View a markdown version of this page

Document history - AWS Security Agent (now part of AWS Continuum)

Document history

The following table describes some of the major updates and new features for the AWS Security Agents User Guide.

ChangeDescriptionDate

Choose a test scope for a penetration test

You can now choose a test scope for a penetration test. Choose Gen AI application to test a generative AI application for large language model (LLM) risks, such as prompt injection, instead of the vulnerability classes of a traditional website. For more information, see Choose a test scope.

October 9, 2026

Configurable pull request code review triggers

You can now limit code reviews by target branch or label, review draft pull requests, and start a review when a label is added in GitHub or GitLab.

October 1, 2026

Tutorials: Gate a CI/CD deployment with a scoped penetration test

Added step-by-step tutorials for running a penetration test as a post-deployment gate in GitHub Actions, GitLab CI/CD, Bitbucket Pipelines, and Azure DevOps Pipelines. Each tutorial deploys an intentionally vulnerable sample application, gates promotion on the finding, and then shows the gate passing after you fix the vulnerability. For more information, see Run penetration tests from your CI/CD pipeline.

September 28, 2026

View email MFA messages for a penetration test credential

You can now view the messages that arrive at a credential’s email MFA address, in the console or with the list-actor-messages API. This means you can use the address directly as the email address for a test user in your application. You can open the verification message yourself, instead of forwarding messages from a mailbox of your own. For more information, see View email MFA messages.

September 25, 2026

Run penetration tests from your CI/CD pipeline

Added documentation for running penetration tests from a CI/CD pipeline. You can add a post-deployment gate for GitHub Actions, GitLab CI/CD, Bitbucket Pipelines, or Azure DevOps Pipelines that tests the deployed change and blocks promotion on findings above a severity threshold. The topic covers how the test is scoped to the deployed change, OpenID Connect (OIDC) authentication, least-privilege IAM trust and permissions policies, dry-run validation, gating and scope conflicts, cleanup, and protecting credentials on the runner. For more information, see Run penetration tests from your CI/CD pipeline.

September 25, 2026

Test penetration test credentials before a run

Added documentation for the updated penetration test setup workflow. You can now test each credential before a run to confirm that AWS Security Agent can sign in. This testing also discovers the domains your application reaches while signed in. Use the new Network configuration step to classify every domain the test may reach.

September 18, 2026

Penetration testing for non-standard ports

AWS Security Agent now tests target endpoints that serve traffic on non-standard ports. Include the port in the target URL, for example https://example.com:8443. Accessible URLs also accept a port.

September 16, 2026

Exposed network ports findings

During a penetration test, AWS Security Agent now reports open network ports on your target hosts as a new informational finding. When a host listens on TCP ports beyond the standard web ports your application uses, AWS Security Agent adds a single Exposed Network Ports finding. The finding lists each port with its detected service and version. AWS Security Agent identifies these ports for your awareness. It does not attempt to exploit the services on them. For more information, see Does AWS Security Agent report open network ports?.

August 31, 2026

Code remediation for Amazon S3 sources

AWS Security Agent now supports code remediation for findings from Amazon S3 sources, for both penetration tests and code reviews, and both automatically and on demand. Because there’s no connected repository to open a pull request against, AWS Security Agent attaches a downloadable code diff to the finding that you can apply locally with git apply.

August 18, 2026

AWS Security Agent now supports 20 target domains per Agent Space

You can now configure up to 20 target domains per Agent Space for penetration testing. This limit was previously 5.

August 18, 2026

Revalidate penetration test findings

Added documentation for revalidating penetration test findings. You can select existing findings and re-test whether they are still exploitable, without running a full penetration test. Revalidation runs as a separate job and reports whether each finding is still active or resolved, without changing the original finding.

August 13, 2026

Maximum task hours for penetration tests and code reviews

Added documentation for setting a maximum task-hours limit when you create a penetration test or code review. When a run reaches the limit, AWS Security Agent stops it gracefully and keeps the findings discovered so far.

August 13, 2026

Pricing and billing

Added documentation for pricing and billing. This topic explains what accrues task hours, the unit AWS Security Agent bills for penetration testing. It covers why task hours differ from the duration of a run and where to find task hours. It also explains why service quotas are not spending limits. For more information, see Pricing and billing.

August 11, 2026

Email MFA for penetration testing credentials

Added documentation for email MFA. You can now enable email-based multi-factor authentication (MFA) for penetration testing credentials. When enabled, AWS Security Agent can complete logins for applications that send a one-time code or verification link by email. AWS Security Agent generates a unique forwarding address that you configure in your email provider.

August 6, 2026

Private connections general availability

Private connections are now generally available. This capability allows AWS Security Agent to connect to source control systems running in private networks using Amazon VPC Lattice, without exposing your systems to the public internet.

July 28, 2026

Private connections (preview)

Added documentation for private connections. This new capability allows AWS Security Agent to connect to source control systems running in private networks using Amazon VPC Lattice, without exposing your systems to the public internet.

June 16, 2026

Threat modeling (preview)

Added documentation for threat modeling. This new capability builds a threat model of your application from design documents (scope docs), source code (sources), or both. Scope docs are feature design documents that define the focus of the analysis, while source code provides context about your existing system. If you don’t provide scope docs, the agent generates a threat model from the source code alone. Each run produces a system overview and a set of threats classified by STRIDE category with severity ratings and recommendations.

June 8, 2026

Full repository code review (preview)

Added documentation for full repository code review. This new capability performs context-aware security analysis of your entire codebase and generates code remediation for findings.

May 12, 2026

Updated Region availability for finding remediation

Region availability for penetration test finding remediation in the AWS Security Agent web application has been updated.

April 16, 2026

Updated Region availability for enabling finding remediation

Region availability for enabling penetration test finding remediation in the AWS Management Console has been updated.

April 16, 2026

Customer managed key support

Added documentation for customer managed key (CMK) support. You can now specify a customer managed KMS key when creating Agent Spaces and integrations to encrypt your data with keys you control.

March 31, 2026

AWS managed policy updates

Added AWSSecurityAgentWebAppPolicy managed policy for the new TargetDomain and DesignReviewFeedback resource types.

March 31, 2026

AWS managed policy updates

Added AWSSecurityAgentWebAppPolicy managed policy for the new AgentSpace resource type and IAM action name changes.

February 9, 2026

AWS managed policy updates

Updated SecurityAgentWebAppAPIPolicy to allow customers to delete design reviews.

January 28, 2026

AWS managed policy updates

Updated SecurityAgentWebAppAPIPolicy to allow customers to start automated code remediation for security findings.

January 20, 2026

AWS managed policy updates

Updated to SecurityAgentWebAppAPIPolicy to allow customers to view images in the console.

December 5, 2025

AWS Security Agents initial release

Initial documentation for service launch

December 2, 2025