Next-Generation AI-Powered Penetration Testing
AI hacks you.
Then AI proves it.
BreachAgent is an autonomous penetration testing agent. It attacks your applications, APIs and perimeter the way a human operator would, hands you a working proof of concept for every finding, and a certified pentester signs the report.
In-scope only. Rules of engagement enforced. Human-signed.
finding Session fixation → account takeover
- recon $ breachagent scope --target app.example.co.za --roe roe-2291.yaml
- recon 3 hosts in scope · 41 endpoints mapped · auth: cookie session
- map GET /login → 200 · Set-Cookie: PHPSESSID=… · rotation on auth: unknown
- attack $ POST /login Cookie: PHPSESSID=b7f2c9… (attacker-chosen)
- attack 302 → /dashboard · session id unchanged after authentication
- prove $ replay b7f2c9… from attacker host → GET /account/settings
- prove 200 · authenticated as j.mokoena@example.co.za · takeover confirmed
- prove impact: full account takeover via pre-set session cookie · CWE-384
- sign-off PoC + fix attached · reproduced by operator · signed 14:02 SAST
- 10K+
- Vulnerabilities discovered
- 99.8%
- Accuracy rate
- 24/7
- Continuous monitoring
- 100%
- Reports human-signed
Reports map to
- ISO 27001
- NIST
- GDPR
- POPIA
- PCI DSS
How an engagement runs
Four steps. One signed report.
No dashboards to babysit. You approve scope, the agent attacks and proves, an operator signs.
-
01
Scope
You define targets and rules of engagement. The agent reads them like a contract: in-scope hosts, forbidden actions, rate limits, hours.
$ breachagent scope --roe roe-2291.yaml in-scope: 3 hosts · 41 endpoints forbidden: DoS, data exfil, prod writes -
02
Attack
It maps the attack surface and chains real techniques: auth abuse, IDOR, SSRF, injection, cloud misconfiguration. Adaptive, not a checklist.
POST /login Cookie: PHPSESSID=b7f2c9… 302 → /dashboard · session unchanged chain: fixation → takeover -
03
Prove
Every finding ships with a working proof of concept, the exact requests, and the impact. Exploitability first, CVSS second.
replay b7f2c9… from attacker host 200 · authenticated as j.mokoena PoC attached · CWE-384 -
04
Sign-off
A certified operator reproduces each critical and high, cuts false positives, and signs the report. Auditors get a human name, not a model version.
reproduced by operator ✓ false positives removed: 2 signed 14:02 SAST · report v1.0
What it does
Every layer, chained together.
Web, API, cloud and perimeter are tested as one attack surface, because that is how they get breached.
-
Attack surface mapping
Domains, subdomains, exposed services, leaked credentials and forgotten assets, correlated so you see one picture instead of 40 000 scanner lines.
-
Live fingerprinting
Continuous watch on perimeter changes: new ports, certificates, cloud buckets and deployments, matched against known attack paths as they appear.
-
Exploit path validation
Safe, rules-bound exploit chains for RCE, IDOR, SSRF, auth flaws and more. Prioritised by what is exploitable today, not by a score.
-
Reports people can act on
Executive summary and technical detail in one document: reproducible chains, screenshots, payloads, fixes, and mapping to ISO 27001, NIST, GDPR and POPIA.
-
Adaptive threat modelling
Techniques evolve with your stack and with the adversary. What worked last quarter is re-tested; what is new is tried first.
-
Every layer
Web apps and APIs, cloud, VPN and perimeter, external endpoints. One engagement, one rules file, one signed report.
Agent + operator
AI speed. A human signature.
Autonomous testing gets you coverage. A certified person gets you a report your auditor, your board and your engineers will accept.
The agent
- Reads the rules of engagement and stays inside them
- Maps every reachable host, endpoint and credential path
- Chains techniques the way a human operator would, at machine pace
- Writes the proof of concept and the reproduction steps
- Re-tests continuously as your perimeter changes
The operator
- Approves scope and rules before anything runs
- Reproduces every critical and high finding by hand
- Removes false positives and rates business impact
- Signs the report with a name and a certification
- Walks your engineers through the fix
Compared
Where it sits.
| Annual manual pentest | Vulnerability scanner | BreachAgent | |
|---|---|---|---|
| Time to first finding | 2–6 weeks | Hours | Hours |
| Coverage | Sampled, tester-dependent | Broad, shallow | Broad and chained |
| Proof of exploitability | Yes, for what was sampled | No — CVSS only | Yes, every finding |
| False positives | Low | High | Low — operator-verified |
| Re-test after fix | Extra engagement | Automatic, unverified | Automatic and verified |
| Human sign-off | Yes | No | Yes |
| Continuous | No | Yes | Yes |
What you get
A report that ends arguments.
Executive summary for the board. Requests, responses and fixes for the engineers. The same document, signed once.
- Reproducible attack chains
- Screenshots and payloads
- Exploitability + CVSS
- Specific remediation per finding
- ISO 27001 / NIST / GDPR / POPIA mapping
- JSON export and ticket push
finding IDOR on invoice API exposes customer PII
- recon $ breachagent scope --target api.example.co.za/v2 --auth bearer:tester
- map GET /v2/invoices/48213 → 200 · owner: tester (own record)
- attack $ GET /v2/invoices/48212
- attack 200 · owner ≠ tester · no object-level authorisation
- attack enumerating 48100–48300 (rate-limited per RoE) → 197/200 readable
- prove PII in scope: name, VAT no., bank account (redacted in report) · 197 records
- prove POPIA s19 relevance flagged · CWE-639 · fix: enforce ownership check server-side
- sign-off PoC + fix attached · reproduced by operator · signed 09:47 SAST
Questions
Before you ask.
Is it safe to run against production?
The agent operates inside a rules-of-engagement file you approve: in-scope hosts, forbidden actions (denial of service, destructive writes, data exfiltration), rate limits and test windows. Anything outside the file is not attempted. Proof of concept for data exposure is done by header inspection or redacted samples, never bulk download.
What do I actually receive?
A signed report with an executive summary, each finding with its reproduction steps, requests and responses, evidence, impact, CVSS and exploitability rating, and a specific fix. Findings can also be delivered as JSON or pushed to your ticketing system.
How does human sign-off work?
A certified operator reproduces every critical and high finding before it appears in the report, removes false positives, and signs the document. If an auditor asks who tested your systems, there is a person to name.
Where is my data processed and stored?
Engagement data is processed and stored in South Africa. Findings are encrypted at rest, retained for the agreed period, and deleted on request. Details are on the Security page.
How is it priced?
Per engagement, scoped by the number of targets and attack surfaces. Continuous coverage is a subscription on the same basis. Ask for a scoped quote; there is no seat licence and no per-scan fee.
Does it replace our annual pentest?
For most compliance frameworks a signed report from a certified operator satisfies the pentest requirement. Many customers keep an annual deep-dive and use BreachAgent for continuous coverage in between.
Point it at something you own.
Tell us the target and the rules. You get a scoped attack, working proofs, and a report with a name on it.