by KaseyaTechBag Intel Page

vPenTest

Your scanner lists thousands of findings. It can’t tell you which ones let an attacker in — vPenTest runs automated internal and external network penetration tests that exploit, escalate and pivot like an attacker, then reports what actually got through — monthly if you want, without booking a consultancy.

Automated network pentesting, not a scannerInternal and external, monthly or on demandQuote only; hosted outside India

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Neither kaseya.com nor vonahi.io prints a price; licences are counted by internal and external IPs
Quote
Reports
Vonahi’s own figure for a report after a test ends; scope and allowed test windows stretch it
48 hours (claim)
Analysts
No Gartner, Forrester or IDC placement for vPenTest; Kaseya’s page shows a G2 rating of 4.6
None
India
Tenants live in the US, Germany or Australia, and CERT-In empanelment is not held
Not hosted

Quick answer

vPenTest, from Vonahi Security (part of Kaseya since 2023), runs automated internal and external network penetration tests: an agent inside your network exploits weaknesses, cracks passwords and moves laterally as an attacker would, and Vonahi says reports follow within 48 hours. It is not a vulnerability scanner. Kaseya prints no price, and tenants are hosted in the US, Germany or Australia, not India. Read more ↓ Show less ↑
Part 01 · Orient

The Kaseya platform family

This page covers vPenTest — Vonahi’s automated network pentesting, with Kaseya’s VulScan scanner folded in. The rest:

Quick facts

30-second orientation
Product
Automated internal and external network penetration testing, delivered as SaaS
Maker
Vonahi Security, a Kaseya company since 2023; Kaseya’s CEO is Rania Succar
What it is not
Not a vulnerability scanner: it exploits, escalates and pivots to prove impact
Price
Quote only; Kaseya’s terms count licences by internal and external IPs
Agent
Ubuntu 24.04 VM or box with 2 cores, 8 GB RAM and 80 GB disk; runs a Kali container
Reports
Within 48 hours of a test ending, by Vonahi’s account; AI-written executive summary
Standards
CREST member in EMEA and Australasia; reports aimed at PCI DSS, SOC 2, HIPAA, ISO 27001
Folds in
VulScan, Kaseya’s network scanner, whose findings import into scheduled pentests
India
Tenants sit in the US, Germany or Australia; Vonahi is not on CERT-In’s empanelled list
In India via
TechBag — IP scoping, a quote with GST, and a walkthrough of the first test
Part 02 · Learn

Understand automated penetration testing before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is automated penetration testing?

Software that attacks your network on a schedule the way a human tester would, then reports what it actually reached.

A yearly consultant pentest vs vPenTest — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA yearly consultant pentestvPenTest
How often you testOnce a year, when the consultant has a slotMonthly or on demand, from 30 minutes ahead
What a finding meansA scanner’s guess that a service is weakProof the weakness was exploited, or not
Seeing the attackA PDF weeks after the testers leaveA live Activity Log while the test runs
Turning results into workSomeone retypes findings into ticketsFindings opened as Autotask tickets
Checking the fixesWait for next year’s engagementRun the same scope again next month
What it is NOT—A scanner, a web-app test, or a CERT-In report

The cheapest test is one internal assessment on a single subnet: deploy the agent, run it out of hours and compare the report with your last pentest.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where tests are scheduled and read

Portal

vPenTest SaaS portal

A multi-tenant web app where each client is an organization: you set scope, IP ranges and test windows, follow progress and download the finished reports.

02
Where internal attacks start from

Agent

Internal vPenTest Agent

A Linux VM or small box on your network, cloud-hosted if needed, that installs fresh tools before each run and attacks from inside through a Kali container.

03
What a test actually does

Attack chain

Automated pentest methodology

OSINT and host discovery, then safe exploits, password attacks and short MitM bursts, then privilege escalation and lateral movement, as a human tester would.

