Running external attack surface management with AI, without a dedicated security team — PentaTrail CTEM/ASM
Pentacon Research, Inc. (Chuo-ku, Tokyo; CEO: Kazuya Hiradate) has made PentaTrail CTEM/ASM — a service that continuously monitors and manages an organisation's external attack surface — generally available in August 2026. Reflecting what we learned during the beta, it automates the path from discovery through vulnerability validation, remediation and executive reporting with AI, so that a company without a dedicated security team can run its external attack surface — and can start without going through sales or a quotation.
Background — the assets you cannot see are the way in
Attacks now start from external assets that organisations have not fully catalogued. More than 80% of ransomware intrusions with an identified entry point came through internet-facing equipment such as VPN devices [1]. What the attacker can see and the organisation cannot is, in itself, the largest weakness. There is little grace period either: for internet-facing equipment, more than half of the vulnerabilities analysed were already known to be exploited by the time they were published [2]. Japan's METI is establishing a scheme for evaluating the security of business partners (SCS) [3], so being able to explain your own posture objectively is becoming a requirement as well.
Even where the need is understood, few companies can staff a dedicated security team. Services that continuously watch the external attack surface become expensive when a human walks alongside, and when prices are not published, comparison itself has to begin with a sales conversation. Many companies stop before that point.
Why we can offer this price without a sales conversation
Most of the cost of security operations has been human time: an analyst reads the results, a consultant advises on remediation, a salesperson prepares a quote. PentaTrail rebuilds that.
The product itself is developed end to end with generative AI, so the largest cost in conventional software development — developer time — is largely absent. The same holds for operations: asset discovery is automated with deterministic techniques such as DNS, certificate transparency logs and OSINT, while vulnerability validation, remediation guidance and executive reports are generated by AI. The staffing cost of models where a human analyst is continuously engaged (typically from several hundred thousand yen per month) does not sit in our pricing. Because prices, features and real sample reports are all published, there is no quotation or sales overhead either. Without the round trip of enquiry, scheduling and proposal, you start faster: registration takes about five minutes, and the first view of your attack surface appears within hours.
This is not a discount. It is a different way of building. Letting small and mid-sized organisations run their external attack surface without adding headcount, and without a dedicated security team — that is where PentaTrail stands.
Evidence — not stopping at "we found it"
PentaTrail carries the threat intelligence experience our CEO built over many years in managed security services into the design of the whole product. Following the five stages of CTEM (Continuous Threat Exposure Management), proposed by Gartner in 2022, it repeats the loop from discovery to remediation rather than running a one-off assessment, and keeps reducing the attack surface. Asset discovery does not rely on AI inference: it cross-checks public information and reports only what actually exists. AI works after that — confirming whether a discovered vulnerability is exploitable, within a scope that does not affect the system, then laying out the steps and the order in which to fix them, and assembling the report for management.
Finding issues and ranking them by risk is the ASM plan. Actually validating them, running remediation through to completion and reporting to management is the CTEM plan.
Pricing
The ASM plan is JPY 40,000 per month and the CTEM plan is JPY 68,000 per month (both excluding tax). Both include 3 domains and 5 users; unit prices for additional domains and users are published on the service site.
We also publish a sample of the report that the service actually produces.
Working with AI agents
PentaTrail ships with an MCP (Model Context Protocol) server as standard. From an AI tool the customer has approved, it can read the state of known assets and vulnerabilities, and perform operations such as creating remediation tasks. Instead of opening the dashboard and copying values out by hand, the person in charge can ask the AI assistant they already use and act on the answer directly.
Comment from the CEO (Kazuya Hiradate)
"Only trained people can respond to cyber attacks. I believed that for a long time, standing in security operations. But over the past year AI has become capable enough to overturn that assumption. Steps that must be backed by fact — discovery, for example — we harden with mechanisms people designed; and where AI genuinely works — validating vulnerabilities, directing remediation — we use AI. PentaTrail is that division of labour, made concrete."
About Pentacon Research
Pentacon Research, Inc. was founded in February 2026 by Kazuya Hiradate, who brings more than 20 years of hands-on experience in CSIRT operations and security governance. Through "AI-native development" — leaning on AI across the whole of development — we are testing how far security that has depended on human effort can be changed.
| Company | Pentacon Research, Inc. |
| CEO | Kazuya Hiradate |
| Founded | February 2026 |
| Address | 2-17-6 Nihonbashi Kayabacho, Chuo-ku, Tokyo, Japan |
| Capital | JPY 10,000,000 |
| Business | Development and provision of information security SaaS, security consulting, research into AI technologies |
Enquiries
Pentacon Research, Inc. — contact form
Sources
- [1] National Police Agency of Japan, "Threat landscape in cyberspace, first half of 2025." Among ransomware cases where the intrusion route was identified, 84% came through internet-facing equipment such as VPN devices and remote desktop. https://www.npa.go.jp/publications/statistics/cybersecurity/data/R7kami/R07_kami_cyber_jyosei.pdf
- [2] Verizon, "2025 Data Breach Investigations Report." Across the 17 edge-device vulnerabilities analysed, the median time from CVE publication to listing in CISA KEV was zero days; 9 were already listed on or before the publication date. https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf
- [3] IPA, "Supply Chain Security Assessment Scheme (SCS)." https://www.ipa.go.jp/security/scs/index.html
External distribution: https://prtimes.jp/main/html/rd/p/000000004.000187914.html
