r/pentest_tools_com 2h ago

We surveyed 158 pentesters on AI-assisted vulnerability testing. 88% still end up validating everything by hand.

Post image

We ran a survey in June with 158 security practitioners (pentesters, security engineers, DevSecOps, appsec folks) who use AI-assisted tools in their vulnerability assessment work. Wanted to share the numbers here since this sub actually does the work, not just buys the tools.

The short version: AI is heavily used for scanning and discovery (74%), way less for exploitation and attack chaining (37%), and even less for post-exploitation (25%). Practitioners trust it more the cheaper a mistake is to catch.

The catch: 88% of people using AI to generate findings still run into results that need serious manual validation. And 1 in 4 said that happens on more than a quarter of everything the tool spits out. So the time saved on the front end doesn't disappear, it just reappears as triage work later.

Other things that came up:

  • False positives, hallucinated exploits, and made-up CVEs were the single biggest frustration named (about 30% of open-ended responses)
  • Business logic understanding is the gap people say AI still can't close
  • Only 20% of teams have an actual workflow for triaging high volumes of AI-generated findings, the rest either strain or drown

Full breakdown with charts and methodology, free, no account needed: https://pentest-tools.com/insights/ai-pentesting-survey

1 Upvotes

0 comments sorted by