AWS Security Agent

2026/08/13 - 11 updated api methods

Changes   Add support for setting a maximum task-hour budget cap on penetration tests and code reviews, and for revalidating previously reported findings via a new REVALIDATION job type.

2026/08/07 - 11 updated api methods

Changes   Added enableEmailMfa input field on Actor to enable email-based MFA during penetration tests. When enabled, a server-generated mfaForwardingAddress is returned. Set up a forwarding rule in your email provider to forward MFA emails to this address so the agent can complete email-based MFA login flows

2026/07/30 - 13 updated api methods

Changes   Adds support for providing a branch override when configured integrated repositories

2026/07/27 - 2 updated api methods

Changes   AWS Security Agent adds a new task hours field that reflects the active work done for a task.

2026/06/17 - 31 new 21 updated api methods

Changes   Updated AWS Security Agent SDK model with new APIs for threat modeling, code review, security requirements, and additional integration providers.

2026/05/22 - 1 updated api methods

Changes   Adds support for verification scripts on penetration test findings. Customers can now download executable scripts to independently reproduce confirmed vulnerabilities, with instructions and required environment variables provided for each finding.

2026/05/13 - 11 new 3 updated api methods

Changes   Add support for code reviews, a new resource type that enables automated security-focused static analysis of source code repositories.

2026/05/04 - 4 updated api methods

Changes   AWS Security Agent is adding a new target domain verification method for private VPC penetration testing. Additionally, the target domain resource will now have a verification status reason field to surface additional details about domain verification

2026/03/31 - 50 new api methods

Changes   AWS Security Agent is a service that proactively secures applications throughout the development lifecycle with automated security reviews and on-demand penetration testing.