The Evolution of Penetration Testing in the Era of AI

Authors

  • Errol Baloyi Council for Scientific and Industrial Research (CSIR)
  • Mpho Letshwenyo Council for Scientific and Industrial Research (CSIR) https://orcid.org/0009-0006-8792-9008
  • Mamello Mtshali Council for Scientific and Industrial Research (CSIR)
  • Alex Ramantswana Council for Scientific and Industrial Research (CSIR)

DOI:

https://doi.org/10.34190/iccws.21.1.4462

Keywords:

Artificial intelligence, Penetration testing, Cybersecurity, Vulnerability assessment

Abstract

Over the past several decades, penetration testing has transitioned from a predominantly manual, expert-driven activity to a mature discipline supported by automation, modular frameworks, and artificial intelligence (AI)-assisted tools. This study provides a descriptive review of the historical evolution of penetration testing tools, highlighting the major technological and methodological advancements that have shaped the field. In addition, a practical comparative evaluation of two widely used tools, Burp Suite Professional and the Open Worldwide Application Security Project (OWASP) Zed Attack Proxy (ZAP) was conducted using a controlled vulnerable web application, Damn Vulnerable Web Application (DVWA), to assess their performance and usability in a realistic testing environment. The study further examines the impact of AI on the contemporary and emerging landscape of penetration testing tools. The findings suggest that AI is augmenting existing tools through enhanced automation and more effective vulnerability identification, while simultaneously enabling new paradigms in both offensive and defensive cybersecurity practices. This work contributes to the understanding of the evolving role of penetration testing in an AI-influenced context and discusses the implications of these developments for researchers, practitioners, and tool developers.

Author Biographies

Errol Baloyi, Council for Scientific and Industrial Research (CSIR)

Errol Baloyi is a cybersecurity professional with a multidisciplinary background spanning the military, academia, and the research sector. He is currently a cybersecurity researcher at the Council for Scientific and Industrial Research (CSIR) and a cybersecurity instructor. He is a Certified Ethical Hacker and an Associate Member of the Institute of Commercial Forensic Practitioners (South Africa). His research interests and areas of expertise include open-source intelligence, threat intelligence, penetration testing, and digital forensics.

Mpho Letshwenyo, Council for Scientific and Industrial Research (CSIR)

Mpho Letshwenyo is a cybersecurity specialist specializing in penetration testing, vulnerability assessments, and cybersecurity governance. Her work focuses on identifying and mitigating security threats to ensure robust and secure systems. In addition to her technical expertise, she conducts cybersecurity research to stay ahead of emerging threats and industry trends. She also has a background in software development, having previously worked as a front-end developer.

Mamello Mtshali, Council for Scientific and Industrial Research (CSIR)

Mamello L. Mtshali is a Cybersecurity Researcher at the Council of Scientific and Industrial Research (CSIR). With experience in Governance, Risk, and Compliance (GRC), threat intelligence, and security operations, she plays a pivotal role in developing and reviewing cybersecurity policies and standard operating procedures (SOPs). Her work ensures organizational alignment with best practice frameworks, including ISO/IEC 27001 and NIST standards. Mamello is also a certified professional, maintaining credentials in CompTIA Security+, ISC² CC, and Microsoft SC-900.

Alex Ramantswana, Council for Scientific and Industrial Research (CSIR)

Alex Ramantswana is a Cybersecurity Specialist and researcher specializing in Penetration Testing, Digital Forensics, Security Operations and vulnerability management. Currently Alex is serving as a Cyber Security consultant at the Council for Scientific and Industrial Research supporting various private and government organizations with Cyber security services that include security monitoring, user security awareness training and the development of Cybersecurity training platforms. Alex has spent nearly a decade protecting critical infrastructure and is passionate about mentoring the next generation of security professionals and simplifying complex security concepts.

Downloads

Published

19-02-2026