Agent online · 24/7 autonomous operations
Meet the XHack Agent
An autonomous AI red-team agent that hunts vulnerabilities the same way a senior offensive engineer does. Instrumented end-to-end, working alongside humans. Built for security teams and solo bug hunters alike.
24/7 autonomous
No coffee breaks
10× engineer throughput
Parallel agents
Validated findings
Uncertain cases flagged, not padded
SCROLL
Agent capabilities
What it does, on its own
Each capability is a real tool wired into the agent, not a marketing bullet. Drop a target and the agent picks the right combination, runs them in parallel, and reports.
PHASE · RECON
Autonomous reconnaissance
Subdomain enumeration, port scanning, technology fingerprinting, and OSINT: all kicked off from a single target and run in parallel by sub-agents until the attack surface is fully mapped.
PHASE · DISCOVERY
Vulnerability discovery
Nuclei templates, SQLi probes, XSS fuzzers, IDOR pattern matchers, deserialisation scanners. The agent picks the right tool, parses the output, and chains the result into the next step.
PHASE · WEAPONISE
Exploit chain building
Strings together low-severity findings into high-impact attack chains the way a senior pentester would. Surfaces the proof-of-concept, not just the CVE list.
PLATFORM · MOBILE
Mobile pentest stack
Native APK / IPA static analysis, jadx + androguard pipelines, exported-component testing via ADB, and Frida hooks for runtime instrumentation when justified.
PHASE · ENRICH
Threat-intelligence enrichment
Every finding gets cross-referenced against the latest CVE feeds, vendor advisories, and dark-web chatter, so you see exploit-in-the-wild status before you triage.
PHASE · COLLABORATE
Side-by-side with humans
The agent works in parallel with your in-house red team: handing off findings, picking up the long-tail of CVE feeds, and covering the hours nobody else can.
The full toolkit
Everything the agent brings with it
Beyond the core attack phases, the agent ships a full workbench: investigate, access it from anywhere, make your methods repeatable, and keep every finding defensible.
INVESTIGATE & HUNT
Sharper tools on the target
Cloud incident investigation
Feed it raw logs or CSV exports. It handles messy timestamps and field names, investigates on its own, and writes a verified incident report with a staged attack chain and clean IOCs. The analysis is the agent's own, not a fill-in template.
Turns raw log dumps into a trustworthy incident write-up without manual triage.
Built-in browser engine
A fast browser the agent drives in-process in a docked, multi-tab pane. It runs custom JavaScript, reads and screenshots any page, and keeps multiple isolated sessions apart, with a headless self-install on fresh servers.
No external Chrome to launch, so web testing is faster and self-contained.
Full traffic capture & Repeater
Every request and response the agent makes is captured with real headers, cookies and bodies, then replayable in the Repeater like a network tab. Edit a request, resend it, and the response updates in place.
Inspectable, replayable traffic for verifying findings and tuning payloads.
JS Hunter
Caches a target's JavaScript, surfaces secret findings and hidden endpoints, and lets you add your own, mapping client-side code into a host-to-endpoint view.
Fast recon of client-side code for keys and undocumented API routes.
ANYWHERE ACCESS
Run engagements from any screen
Web Console
A full browser interface served locally by the desktop app: live streaming chat with tool cards, inline approvals, and every panel — sub-agents, Vulnerabilities, Repeater, Cloud, Autonomous — in the browser, behind a local login.
Use the agent from any browser, with nothing in the cloud.
Installable app, desktop & phone
Install the console as an app on desktop and phone, with its own icon and window. Fully responsive, with a mobile-safe composer, safe areas, and a resizable layout.
Run engagements from a phone or tablet as a real app.
Background & concurrent chats
Turns keep running even if you close the tab. Run several chats at once, let autonomous engagements continue headless, and reopen to find everything resumed exactly where it left off.
Long pentests and autonomous runs no longer die when you navigate away.
One-word remote access
Expose the console for remote access with a single command — no long flags to remember — so a server operator gets a reachable console instantly.
Stand up a remote-accessible console on a VPS in seconds.
REPEATABLE & EXTENSIBLE
Make it yours, make it repeatable
Workflow Engine
Design attack methodologies as a visual, drag-and-drop node graph. The agent learns each one and runs it step by step inside the chat, with a live page showing exactly where it is. On web and desktop.
Repeatable, shareable methodologies instead of re-prompting the same playbook.
MCP tools & remote connections
Connect external MCP servers and tools to the agent, including remote MCP connections added straight from the web console for server operators.
Extend the agent with third-party capabilities, no code changes needed.
Pay-per-use API key
A separate pay-per-use credential the agent can use instead of your subscription, billed from credits, with model routing and automatic fallback when your plan limit is reached.
