For Pen-Test Firms

Resources for Pen-Test Firms Running HailBytes ASM

Continuous external reconnaissance for offensive-security boutiques, whether you’re using it internally to scope engagements faster or reselling it as a recurring deliverable between point-in-time tests.

Two ways pen-test firms use HailBytes ASM

HailBytes ASM is reNgine in the cloud: the same open-source reconnaissance engine your testers may already know, deployed as a managed service in your AWS or Azure account. Subdomain enumeration, port scanning, vulnerability detection, and change tracking run continuously and on-demand, with the marketplace billing path your clients’ procurement teams will accept. The platform fits two distinct motions inside an offensive-security firm.

Internal scoping accelerator. Run ASM against prospects and active clients as a pre-engagement reconnaissance and SOW-scoping tool. Quote external assessments in 24 hours instead of a week. Walk into kickoff with a current asset inventory so your testers spend their hours on exploitation and impact analysis, not on the same recon every engagement re-does. This is a cost-side investment that pays back as faster sales cycles and tighter engagement margins.

Continuous monitoring deliverable. Add each client as a Project on your ASM instance, white-labeled as part of your firm’s service offering, and bill them monthly for ongoing external monitoring between point-in-time engagements. This is recurring revenue against the same client base you already have project relationships with. Margin lives in the spread between each client’s attributed share of the instance and the monthly fee, plus the analyst time for triage and a written deliverable the client’s security team can act on. One 8 vCPU instance is the entry shape at ~$1,680/month all-in ($1,400 software fee plus roughly $280 of cloud infrastructure in your own account) and handles 10–50 scheduled scans a day, so the platform only pays for itself once three or four client Projects are on it.

Most firms doing this well end up running both motions in parallel: internal scoping for every prospect and active engagement, plus client-facing continuous monitoring for the subset of clients who want and can afford it.

What pen-test CTOs ask before committing

Three questions come up on every demo call. We covered each of them in detail:

  • What’s the difference between this and self-hosted reNgine? For the internal-scoping use case, it’s a question of engineering opportunity cost. For the client-facing reseller use case, it’s a fundamentally different conversation about uptime, audit logging, and the marketplace billing path. Article: Reselling Continuous ASM Between Pentests.
  • How do we package this as a recurring client deliverable without burning analyst time? Three pricing models that work, a sample P&L on a $750/month per-client retainer, and the operational mistakes that kill the margin (bloated reports, ungated alerts, per-asset pricing). Note the retainer only works on a shared instance: at four client Projects on one 8 vCPU instance the attributed platform cost is ~$420/client/month, leaving ~$330/month gross before analyst time — a dedicated instance per client at ~$1,680/month is under water at that retainer.
  • How does ASM make the next pentest engagement materially better? Faster scoping, pre-engagement recon already done, findings with timeline context the client’s board actually responds to.

If you’d rather see the platform than read about it, the AWS and Azure marketplace listings give a 30-day free trial. Run it against your firm’s own attack surface first; the internal scoping use case is the fastest way to evaluate fit before standing up your first client instance.

Going deeper: client-facing reseller deep-dive

For the client-facing reseller motion (continuous-monitoring deliverable between engagements), the partner resell page has the full operational mechanics: AWS CPPO and Azure MPO 4-step setup, the annual commitment discount tiers (30% 1-year prepaid / 35% 2-year / 40% 3-year), how the wholesale baseline steps down as your client count grows, and how to run ASM as a branded continuous-monitoring product: the console and reports carry your firm’s branding instance-wide, and Projects keep each client engagement separated for your own analysts. A client that needs its own branding or its own identity provider needs a dedicated instance.

If you are scoping a PoC for a client before the resale conversation, the PoC process page documents the 14-day and 30-day scoping options, deliverables, and the four-stage rollout decision gates from pilot to full enterprise rollout.

Articles for Pen-Test Firms

ASM · Pen-Test
Reseller Motion

Reselling Continuous ASM Between Pentests

Pricing tiers, white-label setup, a sample $750/mo per-client retainer P&L on a shared instance, and the engagement mechanics that make ASM a sticky service line.

Read More →
Internal Scoping

HailBytes ASM vs Manual Reconnaissance

Why offensive-security teams switch from manual recon (subfinder, amass, custom bash) to continuous automated workflows for engagement scoping.

Read More →
Operations

Continuous Attack Surface Monitoring

Operationalizing continuous monitoring with scan cadence, change detection, SIEM integration, and automated triage workflows.

Read More →
Mapping

Attack Surface Mapping with HailBytes ASM

From subdomain enumeration through port scanning and nuclei vulnerability detection in a single automated pipeline.

Read More →
Setup

The Reconnaissance Setup Tax

Why security teams spend 42+ hours deploying recon tools, what the “setup tax” costs annually, and how cloud-first deployment eliminates it.

Read More →
Jira · Slack · SIEM
Integration

Piping ASM Findings into Jira, Slack, and Your SIEM

Webhooks, API exports, and automated triage workflows that close the gap between discovery and remediation in your existing tooling.

Read More →
TCO

The Real Cost of DIY Security Tooling

TCO analysis comparing self-hosted open-source recon tooling against a managed deployment: engineering time, key-person risk, and opportunity cost.

Read More →
SOC 2 / ISO 27001
Compliance

Meeting SOC 2 and PCI-DSS Pen Test Requirements

How to use HailBytes ASM (and SAT) to satisfy SOC 2 Type II, PCI-DSS, and ISO 27001 penetration testing and continuous-monitoring controls.

Read More →
Free resource

Free Guide: Pen-Test Firm Recon Automation

Standardize and automate the recon phase to compress engagement timelines and free senior testers for the work that bills. Instant access.

Try the Internal-Scoping Use Case First

Spin up a 30-day free trial through the AWS or Azure marketplace and run ASM against your firm’s own attack surface. The internal scoping use case is the fastest way to evaluate fit before standing up your first client-facing instance.

View HailBytes ASM → Scope Reseller Terms →