Security assessments, including penetration testing, are a crucial component in mitigating cybersecurity risks. However, traditional methods for conducting these assessments are often manual and come with a high cost. Additionally, the results obtained from on-prem and cloud infrastructure evaluations are often reported separately, leading to fragmented visibility into an organization’s security posture. Prancer offers a solution to these challenges with our end-to-end cloud security solution, Pen-Test as a Service (PTaaS). PTaaS provides clients with a comprehensive and cost-effective approach to securing their cloud environment, while offering an easy-to-use interface for ongoing security management.

Prancer is proud to offer a patented solution, Pen-Test as a Code (PAC) engine, which automates and streamlines penetration testing for both on-prem and cloud applications. Our PAC engine simulates potential attack scenarios and performs thorough penetration testing to identify vulnerabilities within an organization’s network. Additionally, our Cloud Security Posture Management (CSPM) engine provides a unified, single-pane-of-glass solution that records and reports security issues across both on-prem and cloud environments. This innovative approach to security management helps organizations achieve a comprehensive and cost-effective view of their security posture.

Prancer’s autonomous security-testing engine provides clients with a comprehensive evaluation of their cloud network security posture. The Pen-Test as a Code (PAC) engine leverages advanced auto-discovery capabilities to identify company assets and detect attack surface at both the application and infrastructure layers. The engine’s reporting functionality highlights any security misconfigurations and provides automated remediation options, reducing the need for manual intervention. The PAC engine also has the ability to formulate targeted attacks by constructing lateral movement strategies and simulating them on demand, either through integration with the CI/CD pipeline or in a continuous mode. These simulated attacks are designed to align with the specific vulnerabilities present in disparate networks.

Prancer maintains a comprehensive database of codified attack scenarios, allowing us to track and accumulate unfamiliar or rare attack scenarios encountered by our clients. This information is used to continuously improve our automated remediation capabilities. Our Pen-Test as a Code (PAC) engine leverages our access to native hacker tools to simulate attacks and uncover potential points of entry from a hacker’s perspective. This helps validate the security of an organization’s assets and provide a comprehensive view of their security posture from an attacker’s viewpoint.

Prancer’s innovative approach to security assessment is fully automated and agentless, providing cost-efficient solutions to our clients. Our Pen-Test as a Code (PAC) engine collects intelligence from the cloud and leverages the comprehensive attack database to perform simulated attack scenarios against an organization’s resources. The use of native hacker tools in this process ensures a thorough evaluation of an organization’s security posture. According to Farshid Mahdavipour, founder and CEO of Prancer, “The PAC engine provides a comprehensive, cost-effective solution for organizations looking to validate the security of their resources.

Prancer’s Pen-Test as a Service (PTaaS) offers significant cost savings to client companies, with a reported reduction of 63 percent in related expenses. The solution’s pre-built coverage of common vulnerabilities reduces the need for scarce resources and results in consistent outputs. Our clients also report a 58 percent increase in agility when leveraging the PTaaS solution. The solution’s ability to scale at the cloud level, combined with its automated and codified nature, provides reliable and consistent results for both internal and cloud-based applications.

Prancer’s PTaaS solution is complemented by our other offerings, including ZDaas (Zero-Day as a Service). Our threat development research team leverages data from multiple sources, including CSPs, CVEs, and the National Vulnerability Database, to continuously monitor for new zero-day vulnerabilities. Upon discovery, the team codifies the vulnerability to ensure our clients are protected against it, delivering a comprehensive security solution.

Prancer’s Dynamic Application Security Testing (DAST) solution leverages cloud intelligence to help developers ensure the security of their applications before deployment. Integrating with the software development lifecycle (SDLC) process and the continuous integration and continuous deployment (CI/CD) pipeline, this solution ensures that new code introduced to the cloud is secure and free of vulnerabilities.

Prancer offers a comprehensive suite of solutions for ensuring the security of its clients’ networks. Its Zero-Trust Security Validation Solution thoroughly evaluates the security of a zero-trust environment.

The Intelligent API Security Solution meticulously verifies the security of APIs, recognizing their potential to pose a threat to organizations.

  • PAC gets all the intelligence out of the cloud and all the vulnerabilities available from our codified attack database and loads the native hacker’s tools to be able to perform the attack emulation for an organization’s resources


The Infrastructure as Code (IAC) Security Engine provides a robust open-source solution with its security policies readily available on GitHub, where it has garnered over a million downloads. The company’s offerings are designed to provide comprehensive security for cloud environments and include support for major cloud providers, including AWS, Azure, GCP, and Kubernetes.

One of Prancer’s clients, utilizing a multi-cloud environment with AWS for the cloud and GCP for hosting APIs and databases, experienced a significant improvement in their security posture within just two weeks of onboarding. Upon connecting their cloud account, Prancer’s solution immediately identified critical vulnerabilities in the network that could have led to a breach and applied auto-remediation to address these issues. Additionally, the client was encountering challenges with their authentication methodologies, which were resolved by Prancer’s penetration testing engine. As a result, the client’s overall security posture improved by 60 percent.

Going forward, the company aims to consolidate its security tools for other organizations by integrating its existing solutions. Another development that Prancer is eagerly anticipating is the incorporation of Artificial Intelligence (AI) to drive risk motivation, remedy detected risks, and minimize false positives. Additionally, the company plans to extend its solution to accommodate Internet of Things (IoT) and Operational Technology (OT) applications.

With numerous solutions in the works, Prancer will continue to advance the cybersecurity space by improving its current solutions and introducing others for years to come.