Document history
The following table describes some of the major updates and new features for the AWS Security Agents User Guide.
| Change | Description | Date |
|---|---|---|
You can now choose a test scope for a penetration test. Choose Gen AI application to test a generative AI application for large language model (LLM) risks, such as prompt injection, instead of the vulnerability classes of a traditional website. For more information, see Choose a test scope. | October 9, 2026 | |
You can now limit code reviews by target branch or label, review draft pull requests, and start a review when a label is added in GitHub or GitLab. | October 1, 2026 | |
Tutorials: Gate a CI/CD deployment with a scoped penetration test | Added step-by-step tutorials for running a penetration test as a post-deployment gate in GitHub Actions, GitLab CI/CD, Bitbucket Pipelines, and Azure DevOps Pipelines. Each tutorial deploys an intentionally vulnerable sample application, gates promotion on the finding, and then shows the gate passing after you fix the vulnerability. For more information, see Run penetration tests from your CI/CD pipeline. | September 28, 2026 |
You can now view the messages that arrive at a credential’s email MFA address, in the console or with the | September 25, 2026 | |
Added documentation for running penetration tests from a CI/CD pipeline. You can add a post-deployment gate for GitHub Actions, GitLab CI/CD, Bitbucket Pipelines, or Azure DevOps Pipelines that tests the deployed change and blocks promotion on findings above a severity threshold. The topic covers how the test is scoped to the deployed change, OpenID Connect (OIDC) authentication, least-privilege IAM trust and permissions policies, dry-run validation, gating and scope conflicts, cleanup, and protecting credentials on the runner. For more information, see Run penetration tests from your CI/CD pipeline. | September 25, 2026 | |
Added documentation for the updated penetration test setup workflow. You can now test each credential before a run to confirm that AWS Security Agent can sign in. This testing also discovers the domains your application reaches while signed in. Use the new Network configuration step to classify every domain the test may reach. | September 18, 2026 | |
AWS Security Agent now tests target endpoints that serve traffic on non-standard ports. Include the port in the target URL, for example | September 16, 2026 | |
During a penetration test, AWS Security Agent now reports open network ports on your target hosts as a new informational finding. When a host listens on TCP ports beyond the standard web ports your application uses, AWS Security Agent adds a single Exposed Network Ports finding. The finding lists each port with its detected service and version. AWS Security Agent identifies these ports for your awareness. It does not attempt to exploit the services on them. For more information, see Does AWS Security Agent report open network ports?. | August 31, 2026 | |
AWS Security Agent now supports code remediation for findings from Amazon S3 sources, for both penetration tests and code reviews, and both automatically and on demand. Because there’s no connected repository to open a pull request against, AWS Security Agent attaches a downloadable code diff to the finding that you can apply locally with | August 18, 2026 | |
AWS Security Agent now supports 20 target domains per Agent Space | You can now configure up to 20 target domains per Agent Space for penetration testing. This limit was previously 5. | August 18, 2026 |
Added documentation for revalidating penetration test findings. You can select existing findings and re-test whether they are still exploitable, without running a full penetration test. Revalidation runs as a separate job and reports whether each finding is still active or resolved, without changing the original finding. | August 13, 2026 | |
Added documentation for setting a maximum task-hours limit when you create a penetration test or code review. When a run reaches the limit, AWS Security Agent stops it gracefully and keeps the findings discovered so far. | August 13, 2026 | |
Added documentation for pricing and billing. This topic explains what accrues task hours, the unit AWS Security Agent bills for penetration testing. It covers why task hours differ from the duration of a run and where to find task hours. It also explains why service quotas are not spending limits. For more information, see Pricing and billing. | August 11, 2026 | |
Added documentation for email MFA. You can now enable email-based multi-factor authentication (MFA) for penetration testing credentials. When enabled, AWS Security Agent can complete logins for applications that send a one-time code or verification link by email. AWS Security Agent generates a unique forwarding address that you configure in your email provider. | August 6, 2026 | |
Private connections are now generally available. This capability allows AWS Security Agent to connect to source control systems running in private networks using Amazon VPC Lattice, without exposing your systems to the public internet. | July 28, 2026 | |
Added documentation for private connections. This new capability allows AWS Security Agent to connect to source control systems running in private networks using Amazon VPC Lattice, without exposing your systems to the public internet. | June 16, 2026 | |
Added documentation for threat modeling. This new capability builds a threat model of your application from design documents (scope docs), source code (sources), or both. Scope docs are feature design documents that define the focus of the analysis, while source code provides context about your existing system. If you don’t provide scope docs, the agent generates a threat model from the source code alone. Each run produces a system overview and a set of threats classified by STRIDE category with severity ratings and recommendations. | June 8, 2026 | |
Added documentation for full repository code review. This new capability performs context-aware security analysis of your entire codebase and generates code remediation for findings. | May 12, 2026 | |
Region availability for penetration test finding remediation in the AWS Security Agent web application has been updated. | April 16, 2026 | |
Updated Region availability for enabling finding remediation | Region availability for enabling penetration test finding remediation in the AWS Management Console has been updated. | April 16, 2026 |
Added documentation for customer managed key (CMK) support. You can now specify a customer managed KMS key when creating Agent Spaces and integrations to encrypt your data with keys you control. | March 31, 2026 | |
Added AWSSecurityAgentWebAppPolicy managed policy for the new TargetDomain and DesignReviewFeedback resource types. | March 31, 2026 | |
Added AWSSecurityAgentWebAppPolicy managed policy for the new AgentSpace resource type and IAM action name changes. | February 9, 2026 | |
Updated SecurityAgentWebAppAPIPolicy to allow customers to delete design reviews. | January 28, 2026 | |
Updated SecurityAgentWebAppAPIPolicy to allow customers to start automated code remediation for security findings. | January 20, 2026 | |
Updated to SecurityAgentWebAppAPIPolicy to allow customers to view images in the console. | December 5, 2025 | |
AWS Security Agents initial release | Initial documentation for service launch | December 2, 2025 |