How it works
Autonomous attack, human on the loop.
The agent does the volume and the speed. A certified operator does the judgement and the signature. Here is the full lifecycle.
-
01
Learn
The agent ingests your rules of engagement and prior findings, and builds a model of what your systems are and how they connect.
-
02
Map
It enumerates hosts, endpoints, parameters, credentials and trust relationships across the in-scope surface.
-
03
Attack
It runs and chains real techniques, adapting to what each response reveals, at a pace no manual tester can match.
-
04
Prove
For every finding it produces a working proof of concept, the exact requests and responses, and a concrete fix.
The engagement, end to end
From your rules file to a signed report.
-
01
Scope
You define targets and rules of engagement. The agent reads them like a contract: in-scope hosts, forbidden actions, rate limits, hours.
-
02
Attack
It maps the attack surface and chains real techniques: auth abuse, IDOR, SSRF, injection, cloud misconfiguration. Adaptive, not a checklist.
-
03
Prove
Every finding ships with a working proof of concept, the exact requests, and the impact. Exploitability first, CVSS second.
-
04
Sign-off
A certified operator reproduces each critical and high, cuts false positives, and signs the report. Auditors get a human name, not a model version.
Safety
Built to run against real systems.
The first question every security team asks about an autonomous attacker is what stops it going too far. The answer is the rules-of-engagement file. It is read before the engagement starts and enforced for its duration.
In-scope hosts are an allowlist, not a suggestion. Denial of service, destructive writes and bulk data exfiltration are refused outright. Rate limits and test windows are yours to set. When the agent needs to prove that data is exposed, it inspects headers or takes a small redacted sample; it never downloads the dataset.
Every critical and high finding is reproduced by hand before it reaches your report, so what you read has been seen twice: once by the agent, once by a person.
Point it at something you own.
Tell us the target and the rules. You get a scoped attack, working proofs, and a report with a name on it.