Updates to BreachLock AEV v1.10.0 Accelerate Continuous Exposure Validation in One Platform

Summary

  • BreachLock Adversarial Exposure Validation (AEV) v1.10.0 introduces a new Asset Management experience, providing a centralized home for internal and external assets, tagging, bulk uploads, and credential storage.
  • Organizations can now validate network controls with the new Network Segmentation Engagement, designed to uncover unauthorized network paths and firewall misconfigurations.
  • Automated campaigns now support recurring schedules, license-aware execution, and improved safeguards against duplicate engagements.
  • A refreshed UI modernizes engagement creation, license management, and administrative workflows.
  • Additional platform enhancements improve scanning efficiency, authentication workflows, engagement lifecycle management, and reporting consistency.

How BreachLock AEV Equips Security Teams with Continuous Exposure Validation

As organizations scale offensive security efforts, maintaining visibility into assets, managing testing operations efficiently, and validating network security controls become increasingly important.

BreachLock AEV v1.10.0 delivered through the BreachLock Unified Platform addresses these challenges with several significant enhancements across asset management, automated testing operations, and network security validation. This release introduces a dedicated Asset Management experience, a new Network Segmentation engagement type, expanded campaign scheduling capabilities, and multiple platform improvements designed to streamline offensive security workflows.

Together, these updates help organizations operate more efficiently while gaining deeper visibility into their environment and potential attack paths.

Request a BreachLock demo.

Improved Asset Management Experience

One of the most significant additions in BreachLock AEV v1.10.0 is the introduction of a dedicated Asset Management experience.

For offensive security programs to be effective, organizations need a clear understanding of what assets they own, where those assets reside, and how they should be tested. As environments grow, managing web applications, domains, subdomains, IP addresses, and testing credentials across multiple workflows can become increasingly difficult.

The new Asset Management experience creates a centralized location where security teams can organize and manage assets more efficiently.

A Dedicated Home for Internal and External Assets

BreachLock AEV now includes a dedicated Assets tab with a clear separation between internal and external assets. This structure helps teams quickly understand their exposure landscape while simplifying asset administration and engagement preparation.

Users can also add internal and external web applications directly from their respective asset views, creating a more streamlined workflow when onboarding new testing targets.

Picture1_Internal Web Assets_BreachLock Unified Platform
Picture1_Internal Web Assets_BreachLock Unified Platform

The BreachLock Unified Platform provides a centralized view of discovered internal web assets, enabling security teams to inventory, classify, and manage application exposure across the attack surface from a single dashboard.

Picture2_External Web Assets_BreachLock Unified Platform
Picture2_External Web Assets_BreachLock Unified Platform

The BreachLock Unified Platform delivers centralized external attack surface visibility, allowing security teams to discover, investigate, and manage internet-facing assets, track investigation status, and organize findings from a single interface.

Better Asset Organization Through Tagging

As environments scale, finding and filtering assets becomes increasingly important. BreachLock AEV now allows users to apply tags across supported asset types, including:

  • Web applications
  • Domains
  • Subdomains
  • IP addresses

Tagging enables security teams to organize assets by business unit, environment, geography, application owner, testing scope, or any other operational criteria that supports their program.

Bulk Asset Onboarding

Managing assets one at a time can create unnecessary administrative overhead. To address this, AEV now supports bulk uploads for internal and external assets. Multiple upload formats are supported based on deployment type, enabling faster onboarding and easier asset management at scale.

Credential Management Within Assets

Security teams often need authenticated testing to accurately assess exposures.

BreachLock AEV now allows credentials to be stored directly against web applications within Asset Management. This creates a more centralized and efficient workflow for managing authenticated assessment requirements across testing engagements.

New Network Segmentation Engagements

Modern attackers rarely stop at initial access. Once inside a network, they actively look for opportunities to move laterally, escalate privileges, and access high-value systems. The new Network Segmentation Engagement gives organizations a dedicated way to validate whether network boundaries are functioning as intended. This engagement type assesses connectivity between network segments and identifies unauthorized pathways that could allow attackers to move across environments.