Keep working past plan limits and pay only for what you use.
TRUST & VISIBILITY
Know what it found and what it used
Stricter vulnerability findings
Findings are enforced to be complete and well-rated: CVSS v4.0 score, CWE, references, and no severity inflation.
Report-ready, defensible vulnerabilities instead of vague or inflated ones.
Usage at a glance
See your usage percentage, monthly allowance, and weekend extra right in the context line, plus a dedicated Usage tab in redesigned settings.
Always know how much of your plan you've consumed.
System stats dock
Shows the app's own CPU and RAM, plus host stats, right in the dock, for lightweight resource monitoring while the agent works.
See resource use at a glance during a run.
Reliability built in
Timed-out shell commands move to the background instead of being killed, sub-agents and tasks are scoped per chat and cleaned up with it, and Repeater replays land reliably.
Fewer lost long-running commands and cleaner session isolation.
⟡ THE ACTUAL APP
Talk to the agent. Watch it work.
One chat window, real tool calls, parallel sub-agents on the right, same UI a senior pentester uses to drive a full engagement.
XHack AI, Android Engagement (acmebank)
AGENT · v2.0.2
AGENTS · 4
LIVE
4 workers · 4 cores
Workspace · acmebank_e7a1c308
Agent architecture
From prompt to verified report
Seven stages, fully observable. Every step writes to an audit log; every finding traces back to the exact tool invocation and the human reviewer who signed off.
Prompt
User intent
Planner
LLM reasoning
Orchestrator
Sub-agents
Executor
Tools + shell
Findings
Raw evidence
Human
Triage + verify
Report
Delivered to client
Threat surface
Everything the agent looks for
The radar below maps the real categories the agent scans for, in parallel, on every engagement.
N
E
S
W
Remote Code Execution
Webshell uploads, SSRF→AWS metadata, deserialisation
Authentication bypass
JWT confusion, OAuth flows, mass-assignment, IDOR
Data exfiltration
SQLi, blind injection, exposed APIs, S3 misconfigs
Mobile-app weakness
APK secrets, exported components, SSL pinning bypass
Supply-chain risk
Dependency CVEs, exposed CI tokens, leaked .env files
Cloud misconfiguration
Open buckets, IAM over-privilege, public DBs, K8s
For everyone who hunts
Built for enterprise teams and solo bug hunters
Same agent. Different scale. Whether you're running a SOC of 50 or hunting alone, the agent multiplies what you can cover.
FOR SECURITY TEAMS
Enterprises
Augment your in-house red team with an autonomous AI that runs continuous coverage across every asset, with no extra headcount.
Continuous coverage of the full attack surface, parallel to your team
Optional managed VAPT: findings cross-checked by senior humans before delivery
Integrated with Jira, Linear, GitHub, and your existing SOC stack
SLA-backed delivery, audit trail on every action, SOC 2 ready
OR · BOTH
FOR BUG HUNTERS
Independent researchers
Your personal recon engine. Hand the agent a target and a scope; it scales your reach without replacing your judgement.
Run parallel sub-agents against every program you're testing
Mobile pentest stack built in: APK / IPA analysis, jadx, Frida, ADB
Reusable engagement workspaces with full audit log per program
Pay-as-you-hunt pricing: no enterprise minimum, no sales calls
0+
Threats eliminated
Across all client engagements
0%
Triage accuracy
Verified by senior red-team
0/7
Autonomous operations
Never sleeps, never pauses
0×
Engineer throughput
Vs. manual pentesting
Engagement flow
Four steps. Done.
From a fresh target to a delivered report: no week-long onboarding, no Statement of Work ping-pong.
STEP 01
You drop a target
URL, IP range, APK, IPA, or an entire ASN. Authorisation captured upfront; scope locked into the engagement record so the agent never strays.
STEP 02
The agent goes to work
Parallel sub-agents fan out: recon, vulnerability discovery, exploit chaining, mobile analysis, cloud audit. Every action logged in real time so you can watch it work.
STEP 03
Humans hunt alongside
Senior red-teamers run their own playbook in parallel, picking up the creative chains and business-logic flaws AI is weaker at, while AI handles the breadth. Findings from both pools get cross-checked.
STEP 04
Report delivered
Executive summary, technical writeup with PoCs, remediation steps, retest schedule. Pushed to Jira, Linear, or GitHub Issues, wherever your team lives.
Deploy your agent
Put the agent on your stack
One target. One conversation. The agent does the rest. Human red-team verifies every high-impact finding before it lands in your dashboard.
ISO 27001 · SOC 2 ready
Uncertain findings flagged, never overstated