Manual · Automated · Agentic

Unifying Manual, Automated, and Agentic Web Security Testing Through an Intelligent Multi-Agent System

Motivation

Addressing these challenges leads to the development of an agentic system that integrates the solutions to enable faster, more reliable, and cost-efficient security agents capable of operating with both large and small language models while reducing processing overhead.The system unifies manual, automated, and agent-driven security testing within a single framework. It also supports extensibility through plugins, allowing integration with existing security platforms such as Burp Suite, Caido, and other security platforms. The system is designed around an architecture where:

Agents Are Configurable

Configure every agent to match your workflow by selecting the tools and models it can use, choosing default configurations, assigning specialized skills, defining execution limits, and deploying or undeploying agents as needed. Manage API keys for your preferred LLM providers, monitor usage, and generate integration keys for external tools such as Burp Suite, Caido, and other security platforms.

ui.gif settings.gif

Agents Are Interactive

Accelerate manual security testing with interactive agents such as Repeater Agent, designed for fast, on-demand actions. Modify and replay HTTP requests, change HTTP methods, tamper with API versions, transform request formats, and automate multiple repetitive testing tasks with a single prompt. These agents focus only on executing your instructions—they do not analyze vulnerabilities, validate findings, or make security decisions, leaving the investigation entirely under your control.

repeater.gif

Agents Are Autonomous

Delegate complex security assessments to autonomous agents such as Pentester Agent, IDOR Agent, and other specialized security agents. Assign a high-level objective like discovering IDOR vulnerabilities, authentication flaws, or injection issues, and let the agent determine the best testing strategy. Even without an explicit objective, autonomous agents can analyze the provided request or endpoint, identify potential attack surfaces, and generate their own testing plan before beginning the assessment. They continue exploring, testing, validating, and reporting findings until the objective is achieved, a stopping condition is reached, or the configured execution limits are met, allowing researchers to focus on results instead of managing every testing step.

graphql.gif cache.gif

Contexts Are Controllable

Control exactly what information agents receive during security testing by defining their request and response context. Restrict agents to specific request components such as the request line, query parameters, headers, or body, or provide access to response headers, response bodies, and metadata such as status codes, response time, and response size. Agents only analyze the selected context, allowing you to reduce noise and focus testing on the information that matters.

cors.gif

Agents Are Orchestratable

Build sophisticated security workflows by combining multiple requests and multiple agents with flexible orchestration strategies. Assign one or more agents to each request and choose whether they work sequentially, in parallel, or through hybrid execution. Multiple requests can also be tested using the same execution strategies, enabling complex assessment pipelines. With a single prompt, the Planner Agent can generate workflows that coordinate requests, assign agents, and organize execution for efficient security testing.

series.gif parallel.gif

Agents Are Schedulable

Automate security operations by scheduling agents to execute tasks at specific times or recurring intervals. Schedule one-time assessments, run recurring vulnerability checks, or launch complex workflows during off-hours. Once scheduled, agents automatically execute the assigned objectives without requiring manual intervention.

schedule.gif

Agents Are Observable

Monitor every stage of agent execution through an interactive workflow graph that visualizes how agents connect, collaborate, and progress in real time. Track execution state through live status indicators, watch vulnerabilities appear as agents discover them, pause or resume running tasks whenever needed, and inspect any agent to view its activity, current status, assigned task, and results from a single interface.

graph.gif finding.gif
Get in touch

Questions or feedback?

Reach out any time — we read every message.

[email protected]