REFLECTIZ has unveiled a new agentic pentesting platform for websites, pitched as delivering up to ten times more coverage than traditional pentests. The approach uses a coordinated team of specialised AI agents that start from a live, existing model of each site—covering pages, scripts, third‑party services, domains, and data flows—to identify and validate vulnerabilities with minimal noise.
The emphasis is on reproducible findings: each issue comes with the involved script, the data it could reach, and whether real users are exposed, enabling faster remediation.
The testing workflow assigns distinct agent roles: one crawls the site as a real user would, including logins and 2FA; another fingerprints the tech stack to tailor applicable attacks; a third executes and chains attacks; a fourth independently reproduces every finding to eliminate false positives. The results are presented as evidence-backed findings plus a coverage map of what was tested and cleared, spanning the full OWASP Top 10.
This agentic pentesting sits within Reflectiz’s Offensive Hub and integrates with existing workflows via REST APIs, CI/CD triggers, and Slack alerts, offering guided fixes through the Atlas remediation agent. Reflectiz notes the system maps 360° web risk by cross‑referencing outputs from Security and Privacy Hubs, providing a single exposure picture and reducing manual dashboard reconciliation.
Reflectiz plans a live demonstration by founders Idan Cohen and Ysrael Gurt on 15 September at 11:00 BST (12:00 CET).