or internal audit.
What you
receive
Every testing cycle ends with a document set you can drop straight into a remediation plan.
- 01Executive summary and risk heat map
- 02Scope, timeline and testing methodology
- 03Findings ranked by severity
- 04Technical detail and proof of concept per finding
- 05Attack path analysis and affected critical assets
- 06Remediation recommendations and a proposed fix roadmap
Executive report
A leadership summary: overall risk level, the most severe findings and prioritised recommendations.
Technical report
Every finding in detail: description, severity, CVSS score, affected assets and reproduction steps.
Exploitation evidence (PoC)
Requests, responses, screenshots and logs proving the vulnerability is genuinely exploitable.
Remediation plan
Fix guidance per vulnerability, with a suggested order and an estimated level of effort.
Attack path diagram
A visual route showing how an attacker moves from entry point to critical asset.
Retest report
Results of the post-remediation run, confirming which issues are closed and which remain.
Where RiskForge
stands today
The platform is in beta and is developed continuously alongside feedback from early-access customers.
Recon & scanning core
Asset discovery, service scanning, technology fingerprinting and CVE matching are stable in production.
Controlled exploitation
Validation playbooks across the OWASP Top 10, together with proof-of-concept capture.
Attack path & advanced reporting
Completing the attack path graph, MITRE ATT&CK labelling and customer-branded report templates.
CI/CD integration & public API
Pipeline-triggered testing, alert webhooks and an API to sync findings into your ticketing system.
Join the beta programme
The beta programme is open to a limited number of organisations. Participants configure their scope together with TechShield's pentest team, receive expert-reviewed reports and feed directly into the product roadmap.
Request early accessQuestions we
hear most often
If your question is not answered here, talk to the TechShield team directly.
Does RiskForge replace manual penetration testing?
No. RiskForge automates the repeatable, time-consuming part of a pentest so it can run far more often, while the scenarios that require human reasoning — business logic flaws, process abuse, social engineering — still need a specialist. The most effective setup combines both: RiskForge running continuously, deep manual pentests on a periodic basis.
Will testing disrupt our production systems?
Disruptive techniques such as DoS or large-scale brute force are excluded from production runs. Scan rate and testing windows are agreed with your operations team beforehand, and every action is logged so it can be reconciled.
What do we need to prepare before starting?
An in-scope asset list (domains, IP ranges, API endpoints), written testing authorisation, a technical point of contact on your side and the permitted testing windows. For authenticated applications, add test accounts covering each user role.
How is our data and testing output protected?
Results are stored on infrastructure operated by TechShield, scoped per project and shared only with the contacts you nominate. Organisations with stricter data requirements can discuss an on-premise deployment.
How long does one testing cycle take?
It depends on scope size. A single web application typically completes within a few hours to a day; infrastructure spanning multiple IP ranges and hundreds of assets takes longer. The exact schedule is agreed during scope definition.
How is it priced?
RiskForge is in beta, so pricing is built around each organisation's scope size and testing frequency. Contact TechShield for a consultation and a quote that fits your setup.