AigentXby KomodoSec

Agentic penetration testing

AigentX learns your application before it attacks it.

AigentX tests business logic and authorization at pentest depth. Run it before a release, on a schedule, or after remediation.

New assessmentReady
Assessment type
Target
app.example.com
Identities
  • Standard user
  • Administrator
Scope
  • app.example.com/*
  • api.example.com/*
Exclusions
  • /billing/*
Testing level
Assessment runningapp.example.com
  1. Reconnaissance and discovery
  2. Mapping the environment
  3. Offensive testing
  4. Validating exploitability

Web Application·2 identities·Passive·1 exclusion

Example configuration

Reconstruction of the AigentX assessment setup.

  • Test more of what you ship
  • Retest after remediation
  • Make expert time go further

How it works

AigentX reconstructs how your application actually behaves.

app.example.com
  • /auth
  • /users
  • /orders
  • /files
  • /admin

What a standard user can reachUser-facing workflows remain reachable. Privileged paths stay closed to this identity.

Reports

Validated findings, with the path and the proof attached.

AigentX confirms exploitability before anything is reported. What reaches your team is a set of results, not a queue of candidates to triage.

  1. Assessment
  2. Validated finding
  3. Report
  4. Remediation
  5. Retest
Remediate, then AigentX replays the original attack path and reports the result.
Book a demo
Assessment report
PDFHTMLStructured
  1. 01Executive context
  2. 02Findings by severity
  3. 03Attack paths
  4. 04Evidencerequest and response
  5. 05Reproduction
  6. 06Remediation
  7. 07Retest

04Evidence — one finding, as delivered

F021 · Attacker-Controlled Coupon Amount Generates Arbitrary Credit
POST /workshop/api/shop/apply_coupon
{"coupon_code":"TRAC075","amount":500}
-> {"credit":600.0,"message":"Coupon successfully applied!"}

POST /workshop/api/shop/orders
{"product_id":1,"quantity":-1}
-> {"message":"Order sent successfully.","credit":610.0}
Reconstruction of AigentX report structure. Evidence verbatim from the published crAPI assessment.

Guardrails

AigentX runs autonomously. You set the guardrails.

You define where AigentX can operate and how far it can go. Inside those boundaries, built-in safety controls limit execution further.

Rules of engagementActive

01You define the boundaries

Testing level

Exploitation permitted where it can be demonstrated safely.

Scope
  • app.example.com/*
  • api.example.com/*
Exclusions
  • /billing/*
  • third-party.example.net
Identity

02AigentX limits itself inside them

It may reach

  • app.example.com/*reachable
  • api.example.com/*reachable
  • /billing/*reachable
  • third-party.example.netreachable
  • /admin/*reachable

It may go as far asExploitation permitted where it can be demonstrated safely.

And no further

  • Stops once the vulnerability and its impact are proven
  • Exploits only to the minimum extent a proof of concept requires
  • Blocks any action that exceeds its internal safety policy
  • Avoids unnecessary modification or deletion of existing data
  • Avoids destructive actions unless the testing level authorizes them
  • Protects service availability unless destructive testing is authorized
  • Works against data it creates itself where a test must manipulate state
Validated findingReproducible evidence attached

Change a rule and the engagement changes with it.

How you run it

Two ways to run AigentX. Same engine.

Book a demo

Managed

AigentX runs the assessment. KomodoSec penetration testers review and validate the findings before delivery.

  1. AigentX runs the assessment
  2. KomodoSec reviews and validates
  3. You receive the delivery

Self-Managed

Your team runs and manages assessments directly, with KomodoSec support available when needed.

  1. Your team runs the assessment
  2. You receive the output directly

Scale

Run it again when your applications change.

One assessment. Four operating moments. The engine and the rules stay the same.

app.example.comWeb ApplicationLast assessment complete

Findings from the last assessment

  • Broken object-level authorizationOpen
  • Authentication bypassOpen
  • Business-logic flawOpen

Revalidate only what you fixed. Everything else is left as it was.

Frequency
Assessment schedule
CompletedUpcoming
Next run—
Configuration

Web Application·2 identities·Active·1 exclusion

Progress
  1. 01
  2. 02
  3. 03
  4. 04
Not started
Report readyPDFHTMLStructured
Connection
Your delivery workflowAigentX
Change delivered · assessment started
  1. 01
  2. 02
  3. 03
  4. 04
Waiting for a change
Report readyPDFHTMLStructured
Example configuration
Reconstruction of an AigentX assessment being run again.

Built by KomodoSec

AigentX was built inside KomodoSec’s offensive-security practice, shaped by years of penetration testing, red team and application-security work. In the managed model, the people reviewing your findings do this for a living.

  • Penetration testing
  • Red team
  • Application security
AigentX
KomodoSec’s penetration testing, red team and application security practice, and the product built inside it.

Selected KomodoSec clients

  • IBM
  • AB InBev
  • Harel Insurance
  • Israel Discount Bank
  • The Phoenix
  • Cal
  • UMTB
  • SafeCharge
  • Trusteer, an IBM company
  • ezbob
  • Papa Murphy's

Evidence · Real customer environment

AigentX did not stop at Salesforce.

  1. 01

    One standard user

    A low-privilege Salesforce sales account. Nothing else supplied.

  2. 02

    The environment, mapped

    Native APIs, SOQL, custom objects, permissions and business logic.

  3. 03

    Keys inside a custom object

    Misconfigured Field-Level Security exposed plaintext cloud credentials.

  4. 04

    Out of Salesforce

    Those credentials authenticated to the connected cloud infrastructure.

    The request that crossed

    GET /services/data/v56.0/query?q=SELECT Id,Name,██ FROM ██AWS__Settings__c

    returned

    AKIA████████████ · eu-central-1

    Plaintext cloud credentials, readable by a standard sales user.

Attack path: a low-privilege Salesforce user maps the environment, recovers cloud credentials from a custom object, and crosses out of Salesforce into the organization’s connected cloud infrastructure.

Public technical assessment

We published the entire assessment.

47
endpoints tested
37
validated findings
7
proven attack chains

Including root compromise, zero-credential account takeover and unlimited credit generation.

Read the assessment

Evaluate AigentX

Give AigentX a target you already know.

Point it at an application your team has already tested, and compare what comes back.

We use these details to arrange your session and nothing else. See theprivacy policy.

Submitting this form needs JavaScript. With it switched off, please reach us through komodosec.com/contact.