Two-stage firewall pentest · powered by KrakenPentest

Don't just guess your firewall's vulnerable.
Prove it.

Most scanners stop at version matching: "you're probably vulnerable to CVE-X." We go one step further. Stage 1 fingerprints your firewall and screens for known-vulnerable versions. Stage 2 sends a behavioral probe to each candidate CVE — proof that the device responds as a vulnerable one would. You get confirmed exploitable versus version match only, with the proof line for every confirmed finding.

~60 seconds · no install · no agent
Behavioral oracle proof CISA KEV cross-checked Authorized & consent-gated
We fingerprint and test against known CVEs for
Fortinet / FortiGatePalo AltoCisco ASA / FirepowerSonicWallWatchGuardSophosCheck PointJuniperpfSense / OPNsenseMeraki
Step 1 of 3 · Your firewall33%

Which firewall protects your network?

We fingerprint it live too — but telling us focuses the test on the CVEs that actually affect your platform.

TARGET
Probing perimeter · 0%
kraken-pentest ·
Pentest complete · your perimeter
LEVEL

Analyzing your perimeter…

This is your live surface-exposure rating; the deep pentest now running will exploit-validate every finding.

What we found on your perimeter
Your full deep-pentest report

This was one snapshot. Attackers don't stop.

ThreatMate runs this pentest continuously across every domain and firewall you manage — proving what's exploitable week after week, not once a year.

See continuous pentesting →
Analysis 72% complete

Where should we send your report?

We're finalizing the deep pentest for your perimeter. Drop your details and the full findings land in your inbox the moment they're ready.

🔒 Used only to deliver your report. No spam · unsubscribe anytime.