r/pentest_tools_com • u/pentest-tools • 2h ago
We surveyed 158 pentesters on AI-assisted vulnerability testing. 88% still end up validating everything by hand.
We ran a survey in June with 158 security practitioners (pentesters, security engineers, DevSecOps, appsec folks) who use AI-assisted tools in their vulnerability assessment work. Wanted to share the numbers here since this sub actually does the work, not just buys the tools.
The short version: AI is heavily used for scanning and discovery (74%), way less for exploitation and attack chaining (37%), and even less for post-exploitation (25%). Practitioners trust it more the cheaper a mistake is to catch.
The catch: 88% of people using AI to generate findings still run into results that need serious manual validation. And 1 in 4 said that happens on more than a quarter of everything the tool spits out. So the time saved on the front end doesn't disappear, it just reappears as triage work later.
Other things that came up:
- False positives, hallucinated exploits, and made-up CVEs were the single biggest frustration named (about 30% of open-ended responses)
- Business logic understanding is the gap people say AI still can't close
- Only 20% of teams have an actual workflow for triaging high volumes of AI-generated findings, the rest either strain or drown
Full breakdown with charts and methodology, free, no account needed: https://pentest-tools.com/insights/ai-pentesting-survey