Picture3_Create Engagement_BreachLock Unified Platform
Picture3_Create Engagement_BreachLock Unified Platform

The BreachLock Unified Platform streamlines security validation by enabling teams to create autonomous engagements across web applications, APIs, networks, and network segments from a single, centralized interface.

Uncover Hidden Network Risks

Network segmentation assessments are designed to surface:

  • Hidden firewall bypasses
  • Legacy firewall rule gaps
  • Unintended network connectivity
  • Unauthorized paths between network segments

By validating actual network access rather than relying solely on documented configurations, security teams gain immediate visibility into segmentation weaknesses before they can be exploited.

Currently, Network Segmentation Engagements are available for internal network environments with external coming soon.

Smarter Campaign Automation and Scheduling

Automation remains a critical component of continuous security validation, and BreachLock AEV v1.10.0 introduces several enhancements that improve the reliability and efficiency of campaign execution.

Picture4_Schedule a Pentest_BreachLock Unified Platform
Picture4_Schedule a Pentest_BreachLock Unified Platform

The BreachLock Unified Platform enables teams to automate pentest scheduling with flexible recurring triggers, ensuring continuous security validation through weekly, monthly, or quarterly testing workflows.

Flexible Scheduling

Campaigns can now run on defined schedules with support for recurring frequencies.

This allows organizations to automate testing workflows that align with operational requirements, whether engagements need to run weekly, monthly, quarterly, or on another cadence.

License-Aware Engagement Creation

AEV now evaluates available licenses before launching campaign-based engagements.

For supported engagement types, currently including internal web engagements, campaigns will create engagements based on available licensing capacity. This helps organizations optimize testing operations while avoiding unnecessary scheduling conflicts.

Duplicate Engagement Prevention

With v1.10.0, campaigns triggered against the same deployment no longer create duplicate concurrent engagements. Instead, the platform ensures only a single engagement is created per deployment, reducing resource consumption and administrative complexity.

A Refreshed User Interface

AEV v1.10.0 introduces a refreshed visual experience across several key workflows. While core functionality and user workflows remain unchanged, the updated interface improves consistency and accessibility across the platform.

Updates include:

  • A redesigned engagement creation workflow
  • An updated license management experience
  • Relocation of the admin panel under the floating AEV action button

These enhancements simplify navigation while providing a more modern and streamlined experience.

Picture5_Create Engagement Internal vs External_BreachLock Unified Platform
Picture5_Create Engagement Internal vs External_BreachLock Unified Platform

The BreachLock Unified Platform simplifies engagement creation by allowing teams to launch internal or external security assessments, manage testing credits, and validate attack surfaces through a unified autonomous testing workflow.

Platform Efficiency Improvements

In addition to major feature releases, v1.10.0 introduces backend optimizations that improve assessment performance and operational efficiency.

  • Smarter Scan Handling: To improve scan efficiency, full scans are now automatically skipped for unreachable assets that return 403 or 404 responses during initial validation. This reduces unnecessary processing and helps focus testing resources on reachable targets.
  • Streamlined Authentication Validation: Authentication workflows have also been optimized. If authentication fails during the first testing objective, additional retry attempts are now skipped. This reduces wasted execution time and accelerates overall assessment workflows.

Stability Fixes Across the Platform

AEV v1.10.0 also delivers several important fixes designed to improve reliability, reporting accuracy, and engagement lifecycle management. These updates ensure engagement states are handled correctly, terminated scans are fully stopped in the backend, and users receive more consistent reporting and platform behavior.

Raising the Bar for Continuous Exposure Validation

BreachLock AEV v1.10.0 focuses on helping organizations manage offensive security operations more effectively while increasing visibility into both assets and attack paths.

These improvements continue to advance BreachLock’s goal of delivering scalable, autonomous security validation that helps organizations identify, validate, and remediate exploitable risk faster and with greater confidence.

Learn more about BreachLock Adversarial Exposure Validation.

Author

BreachLock Labs

BreachLock Labs

Industry recognitions we have earned

Reuters logo Top logo Forbes logo GigaOm logo Global logo Bloomberg logo Globee logo

Fill out the form below to let us know your requirements.
We will contact you to determine if BreachLock is right for your business or organization.

background image