The reason internal testing is usually a once-a-year consulting engagement is that it can break things. Umbra makes that a setting rather than a leap of faith.
Read-only enumeration and configuration checks. Nothing writes, nothing authenticates repeatedly, nothing that could lock an account. Run it on a Tuesday afternoon.
Adds authenticated checks and controlled credential testing, with lockout-aware pacing — the techniques that touch account state are deliberately bounded, because a security assessment that locks out the finance department is not a security assessment.
Full exploitation attempts where a real proof requires them. For a maintenance window, a lab, or a segment you are willing to disturb.
Not a category list. These are the identifiers the agent dispatches, read straight out of its source, so you can see exactly what it does before you install it. The agent's proxy transport is dispatched by the same switch and is left out — it is how the techniques reach a host, not a technique.
Enumeration produces enormous volume. What makes it useful is the same thing that makes the rest of Umbra useful: a finding has to survive validation before it reaches you, and it arrives with the evidence that convinced the validator.
Read how that works on{" "} exploit validation .
Internal pentest is part of the Standard plan and above — not a separate SKU, not a per-assessment charge.
Part of{" "} continuous security validation {" "} — discover, prove, fix, re-test.