Web applications
Access control, authentication, injection, SSRF, session handling, file processing, and business logic.
Casco signs into approved targets, designs security tests based on what it observes, confirms exploitable vulnerabilities, and writes each finding with reproduction scripts engineers can rerun.
Casco customers
Definition
AI pentesting uses AI agents to test an approved target. The agent observes the target, keeps track of prior responses, and chooses the next security test from what it learns.
Casco can compare approved accounts, follow application state, and change a later request based on an earlier response.
Findings include the affected resource, observed impact, fix guidance, and reproduction scripts engineers can rerun.
Test process
The customer defines what Casco may test. The agent then builds context, runs permitted tests, and documents results it can reproduce.
List the targets, environments, test identities, and prohibited actions before the test begins.
The agent uses the approved accounts and records routes, roles, objects, APIs, tools, permissions, and responses as test context.
The agent changes inputs, accounts, objects, and request order based on the responses it receives.
Casco reproduces the issue, records the affected resource and impact, and adds fix guidance plus reproduction scripts.
AI pentesting vs. other testing
Scanners, manual tests, and agent-run tests work differently. This table describes the typical method used by each one.
| Capability | Vulnerability scanner | Manual pentest | AI pentesting |
|---|---|---|---|
| Testing logic | Predefined checks and pattern matching | A tester chooses each next test | An agent chooses the next test from the response |
| Authenticated workflows | Limited or scripted | Uses the accounts provided for the engagement | Can use several approved test accounts |
| Business logic | Limited to predefined checks | Tester designs application-specific tests | Agent designs tests from observed behavior |
| Cadence | Continuous | Periodic engagement | Scheduled or continuous |
| Exploit validation | May report a possible issue | Tester reproduces the issue | Agent reproduces the issue and saves the steps |
| Human judgment | Not part of the tool | Included throughout the test | Available through Casco Supervised |
Individual tools and engagements vary. Casco Supervised adds review by a Casco security engineer.
AI pentesting coverage
A scope can include a web application, its API, the cloud services behind it, and an AI agent or tool call. Each system and account must be approved for testing.
Access control, authentication, injection, SSRF, session handling, file processing, and business logic.
Object- and function-level authorization, tenant isolation, resource controls, token handling, and unsafe API consumption.
Exposed services, internet-facing assets, identity boundaries, misconfiguration, and reachable attack paths.
Prompt injection, excessive agency, data exposure, tool misuse, RAG and vector risks, MCP, and agent authorization.
Casco uses the relevant OWASP checklists and adds tests for the roles, workflows, tools, and data in the approved target.
Published work
Read Casco security research, a customer account, and a guide to the reports produced during a pentest and retest.
Security research
7 of 16
The findings included data exposure, remote code execution, and database takeover paths. Affected founders were notified and the company names were responsibly anonymized.
Read the researchCustomer / CrewAI
“In my 15 years working in cybersecurity, Casco is the first cybersecurity product that makes security testing high-quality, fast, and easy.”
Matthew Broom, Head of Security at CrewAI
Pentest artifacts
Review the scope, finding detail, fix guidance, and remediation status that each report should contain.
Review the artifactsTest controls
The rules of engagement list the targets, accounts, environments, and prohibited actions. Casco also provides stable source IPs and request IDs for tracing its traffic.
List the domains, environments, accounts, roles, and exclusions before the test starts.
Use stable source IPs and request IDs to identify Casco traffic in your own systems.
Casco does not perform DDoS or resource-exhaustion attacks. Sensitive workflows can use staging or engineer review.
Keep the requests, responses, scripts, impact, and fix guidance available for engineering review.
AI pentesting FAQ
AI pentesting uses AI agents: software that can observe an approved target, keep track of prior responses, and decide which security test to run next. Casco reports vulnerabilities the agent can reproduce and includes the affected resource, impact, fix guidance, and reproduction scripts.
The customer approves the targets, accounts, roles, and prohibited actions. The agent signs in, records reachable functionality, changes inputs and requests, and checks whether the result creates unauthorized access or another security impact. Confirmed findings include reproduction steps and fix guidance.
A scanner runs a fixed catalogue of checks. An AI pentesting agent can change its next request based on the previous response, use several test accounts, and test sequences that depend on application state. Scanners are still useful for broad, repeatable checks.
Not in every case. Human review is still useful for unusual systems, sensitive environments, disputed impact, and formal attestation. Casco offers autonomous tests and Casco Supervised, where a security engineer reviews the scope and findings.
Casco can test approved web applications, APIs, cloud infrastructure, AI applications, and agents. The exact checks depend on the targets, test accounts, documentation, integrations, and access included in the scope.
It can be, when the scope and prohibited actions are defined correctly. Casco tests only approved targets and accounts, does not run DDoS or resource-exhaustion attacks, and can identify its traffic with stable source IPs and request IDs. Sensitive workflows can be moved to staging or reviewed by a security engineer.
Casco Supervised can provide a human-reviewed report and attestation letter. Casco is a CREST-accredited penetration testing provider. Confirm the required scope and document format with the auditor before the test.
People use the phrase both ways. Casco uses AI agents to run pentests and also tests AI applications and agents for prompt injection, tool misuse, permission failures, and data exposure.
Test an approved target
Provide a target and test accounts. Casco will show how the agent uses the application, runs tests, confirms an issue, and writes the finding.