All insights

Introducing ARES for automated penetration testing

Security engineer reviewing an authorized internal network test in a modern operations workspace

See how Meridian ARES validates exploitable attack paths, preserves evidence, and connects authorized penetration testing to remediation and retesting.

Published September 8, 20266 min readBy Rachel Bennett

CulperSec has released ARES, an automated penetration-testing capability within Meridian. ARES helps security teams answer a question that vulnerability data alone cannot settle: which weaknesses can actually be used to create a working attack path?

ARES performs authorized internal and external penetration testing, records evidence of validated paths, and keeps the resulting remediation work connected inside CulperIQ. Instead of ending with another static report, the assessment becomes an operating workflow that teams can scope, execute, review, remediate, and retest.

The result is a clearer view of practical exposure and a more direct route from technical proof to an owned fix.

Vulnerability data is not proof of exploitability

Vulnerability scanners are valuable. They identify outdated software, known weaknesses, configuration issues, and other conditions that deserve attention. But a scanner result usually describes possibility. It does not necessarily show whether a weakness is reachable, whether available controls interrupt the path, or whether several conditions can be combined to produce meaningful impact.

That distinction matters because organizations rarely have enough time to treat every finding as equally urgent. A long list of theoretical issues can obscure the smaller number of conditions that create a usable path through the environment.

ARES is designed for this gap. It moves beyond identification and performs controlled exploitation within an approved scope. The objective is to validate how an attacker could move from exposure to impact, while preserving the evidence defenders need to understand and break that path.

This does not replace vulnerability management. Vulnerability management supports continuous discovery, prioritization, remediation tracking, and verification across the fleet. ARES adds a different form of evidence: proof that particular weaknesses can be used in practice and, where applicable, combined into an attack path.

Automated testing shaped by human expertise

Useful automated penetration testing requires more than scheduling a generic set of checks. The quality of the assessment depends on what the system tests, how it approaches the environment, and how closely that work reflects realistic offensive methods.

ARES assessments are crafted and updated by CulperSec's expert human testers. They draw from the kinds of tools and techniques our specialists use during human-led red-team assessments. That practitioner input gives ARES a testing foundation grounded in how experienced testers examine attack surfaces, enumerate systems, evaluate weaknesses, and connect individual conditions into practical paths.

Automation makes those assessments repeatable. Teams can run approved tests without rebuilding the process from scratch each time, then return to the relevant path after remediation. As CulperSec's testers update ARES assessments, the automated workflow can continue to reflect current practitioner knowledge and testing methods.

ARES and a human-led red-team engagement still serve different purposes. ARES is software-driven automated penetration testing. CulperSec Professional Penetration Testing and Red Teaming are specialist engagements led by human practitioners who can adapt objectives, judgment, and tactics throughout an engagement. Organizations may use either approach or combine them, depending on the depth, frequency, and assurance they need.

A controlled workflow from scope to verification

Penetration testing must begin with authorization. ARES turns an approved scope into a repeatable workflow with explicit boundaries and a documented result.

Define the scope

Teams establish the authorized targets, exclusions, timing, and rules of engagement before testing starts. This creates a clear operating boundary for the assessment and helps ensure that testing aligns with the organization's objectives and risk constraints.

Enumerate the environment

ARES collects information about the authorized environment, including reachable systems, exposed services, and potential weaknesses. This reconnaissance helps establish what is visible from the selected testing perspective, whether the assessment targets an external attack surface or an internal network.

Execute controlled exploitation

ARES tests whether identified conditions can be used in practice. Rather than treating every issue as an isolated record, it can show how weaknesses relate across systems and boundaries to form a broader path.

This is where the distinction between a suspected issue and validated risk becomes useful. Teams gain evidence about reachability, exploitability, and practical impact that can inform remediation decisions.

Preserve evidence and assign work

Validated findings remain connected to supporting evidence, affected assets, ownership, and remediation activity in CulperIQ. Security teams can review what happened, communicate the path to the responsible system owner, and track the work required to close it.

Keeping this context together reduces the translation work that often follows a penetration test. Owners do not have to reconstruct the technical reasoning from a PDF, while security leaders can follow progress without separating the assessment from the remediation record.

Retest the path

Closing a ticket is not the same as closing an attack path. After a team applies a fix, ARES can repeat the relevant test to determine whether the validated path has been interrupted.

That retest provides a stronger completion signal. It helps distinguish between remediation that was attempted and remediation that changed the exploitable condition. The result is documented alongside the original evidence and remediation activity.

What changes for security teams

ARES gives teams a practical way to make penetration testing more repeatable and operational.

First, it helps focus attention on validated risk. Severity ratings and vulnerability data still provide useful context, but evidence of a working path gives organizations another way to decide what needs immediate action.

Second, it supports more frequent validation. Environments change after an assessment. New services appear, identities change, systems are reconfigured, and previously closed paths may take a different form. Repeatable automated testing gives teams a way to reassess authorized parts of the environment without treating every test as a new manual project.

Third, it preserves the relationship between the finding and the fix. The affected asset, technical evidence, assigned owner, remediation decision, and retest result stay within one operating context. That continuity is important when several teams share responsibility for resolving the path.

Finally, it improves the quality of remediation verification. Teams can return to the condition that was proven exploitable and test whether the change actually closed it. This shifts the end of the workflow from administrative completion toward technical confirmation.

Built for internal and external perspectives

Attack paths do not begin from only one position. An external assessment can evaluate reachable assets and services from outside the organization. An internal assessment can examine what becomes possible from an authorized position within the network.

ARES supports both internal and external penetration testing in one product, allowing teams to evaluate different parts of the attack surface while keeping results in the same CulperIQ operating context.

From assessment output to verified reduction

A penetration test is most useful when its findings lead to action and that action can be verified. Yet assessment evidence is often separated from the systems, owners, and work that follow. Over time, the report becomes a historical artifact while teams lose visibility into whether the practical risk was removed.

ARES keeps the lifecycle together. It maps the authorized attack surface, executes controlled tests, validates practical paths, records evidence, connects remediation to accountable owners, and supports retesting after changes are made.

That is the value of automated penetration testing inside Meridian. It is not another source of undifferentiated findings. It is a repeatable way to establish what can be exploited, give defenders the context to break the path, and document whether the fix held.

If your team needs to move from suspected weakness to validated attack-path evidence, Meridian ARES provides an authorized testing and remediation workflow inside CulperIQ.

About the author

Continue reading

More perspectives

View the archive
Systems administrator reviewing mail server logs in a data center

September 2, 2026 · 9 min read

Zimbra patching needs a hunt

CVE-2026-73570 is under active exploitation. Zimbra teams need to identify the vulnerable configuration, upgrade, and investigate for compromise.

Read article

Put insight to work

Bring the right security expertise to the next decision.

Tell us what your organization is facing. We will help define the practical next step.

Start a conversation