ZeroHour
Horizon3.aipublished ()ingested Horizon31

How Virginia Tech Connected Pentesting to Its Engineering Workflow

infoIndustryimportance 15
AI summary · glm-5.3-flash

Horizon3.ai customer story details Virginia Tech automating external pentesting via NodeZero's GraphQL API with GitLab and ServiceNow integration for remediation tracking.

Horizon3.ai published a customer story describing how Virginia Tech, whose environment serves more than 38,000 students across hundreds of independent departments and multiple cloud providers, used NodeZero's GraphQL API to automate external pentesting through GitLab. Findings are routed directly into ServiceNow for subnet-owner assignment and remediation tracking, creating a repeatable attack-validation-to-remediation workflow.

  • Automated external attack validation across hundreds of departments and cloud providers
  • NodeZero positioned as attack validation layer between GitLab and ServiceNow
  • Findings routed to subnet owners for tracked remediation
Full article398 words · extracted from horizon3.ai · click to collapse

Finding exploitable risk is only part of the security challenge. In large, decentralized organizations, findings also need to reach the right owners and move into remediation without creating another disconnected process.

Virginia Tech needed a scalable way to validate external exposure across an environment spanning hundreds of independent departments, multiple locations, cloud providers, and locally managed infrastructure.

This customer story explores how Virginia Tech used the NodeZero® GraphQL API to automate external pentesting through GitLab and route findings into ServiceNow, creating a repeatable workflow from attack validation to remediation.

Key Insight

Security testing creates more value when findings flow directly into the systems teams already use to manage engineering work and remediation.

Rather than treating pentesting as a standalone security activity, Virginia Tech integrated NodeZero into its existing engineering processes.

The result:

  • Automated external pentesting through GitLab
  • Attack validation integrated into an existing engineering workflow
  • Direct routing of findings into ServiceNow
  • Clear assignment and follow-up for subnet owners
  • A repeatable process connecting testing, ownership, and remediation
  • Greater accountability across a highly decentralized environment

What You’ll Learn

  • How to operationalize pentesting across a large, federated organization
  • How the NodeZero GraphQL API enables security workflow automation
  • How Virginia Tech integrated autonomous pentesting with GitLab
  • Why routing findings directly into ServiceNow improves remediation workflows
  • How automation helps lean security teams scale external attack validation
  • How to connect security findings with the teams responsible for remediation
  • Why pentesting shouldn’t end when a report is produced

Why It Matters

Large organizations often distribute technology ownership across many teams. That makes security validation as much an operational challenge as a technical one.

At Virginia Tech, the security organization supports an environment serving more than 38,000 students, with hundreds of independent departments and infrastructure spanning Virginia, the Washington, D.C., area, major cloud providers, and public-facing assets around the world.

Generating another security report wouldn’t solve the coordination problem.

By using NodeZero as the attack validation layer between GitLab and ServiceNow, Virginia Tech created a workflow in which testing can run automatically, findings reach responsible owners, and remediation is tracked through established processes.

Testing no longer ends when the pentest does. Each run becomes part of a repeatable security operation connecting validation → ownership → remediation.

Download the customer story to see how Virginia Tech integrated NodeZero with GitLab and ServiceNow to automate external pentesting and create a repeatable path from attack validation to remediation.

Text extracted automatically; images, tables and formatting may be missing. Original: https://horizon3.ai/customer-story/virginia-tech-automated-external-pentesting/