Home icon

AWS Security Agent now supports email-based MFA for penetration testing

News



AWS Security Agent now supports email-based MFA for penetration testing, expanding coverage for applications using email verification as part of their login flow.

  • Generates unique forwarding addresses per credential to route MFA emails to the agent
  • Automatically reads forwarded messages and submits codes or links to complete authentication
  • No email account credentials stored, maintaining strong privacy posture
  • Complements existing TOTP support for unified multi-method MFA testing
  • Available in all AWS Regions where AWS Security Agent is supported

This feature enables penetration testers to comprehensively test applications previously out of scope due to email-based authentication requirements.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Mar 31
2026
AWS Security Agent on-demand penetration testing now generally available
Feb 25
2026
AWS Security Agent adds support for penetration tests on shared VPCs across AWS accounts
Mar 31
2026
AWS Security Agent on-demand penetration testing is now generally available
Mar 19
2026
AWS Security Agent now supports downloading penetration testing reports

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.