> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/penetorshontesuto/configure-a-pentest/starting-an-assessment.md).

# ペネトストの設定方法

ペンテストの準備に、何週間もメールをやり取りしたり、複雑なスコープ文書を作成したりする必要はありません。Aikidoならプロセスが効率化されるため、監査の準備中でも、セキュリティ態勢を強化したいだけでも、すぐに評価を開始できます。

### 前提条件

開始する前に、以下が揃っていることを確認してください：

* **ペンテストの管理** [権限](/docs/docs-ja/hajimeni/automated-user-management/setting-roles-and-permissions.md) Aikidoで
* **十分なクレジット** あなたの [ウォレット](/docs/docs-ja/miscellaneous-info/wallet-and-credits.md).
* **認可** を対象ドメインに対してスキャンする。

ウィザードを起動するには、次へ移動します **ペンテスト** Aikidoで、次を開きます **プロジェクト** に移動し、 **評価を作成**.

{% stepper %}
{% step %}

### アプリケーションの種類を選択

テストしたいアプリケーションの種類を選択します。Androidアプリの場合は、 **Android** を選択し、 [Androidアプリのペンテスト](/docs/docs-ja/penetorshontesuto/configure-a-pentest/android-pentesting.md).
{% endstep %}

{% step %}

### スコープを定義する

レポートの実用性を高めるため、1回の評価につき1つのアプリケーションに絞ることを推奨します。

{% hint style="warning" %}
**テスト環境を使用する：** ペンテストには破壊的な操作が伴います。ダウンタイムやデータ破損を避けるため、評価は常にステージングまたはQA環境で実行してください。
{% endhint %}

1. **ドメインを入力：** アプリケーションのURLを入力してください。
2. **スコープ：** アプリケーション全体をテストするか、テストの重点を置く場所を具体的に指示します。

<div data-with-frame="true"><figure><img src="/files/e51f43d91f12314cb4f604a15e9997c054e74379" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}

### 検出されたドメインを確認する

システムは依存関係（例：認証サービス、APIゲートウェイ、…）を検出します。

* **ドメインを追加して次のようにマークします** `対象内` をペンテストに含める。
* **ドメインを追加して次のようにマークします** `到達を許可` 使用は許可するが、ペンテスト対象からは除外する。
* **ブロック済み：** 定義されていないものは、安全のためデフォルトでブロックされます。

<div data-with-frame="true"><figure><img src="/files/46f916c00e02bee681cf5373e18e801a72db5077" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}

### 認証

AikidoはAIエージェントを使用して複雑なログインフローをナビゲートします。複雑なスクリプトは不要です。ログイン方法を教えてください。

* **ロールを定義：** 異なるユーザータイプ向けの資格情報セットを作成します（例： `管理者`, `テナントAのユーザー`, `読み取り専用ユーザー`）。これにより、認証だけでなく認可ロジックもテストできるようになります。
* **手順を記述：** 平易な英語で記述してください。

  > *例：「/admin に移動。ユーザー 'admin' とパスワード '1234' でログイン。2FAプロンプトが表示された場合は、提供されたOTPシークレットを使用してください。」*
* **セルフ登録：** アプリが公開サインアップを許可している場合、エージェントが自分でアカウントを作成できます。

<div data-with-frame="true"><figure><img src="/files/7cdf49fa71c76351ca3f779e7d2b91cf15735b94" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}

### コードとドキュメント

ホワイトボックステストは、深いロジックを分析する能力を大幅に高め、重要な問題を見落とすリスクを下げます。より詳細な情報 [こちら](/docs/docs-ja/penetorshontesuto/configure-a-pentest/leveraging-code-and-documentation.md).

* **リポジトリをリンク：** コードリポジトリを接続してください。コードベースをインデックス化し、外部からは見えないロジック上の欠陥を特定します。
* **仕様をアップロード：** OpenAPI/Swaggerの仕様書や過去のペンテストレポートを添付して、スキャナーを既知の機密領域へ導きます。
* **追加コンテキスト：** アプリケーションの挙動を理解するのに役立つ追加情報を提供してください。

<div data-with-frame="true"><figure><img src="/files/b84e9ca2e3d080ccd5396d0141c62889efa78877" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}

### 安全性

ペンテストは負荷が高くなることがあります。サービスの劣化を防ぐため、これらの設定を構成してください。

* **1秒あたりの最大リクエスト数：**
  * **高：** より早く完了するが、サーバー負荷は高くなります。
  * **低：** より遅いですが、システムへの負荷はより穏やかです。
* **許可されたスキャン時間：** 他の作業への影響を避けるため、ペンテストを特定の時間帯に制限します。

<div data-with-frame="true"><figure><img src="/files/7791fb9d74357637bdd09cba9c6979f5723e45a1" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}

### 評価タイプを選択

目的に合った評価プロファイルを選択してください。

* **標準ペンテスト：** 1つのアプリケーションとその主要APIを対象とした、固定価格の一般的な時間制限付き評価です。
* **適正規模ペンテスト：** アプリケーションのセキュリティ関連箇所をすべてカバーするための、当社推奨の方法です。Aikidoがアプリケーションのスコープと複雑さに合わせて評価規模を調整します。

参照: [ペンテストの料金](https://github.com/AikidoSec/docs/tree/main/pentests/configure-a-pentest/pentest-pricing.md) 価格の詳細と固定ティアの参考情報については、
{% endstep %}

{% step %}

### 概要と開始

設定を確認し、 **評価を実行** をクリックしてスキャンを開始します。

* **キャンセルポリシー：** 実行中にミスに気づいたり、何か問題が発生したりした場合は、開始直後にキャンセルできます。
  * *注意：早期にキャンセルされた場合、クレジットは自動的に返金されます。*
    {% endstep %}
    {% endstepper %}

### サポートが必要ですか？

スキャナーが認証できない場合、またはスコープ設定に不安がある場合は、次を開いてください **Intercomチャット** 右下隅のものを開いてください。私たちのチームがお手伝いします！


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/penetorshontesuto/configure-a-pentest/starting-an-assessment.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