04
How results reach people

Reports

Reports and Activity Log

A live log of every agent action for SIEM correlation, then technical and executive reports, which Vonahi says arrive within 48 hours of the test ending.

A SaaS portal and one Linux agent inside your network — attacks run from within, results land in the portal.

Part 03 · Evaluate

Nine capabilities. Attack, prove, connect.

vPenTest attacks your network the way an intruder would, then reports which weaknesses actually let it in.

Attack
OSINT

Starts where attackers start

External tests first gather domains, DNS records and usernames from public sources, then turn them into login attempts.

Attack
Exploitation

Exploits, not just findings

Long-tested exploits are tried against what discovery turns up; attacks known to cause a denial of service are left out.

Attack
Post-exploitation

Escalate, then pivot

With a foothold it cracks password hashes, escalates privileges and moves laterally, showing how far one breach can spread.

Prove
Activity Log

Watch the attack as it runs

Every agent action is logged in real time, so you can check afterwards whether your SIEM and EDR noticed any of it.

Prove
Reports

Findings within two days

Vonahi says reports arrive within 48 hours of a test; since 2025 an AI summary and slides put the top risks in business terms.

Prove
CREST

A CREST-certified option

Organisations in EMEA or Australasia can pick a CREST-certified network test when scheduling; India is outside that scope.

Connect
VulScan

Scanner results folded in

The VulScan integration copies its internal and external findings and fix steps into a scheduled vPenTest assessment.

Connect
Autotask

Each finding becomes a ticket

Since April 2026 findings can open and update Autotask tickets, so fixing starts in the PSA rather than in a PDF.

Connect
Dark Web ID

Leaked passwords put to use

Credentials Dark Web ID has found can be tried during a test, to show whether a leaked password or missing 2FA lets someone in.

Why vPenTest

A scanner says a door might be unlocked. vPenTest tries the handle and reports what it reached.

Here’s what genuinely sets it apart — and exactly where it stops.

01

It exploits, where a scanner only lists

A scanner reports that a service might be vulnerable. vPenTest tries the exploit, cracks the hashes it captures, escalates privileges and moves sideways, then shows which findings chained into real access. Severity starts from CVSS, and Vonahi lowers a finding that led nowhere.

02

A pentest every month, not once a year

A test can be scheduled to start 30 minutes ahead, inside the hours you allow, and repeated monthly as the network changes. Reports trend findings from one run to the next. Vonahi pitches it at over 60% below a manual pentest’s cost; that is its claim, so compare quotes.

03

Why it sits in the Vulnerability Management guide

A vulnerability programme finds weaknesses, ranks them, fixes them and checks the fixes. vPenTest serves the ranking and checking: it proves which scanner findings an attacker could actually use. TechBag has no automated-pentest guide, and this guide already covers pentesting.

04

Where it stops

It tests networks; web-application testing is not in its documentation. Exploits cannot be switched off per host, so fragile systems must leave the scope. There is no published price, no India hosting region and no CERT-In empanelment, and it does not replace continuous scanning.

The idea
Exploit to prove, not scan to list
The cadence
Monthly or on demand, 30 minutes ahead
The price
Quoted by internal and external IPs
Proof, not promises

The numbers behind the platform

48 hours
Vonahi’s stated time from the end of a test to the finished report
— Vendor
30 minutes
the shortest lead time when scheduling a test, so the agent can update its tools
— Vendor
8 GB RAM
the memory Vonahi asks for on the agent, with 2 cores and 80 GB of disk
— Vendor
3 regions
hosting regions for tenants: United States, Germany and Australia, none in India
— Vendor
2 CREST regions
where Vonahi is a CREST member company: EMEA and Australasia
— Vendor
90 days
the default report retention in Kaseya’s terms, unless you configure another period
— Vendor

What your vPenTest rollout looks like

Week 1Model

Count and clear the scope

List internal and external IP ranges, get written approval from every owner, and pull fragile systems out of scope.

