AI agents that run the pentest.

Casco signs into approved targets, designs security tests based on what it observes, confirms exploitable vulnerabilities, and writes each finding with reproduction scripts engineers can rerun.

Approved scopeConfirmed vulnerabilitiesOptional engineer review

Casco customers

CrewAIGustoDaytonaBlaxel

Definition

What AI pentesting means.

AI pentesting uses AI agents to test an approved target. The agent observes the target, keeps track of prior responses, and chooses the next security test from what it learns.

Casco can compare approved accounts, follow application state, and change a later request based on an earlier response.

Findings include the affected resource, observed impact, fix guidance, and reproduction scripts engineers can rerun.

Test process

From approved scope to confirmed finding.

The customer defines what Casco may test. The agent then builds context, runs permitted tests, and documents results it can reproduce.

  1. 01

    Approve the targets and accounts.

    List the targets, environments, test identities, and prohibited actions before the test begins.

  2. 02

    Build context for how the target works.

    The agent uses the approved accounts and records routes, roles, objects, APIs, tools, permissions, and responses as test context.

  3. 03

    Choose and run security tests.

    The agent changes inputs, accounts, objects, and request order based on the responses it receives.

  4. 04

    Confirm the issue and write the finding.

    Casco reproduces the issue, records the affected resource and impact, and adds fix guidance plus reproduction scripts.

AI pentesting vs. other testing

How AI pentesting compares.

Scanners, manual tests, and agent-run tests work differently. This table describes the typical method used by each one.

Comparison of vulnerability scanning, manual penetration testing, and AI pentesting
CapabilityVulnerability scannerManual pentestAI pentesting
Testing logicPredefined checks and pattern matchingA tester chooses each next testAn agent chooses the next test from the response
Authenticated workflowsLimited or scriptedUses the accounts provided for the engagementCan use several approved test accounts
Business logicLimited to predefined checksTester designs application-specific testsAgent designs tests from observed behavior
CadenceContinuousPeriodic engagementScheduled or continuous
Exploit validationMay report a possible issueTester reproduces the issueAgent reproduces the issue and saves the steps
Human judgmentNot part of the toolIncluded throughout the testAvailable through Casco Supervised

Individual tools and engagements vary. Casco Supervised adds review by a Casco security engineer.

AI pentesting coverage

Systems that can share one test scope.

A scope can include a web application, its API, the cloud services behind it, and an AI agent or tool call. Each system and account must be approved for testing.

01

Web applications

Access control, authentication, injection, SSRF, session handling, file processing, and business logic.

02

APIs

Object- and function-level authorization, tenant isolation, resource controls, token handling, and unsafe API consumption.

03

Cloud infrastructure

Exposed services, internet-facing assets, identity boundaries, misconfiguration, and reachable attack paths.

04

AI systems & agents

Prompt injection, excessive agency, data exposure, tool misuse, RAG and vector risks, MCP, and agent authorization.

Testing includes OWASP Top 10, API Top 10, and LLM Top 10.

Casco uses the relevant OWASP checklists and adds tests for the roles, workflows, tools, and data in the approved target.

Test controls

The agent can test only what you approve.

The rules of engagement list the targets, accounts, environments, and prohibited actions. Casco also provides stable source IPs and request IDs for tracing its traffic.

01

Approved targets and accounts

List the domains, environments, accounts, roles, and exclusions before the test starts.

02

Traceable test traffic

Use stable source IPs and request IDs to identify Casco traffic in your own systems.

03

No DDoS or resource exhaustion

Casco does not perform DDoS or resource-exhaustion attacks. Sensitive workflows can use staging or engineer review.

04

Saved reproduction material

Keep the requests, responses, scripts, impact, and fix guidance available for engineering review.

Explore network observability

AI pentesting FAQ

Common questions about AI pentesting.

What is AI pentesting?+

AI pentesting uses AI agents: software that can observe an approved target, keep track of prior responses, and decide which security test to run next. Casco reports vulnerabilities the agent can reproduce and includes the affected resource, impact, fix guidance, and reproduction scripts.

How does AI pentesting work?+

The customer approves the targets, accounts, roles, and prohibited actions. The agent signs in, records reachable functionality, changes inputs and requests, and checks whether the result creates unauthorized access or another security impact. Confirmed findings include reproduction steps and fix guidance.

How is AI pentesting different from an automated scanner?+

A scanner runs a fixed catalogue of checks. An AI pentesting agent can change its next request based on the previous response, use several test accounts, and test sequences that depend on application state. Scanners are still useful for broad, repeatable checks.

Can AI replace a human penetration tester?+

Not in every case. Human review is still useful for unusual systems, sensitive environments, disputed impact, and formal attestation. Casco offers autonomous tests and Casco Supervised, where a security engineer reviews the scope and findings.

What can Casco AI pentesting test?+

Casco can test approved web applications, APIs, cloud infrastructure, AI applications, and agents. The exact checks depend on the targets, test accounts, documentation, integrations, and access included in the scope.

Is AI pentesting safe for production systems?+

It can be, when the scope and prohibited actions are defined correctly. Casco tests only approved targets and accounts, does not run DDoS or resource-exhaustion attacks, and can identify its traffic with stable source IPs and request IDs. Sensitive workflows can be moved to staging or reviewed by a security engineer.

Can AI pentesting reports support SOC 2 or ISO 27001?+

Casco Supervised can provide a human-reviewed report and attestation letter. Casco is a CREST-accredited penetration testing provider. Confirm the required scope and document format with the auditor before the test.

Does “AI pentesting” mean using AI to pentest or pentesting AI?+

People use the phrase both ways. Casco uses AI agents to run pentests and also tests AI applications and agents for prompt injection, tool misuse, permission failures, and data exposure.

Test an approved target

See Casco run a pentest.

Provide a target and test accounts. Casco will show how the agent uses the application, runs tests, confirms an issue, and writes the finding.

Book an AI pentest demo