Skip to content

Next-Generation AI-Powered Penetration Testing

AI hacks you.
Then AI proves it.

BreachAgent is an autonomous penetration testing agent. It attacks your applications, APIs and perimeter the way a human operator would, hands you a working proof of concept for every finding, and a certified pentester signs the report.

In-scope only. Rules of engagement enforced. Human-signed.

breachagent · engagement BA-2291-03 · in-scope: app.example.co.za

finding Session fixation → account takeover

  1. recon $ breachagent scope --target app.example.co.za --roe roe-2291.yaml
  2. recon 3 hosts in scope · 41 endpoints mapped · auth: cookie session
  3. map GET /login → 200 · Set-Cookie: PHPSESSID=… · rotation on auth: unknown
  4. attack $ POST /login Cookie: PHPSESSID=b7f2c9… (attacker-chosen)
  5. attack 302 → /dashboard · session id unchanged after authentication
  6. prove $ replay b7f2c9… from attacker host → GET /account/settings
  7. prove 200 · authenticated as j.mokoena@example.co.za · takeover confirmed
  8. prove impact: full account takeover via pre-set session cookie · CWE-384
  9. sign-off PoC + fix attached · reproduced by operator · signed 14:02 SAST
high CVSS 8.8 CWE-384 verified by OSCP-certified operator
10K+
Vulnerabilities discovered
99.8%
Accuracy rate
24/7
Continuous monitoring
100%
Reports human-signed

Reports map to

  • ISO 27001
  • NIST
  • GDPR
  • POPIA
  • PCI DSS

How an engagement runs

Four steps. One signed report.

No dashboards to babysit. You approve scope, the agent attacks and proves, an operator signs.

  1. 01

    Scope

    You define targets and rules of engagement. The agent reads them like a contract: in-scope hosts, forbidden actions, rate limits, hours.

    $ breachagent scope --roe roe-2291.yaml
    in-scope: 3 hosts · 41 endpoints
    forbidden: DoS, data exfil, prod writes
  2. 02

    Attack

    It maps the attack surface and chains real techniques: auth abuse, IDOR, SSRF, injection, cloud misconfiguration. Adaptive, not a checklist.

    POST /login  Cookie: PHPSESSID=b7f2c9…
    302 → /dashboard · session unchanged
    chain: fixation → takeover
  3. 03

    Prove

    Every finding ships with a working proof of concept, the exact requests, and the impact. Exploitability first, CVSS second.

    replay b7f2c9… from attacker host
    200 · authenticated as j.mokoena
    PoC attached · CWE-384
  4. 04

    Sign-off

    A certified operator reproduces each critical and high, cuts false positives, and signs the report. Auditors get a human name, not a model version.

    reproduced by operator ✓
    false positives removed: 2
    signed 14:02 SAST · report v1.0

What it does

Every layer, chained together.

Web, API, cloud and perimeter are tested as one attack surface, because that is how they get breached.

Agent + operator

AI speed. A human signature.

Autonomous testing gets you coverage. A certified person gets you a report your auditor, your board and your engineers will accept.

The agent

  • Reads the rules of engagement and stays inside them
  • Maps every reachable host, endpoint and credential path
  • Chains techniques the way a human operator would, at machine pace
  • Writes the proof of concept and the reproduction steps
  • Re-tests continuously as your perimeter changes

The operator

  • Approves scope and rules before anything runs
  • Reproduces every critical and high finding by hand
  • Removes false positives and rates business impact
  • Signs the report with a name and a certification
  • Walks your engineers through the fix

Compared

Where it sits.

Annual manual pentestVulnerability scannerBreachAgent
Time to first finding 2–6 weeks Hours Hours
Coverage Sampled, tester-dependent Broad, shallow Broad and chained
Proof of exploitability Yes, for what was sampled No — CVSS only Yes, every finding
False positives Low High Low — operator-verified
Re-test after fix Extra engagement Automatic, unverified Automatic and verified
Human sign-off Yes No Yes
Continuous No Yes Yes

What you get

A report that ends arguments.

Executive summary for the board. Requests, responses and fixes for the engineers. The same document, signed once.

  • Reproducible attack chains
  • Screenshots and payloads
  • Exploitability + CVSS
  • Specific remediation per finding
  • ISO 27001 / NIST / GDPR / POPIA mapping
  • JSON export and ticket push
breachagent · engagement BA-2291-07 · in-scope: api.example.co.za

finding IDOR on invoice API exposes customer PII

  1. recon $ breachagent scope --target api.example.co.za/v2 --auth bearer:tester
  2. map GET /v2/invoices/48213 → 200 · owner: tester (own record)
  3. attack $ GET /v2/invoices/48212
  4. attack 200 · owner ≠ tester · no object-level authorisation
  5. attack enumerating 48100–48300 (rate-limited per RoE) → 197/200 readable
  6. prove PII in scope: name, VAT no., bank account (redacted in report) · 197 records
  7. prove POPIA s19 relevance flagged · CWE-639 · fix: enforce ownership check server-side
  8. sign-off PoC + fix attached · reproduced by operator · signed 09:47 SAST
high CVSS 7.5 CWE-639 verified by OSCP-certified operator

Questions

Before you ask.

Is it safe to run against production?

The agent operates inside a rules-of-engagement file you approve: in-scope hosts, forbidden actions (denial of service, destructive writes, data exfiltration), rate limits and test windows. Anything outside the file is not attempted. Proof of concept for data exposure is done by header inspection or redacted samples, never bulk download.

What do I actually receive?

A signed report with an executive summary, each finding with its reproduction steps, requests and responses, evidence, impact, CVSS and exploitability rating, and a specific fix. Findings can also be delivered as JSON or pushed to your ticketing system.

How does human sign-off work?

A certified operator reproduces every critical and high finding before it appears in the report, removes false positives, and signs the document. If an auditor asks who tested your systems, there is a person to name.

Where is my data processed and stored?

Engagement data is processed and stored in South Africa. Findings are encrypted at rest, retained for the agreed period, and deleted on request. Details are on the Security page.

How is it priced?

Per engagement, scoped by the number of targets and attack surfaces. Continuous coverage is a subscription on the same basis. Ask for a scoped quote; there is no seat licence and no per-scan fee.

Does it replace our annual pentest?

For most compliance frameworks a signed report from a certified operator satisfies the pentest requirement. Many customers keep an annual deep-dive and use BreachAgent for continuous coverage in between.

Point it at something you own.

Tell us the target and the rules. You get a scoped attack, working proofs, and a report with a name on it.