Week 2Decide

Stand up the agent

Build the Ubuntu agent on a bridged VM or small box, open outbound 443 and allowlist Vonahi’s source IPs for external runs.

Week 3Pilot

Run the first internal test

Schedule it out of hours, watch the Activity Log beside your SIEM, and note what your EDR did and did not alert on.

Month 2Prove

Fix, then test again

Turn findings into tickets, fix the paths that reached valuable data, then rerun the same scope to prove they closed.

Month 3Commit

Set the monthly rhythm

Add the external test, link VulScan or Autotask if you use them, and agree a monthly cadence with owners of each range.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.3
47+ reviews*
86% would recommend
Attack realism4.5
Report quality4.4
Ease of setup4.4
Remediation workflow3.8
Value for money4.1
5★
51%
4★
33%
3★
11%
2★
3%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Manufacturing
“The first internal run cracked a service account hash and reached a file server our scanner had rated medium.”
IT Security Lead
Manufacturing
BFSI
“We moved from one consultant test a year to monthly runs. The trend page shows the board fewer findings each quarter.”
Head of IT
BFSI
IT Services
“Read the Activity Log beside your SIEM. Ours missed the lateral movement entirely, which mattered more than the report.”
SOC Manager
IT Services
Pharma
“Exploits cannot be turned off per host, so we left two legacy controllers out of scope and ran an assessment on them.”
Infrastructure Engineer
Pharma
Education
“Agent setup took an afternoon on a spare Hyper-V host. Bridged networking was the step we nearly got wrong.”
Systems Administrator
Education
Fintech
“Good network testing, but our auditor still asked for a CERT-In empanelled firm, so we pay for that report too.”
Compliance Manager
Fintech
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the vulnerability management market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Vulnerability Management Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
vPenTestThis page

Quote only; licences counted by internal and external IPs.

Grid 02 · The architecture

Exploit Proof × Testing Cadence

The grid nobody publishes — how far a product goes towards proving a weakness is exploitable vs how often it can test without hiring people.

Continuous detectorsAutomated attackersOccasional scannersExpert point-in-time tests
vPenTestThis page

Exploits, escalates and pivots; runs monthly or on demand.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

vPenTest vs the vulnerability management field

Against Mitigata VAPT, Tenable Nessus Professional, Qualys VMDR, Rapid7 InsightVM and Tenable Vulnerability Management — on testing depth, coverage, price, scale, integrations, India and exit.

DimensionvPenTestMitigata VAPTTenable Nessus ProfessionalQualys VMDRRapid7 InsightVMTenable Vulnerability Management
What it isAutomated net pentestHuman-led VAPT serviceStand-alone scannerScan, rank and patchRisk-based VM, hybridCloud VM lifecycle
DeploymentSaaS + one Linux agentDelivered by testersSoftware you runCloud, agent + scannersConsole you hostCloud, sensors + agents
CoverageInternal + external netsWeb, API, net, cloudHosts, basic web checksHosts, cloud, endpointsHosts; web is extraHosts; web, cloud extra
Pricing modelPer IP tested, quotedPer applicationPer scanner a yearPer asset, quotedPer asset a monthPer asset a year
Published entry priceNot publishedEntry tier per app$4,790 a yearReported ~$199–250$1.62 per asset/month$3,700 for 100 assets
Included vs add-onVulScan sold apartReport and re-testScanner onlyPatching bundledWorkflow in the cloudNo patching
Scale and limits45 s–4 min per hostBound by tester timeOne scanner by designCloud-scaleHeavy console sizingAbove 10,000 assets
Testing depthExploits and pivotsManual exploitationDetects, no exploitDetects, TruRisk-rankedExploit-weighted rankingDetects, VPR-ranked
IntegrationsAutotask, DWID, APIFeeds its own servicesReports and exportsOne platform, many appsAgent shared with SIEMPath to Tenable One
Governance and tenantsMulti-tenant, KaseyaOneA service, not a tenantNo central consoleOne shared tenantYour console, assignedCloud tenant
India data and CERT-InUS, Germany, AustraliaIndian, CERT-In soldStays on your hostIndia platformConsole can sit in IndiaNot documented
SupportTickets, 1 business dayFrom the test team24/7 costs extraOften via partnersAsk for targetsAsk for targets
Lock-in and exitReports purge on a timerThe report is yoursFiles stay localHistory in the tenantOld scores not keptTrends in the cloud
Best fitMonthly network pentestsRegulator-facing VAPTConsultants, small teamsFind and fix in oneHybrid, deadline-drivenPublished-price cloud VM
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose vPenTest if…

