Nubesti Security Lab
See a finding โ clearly fictional.
This record is from a controlled lab application. It is not a customer, not a production hostname, and not a disclosed vulnerability in a third party.
- Asset
- api.lab.nubesti.test
- Finding
- Broken object-level authorization
- Severity
- Critical
- MITRE ATT&CK
- T1190 โ Exploit Public-Facing Application
- Evidence
- Request / Response pair from a controlled replay against the lab API
- Exploitability
- Validated in the lab (object ID swapped; another tenant record returned)
- Impact
- Unauthorized read of another accountโs records in the lab dataset
- Remediation
- Enforce object-level authorization on every record access; add regression tests
- Status
- Fixed in lab build 2026.09
- Retest
- Passed
How it works
Authorized scope, then evidence.
A test does not start because a form was filled. It starts when the customer can show they may test the asset.
-
01
Define authorized scope
The customer verifies assets and authorization. KYC must be complete and paid.
-
02
Autonomous reconnaissance
Nubesti maps the authorized attack surface โ not the open internet.
-
03
Attack simulation and validation
Agents test exploitable paths inside that scope and keep evidence.
-
04
Evidence
Each finding should include technical context a reviewer can accept or reject.
-
05
Remediation
Recommendations or draft fixes when available. Drafts are a starting point.
-
06
Retest
The same finding can be tested again after a change.
What the platform is built to do
Autonomous testing
After KYC and authorization, agents can run scheduled assessments on the assets you designate โ without a human clicking through every check.
ATT&CK and OWASP mapping
Workflows mapped to MITRE ATT&CK techniques and OWASP risk classes. Reports should show which mapped checks ran.
False-positive reduction
Findings are validated with exploitability checks and evidence. We do not claim zero false positives.
Repeatable tests on an
authorized scope
Continuous security testing
Agents can replay the same authorized playbooks on a schedule you choose, so findings show up while the change is still in the sprint โ not only at the next quarterly pentest.

ATT&CK and OWASP mapping
Testing workflows can be mapped to MITRE ATT&CK techniques and OWASP risk classes. Mapping is not a claim that every technique in the matrix was executed.

Evidence before a change window
Findings are meant to include technical context a reviewer can accept or reject. Draft fixes, when offered, are a starting point โ not an automatic merge.

AI Red Team Security Plans
Starter
Essential AI-powered vulnerability detection for small teams and applications
- OWASP Top 10 automated vulnerability scanning
- Basic MITRE ATT&CK technique simulation
- Web application security testing
- 5 target applications or endpoints
- Monthly security reports
- Email support (24-48h response)
- OWASP Top 10 Testing
- MITRE ATT&CK TechniquesBasic mapped techniques
- Web Applications
- Basic Security ReportsMonthly
- Email Support24-48h response
Professional
Advanced AI red teaming with comprehensive threat simulation for growing organizations

- Testing workflows mapped to MITRE ATT&CK techniques
- Advanced OWASP testing + custom attack vectors
- Cloud infrastructure security testing
- 20 target applications or endpoints
- API and microservices testing
- Slack/Teams integration
- Weekly reports + live dashboard
- Priority support (4-8h response)
- OWASP Top 10 Testing
- MITRE ATT&CK TechniquesExpanded mapped techniques
- Custom Attack VectorsLimited
- Web Applications
- API & Microservices Testing
- Cloud Infrastructure (AWS/Azure/GCP)Single cloud
- Network InfrastructureLimited
- Basic Security ReportsWeekly
- Slack/Teams Integration
- Exportable dated findingsBasic
- Email Support4-8h response
- Custom Training & WorkshopsQuarterly
Enterprise
Complete AI red team solution with custom attack scenarios for large organizations
- Custom attack scenarios tailored to your infrastructure
- Advanced persistent threat (APT) simulations
- Multi-cloud security testing (AWS, Azure, GCP)
- Unlimited targets and applications
- Exportable dated findings for your audit packs
- Custom integrations (SIEM, ticketing systems)
- Real-time monitoring and alerts
- Dedicated security engineer + 24/7 support
- OWASP Top 10 Testing
- MITRE ATT&CK TechniquesCustom scoped playbooks
- Custom Attack VectorsUnlimited
- Advanced Persistent Threat (APT) Simulation
- Web Applications
- API & Microservices Testing
- Cloud Infrastructure (AWS/Azure/GCP)Multi-cloud
- Network InfrastructureIn-scope custom
- Basic Security ReportsReal-time
- Slack/Teams Integration
- SIEM Integration
- Exportable dated findingsAudit packs
- Email Support24/7 priority
- Dedicated Security Engineer
- Custom Training & WorkshopsMonthly
- On-premise DeploymentAvailable
Trust Center
How Nubesti treats authorization, data, and platform security.
This page is the public index for security, privacy, and responsible offensive-testing controls. It links to binding legal documents. It does not claim certifications Nubesti does not hold.
Questions teams usually ask
Nubesti runs continuous autonomous security tests against assets you authorize. Findings include technical evidence so a reviewer can accept or reject them. Tests do not start until paid KYC is complete.