SpartanX supports multiple engagement types, each designed for a distinct phase of an organization's security testing lifecycle. From full-scope autonomous red team campaigns to targeted validation of specific findings, understanding the options helps you choose the right test for the right moment.
External Attack Surface Engagements
External engagements target publicly reachable assets — web applications, APIs, network endpoints, and anything else internet-accessible. SpartanX provides two launch paths:
Full Scope Operation with Adaptive Intensity (Basic Wizard) — a streamlined, one-click launch that autonomously runs an end-to-end campaign: reconnaissance, exploitation, and adaptation. When the platform detects a specific technology, it dynamically invokes the right testing modules. This is the fastest path to results.
Advanced Wizard — offers more granular control: exclude specific assets, set intensity to Normal or Deep (deep reasoning uncovers novel attack paths and is more likely to surface zero-day vulnerabilities), define exceptions, and schedule recurring tests.
Recurring scheduling is critical. Annual penetration tests are no longer sufficient — the advanced wizard makes it easy to set weekly or monthly red team cycles.
Internal Engagements via NodeX Connectors
NodeX Connectors extend SpartanX's red teaming capabilities to internal networks. A NodeX Connector is a downloadable virtual image (OVA, VMDK, Hyper-V, etc.) that you deploy on any machine with internal network access — a laptop, a cloud VM, or a production network segment.
Once deployed and paired with the SpartanX platform, NodeX brings the same full-scope operation and advanced wizard options to internal infrastructure. There's no limit on the number of connectors, and no additional cost per deployment.
Deploy in AWS, GCP, Azure, or on-premises
Test corporate networks, development environments, and production infrastructure
Simulate insider threats or compromised contractor access
Targeted Attack ValidationTargeted Attack Validation is for organizations that already have vulnerability data from other tools. Import reports from scanners like Tenable Nessus, Qualys, or Acunetix, and SpartanX will validate whether those findings are genuinely exploitable — filtering out false positives and confirming real risk.
This engagement type is available for both external (public IPs and URLs) and internal (RFC 1918 addresses) assets. It doesn't discover new vulnerabilities — it validates existing ones.
Remediation VerificationOnce developers have patched a vulnerability, Remediation Verification confirms the fix is effective. SpartanX retests the specific vulnerability — or an entire asset's vulnerability list — to verify that the remediation holds.
This can be run on a per-vulnerability basis or across all findings on a given asset, and it supports scheduling to automate recurring verification cycles.
Static Code Analysis (SAST and Mobile)SpartanX provides AI-powered static analysis that goes beyond traditional regex-based SAST:
It analyzes code across interconnected repositories — not just in isolation — to catch vulnerabilities that arise from cross-repository dependencies.
It examines the supply chain: third-party libraries, public packages, and imported dependencies.
For mobile apps (APK for Android, IPA for iOS), it supports both source code analysis and dynamic runtime validation, covering SAST and DAST in a single workflow.
What's NextThe next sections walk through launching each engagement type step by step, starting with external engagements using both the basic and advanced wizards.