  • ✓You want to know which findings an attacker could really use, not another list of thousands
  • ✓One consultant pentest a year is too rare for a network that changes every month
  • ✓You run Autotask, VulScan or Dark Web ID and want test results to land where your team already works

Compare alternatives if…

  • ✓Your regulator wants a CERT-In-empanelled auditor’s report — hire a tester from CERT-In’s published list
  • ✓You need continuous scanning of every asset first — Qualys VMDR, Tenable VM and InsightVM do that job
  • ✓Web applications and APIs are your exposed surface — vPenTest documents network testing only

Do not expect…

  • ✓A published price, or an India hosting region
  • ✓A vulnerability scanner, a patch tool or a web-app test
  • ✓An analyst placement — none exists for vPenTest

vPenTest is one of 20 vulnerability management products TechBag carries. The Vulnerability Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does pentesting by hand cost you?

Drag the sliders (IP addresses in scope; security staff-hour cost). Estimates model the staff and consultant time spent scoping, running, chasing and re-testing manual network pentests at an assumed 1.5 hours per IP a year, with 70% of it removed by automated, scheduled testing. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual pentest labour cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote only. Kaseya and Vonahi publish no vPenTest price. Kaseya’s terms count licences by type — internal IPs and external IPs among them — over a committed service term, so the quote turns on how many addresses you test. Vonahi markets it as over 60% cheaper than a manual network pentest; that is its claim, not a quote. VulScan is licensed separately. TechBag counts your in-scope IPs first, then gets the quote with GST.

Internal network pentest

Best for what an insider or infected laptop could reach

  • Runs from your vPenTest agent
  • Licensed by internal IP count
  • Quote only

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

External network pentest

Best for testing your internet-facing perimeter

  • OSINT, then attacks from Vonahi’s IPs
  • Licensed by external IP count
  • Quote only

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Purpose

Do you need proof of exploitable paths, or simply a list of weaknesses? The second is a scanner’s job.

2
Scope

How many internal and external IPs are in scope? Every networked device, printers and cameras included, counts.

3
Authorisation

Have the owners of every range, including clients and cloud tenants, approved testing in writing?

4
Fragile systems

Which hosts must not be exploited? They have to leave the pentest scope, as exploits cannot be disabled per host.

5
Agent

Can you host an Ubuntu 24.04 agent with 2 cores, 8 GB RAM, 80 GB disk, bridged networking and outbound 443?

6
Regulator

Does your regulator or auditor accept this report, or require a CERT-In-empanelled firm’s VAPT as well?

7
Data location

Is hosting results in the US, Germany or Australia acceptable under your DPDP and contractual obligations?

8
Licence

Does the quote state internal and external IP counts, the term, test frequency and whether VulScan is included?

FAQ

Questions buyers ask

vPenTest is Vonahi Security’s automated network penetration testing platform, part of Kaseya since 2023. An agent inside your network, plus Vonahi’s external attack infrastructure, runs internal and external tests that exploit weaknesses, crack passwords and move laterally, then reports what an attacker could reach.

Ready to evaluate vPenTest?

Count the internal and external IPs you need tested first, or let a TechBag advisor scope a first internal pentest and walk your team through what it reached.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.