Autonomous pentesting tools have matured to the point where they can reliably find vulnerabilities, but finding vulnerabilities is not the same as doing a professional pentest. Bug bounty hunting optimizes for high-severity impact while a client engagement requires systematic coverage against a framework, with every control checked.
In this talk we will explore how we designed an internal solution that layers the OWASP ASVS framework on top of existing agentic testing products. We will cover what we put in place to get reliable results, the guardrails we designed to ensure safe behavior in client environments, and how our harness improves the coverage of agentic testing solutions.
Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/