Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentests
Specialized team of AI agents that discover, attack, and validate web vulnerabilities, leveraging pre-existing site context to eliminate noise and speed remedia
Reflectiz, a continuous web exposure management company, has introduced an agentic penetration testing platform for websites. The new system utilizes specialized AI agents that discover, attack, and validate vulnerabilities across complex web environments, achieving coverage up to ten times greater than traditional pentesting tools.
Traditional pentesting is typically a one-time event, resulting in a report of the moment. However, websites undergo frequent changes, with login, checkout, and payment processes continuously targeted by attackers. These gaps in coverage pose significant security risks. Idan Cohen, CEO and co-founder of Reflectiz, explained that teams require testing that keeps pace with releases at a manageable cost, while also ensuring reliable coverage of the testing performed.
Reflectiz's agentic pentesting leverages its decade-long experience scanning thousands of production websites to create a live model of each site. This includes pages, scripts, third-party elements, domains, sensitive inputs, and behaviors. The pentesting agents then enhance this model with an attacker's perspective. A finding is presented not just as a line item but with the specific script involved, the data it can access, and whether real users are affected at the moment. This enables teams to swiftly address the issue rather than spending time on investigation.
The core of Reflectiz's technology is its engine, which has been continuously reading live websites for years, building a map of the site that other tools fail to construct. The agentic pentesting operates as a coordinated team of AI agents, each with a defined role. One agent simulates user activity like logins, one-time codes, and two-factor authentication, mapping the actual site.
Another agent identifies the application's stack and determines applicable attacks. A third agent executes these attacks and links the findings. An independent validator then verifies every finding before it is included in the report, removing false positives and providing detailed reproduction steps and evidence. This results in verified findings with clear steps for reproduction and a coverage map indicating what was tested and cleared.
The agentic pentesting fully covers the OWASP Top 10 security risks. Teams can set the depth of testing for each flow, ranging from quick predefined checks to expert-level attack chains on critical assets. Reflectiz's new Offensive Hub, which includes this agentic pentesting, joins Security Hub and Privacy Hub on the Reflectiz platform, offering a comprehensive 360° view of web risk.
This includes not just what runs on the website, what data it processes, and how it can be attacked, but also how findings from all three hubs can be cross-referenced without manual dashboard reconciliation.
Guided fixes are another key feature, with Atlas, the Reflectiz AI remediation agent, explaining each risk and guiding teams through the remediation process. Results from the agentic pentesting flow into existing workflows through a REST API, CI/CD triggers, and Slack alerts.
Reflectiz founders Idan Cohen and Ysrael Gurt will demonstrate the agentic pentesting in a live webinar scheduled for September 15 at 11 AM ET / 6 PM CET. Registration for the webinar can be found at https://www.reflectiz.com/lp/founders-case-study-webinar/. Further information about Reflectiz and its products can be found at https://www.reflectiz.com.
Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.