
WYM-ACC-vedha · Autonomous Security Testing
Vedha
vedha - piercing, going through to what is inside
Authorized penetration testing on a release cadence, not a quarterly one.
Vedha is an autonomous multi-agent penetration testing platform for authorized security work. A goal is decomposed into an ordered plan, specialist agents carry out reconnaissance, discovery, and exploitation attempts inside an ephemeral sandbox, and a knowledge graph retains what has been found so later work builds on it rather than repeating it. Findings arrive as a structured report mapped to control areas. Because agents reason about whether a finding is genuinely exploitable, false positive rates fall well below signature-based scanning.
Continuous
testing cadence instead of quarterly
Reasoned
findings assessed for exploitability, not pattern-matched
Problem
Manual penetration tests cost tens of thousands and land weeks after the code has already changed, leaving a blind spot between engagements that grows with every deploy.
Outcome
Pentest-quality findings produced continuously against authorized scope, with reasoning and evidence attached to every finding.
How it works
01
Scope and authorize
A target and goal are defined against scope the customer explicitly authorizes.
02
Plan and decompose
The goal becomes an ordered set of subtasks, refined as the environment reveals itself.
03
Execute in a sandbox
Tooling runs inside an ephemeral container so the target environment is never put at risk.
04
Report with evidence
Findings are categorized by control area with severity, exploitability reasoning, and remediation.
Bill of materials
This pack composes catalog agents. Same IDs as the rest of the catalog.
Pack Architecture & Agent Composition Graph
10 Composed Agents- AGT-0237
CI/CD Build Failure Diagnosis Agent
Software Engineering
- AGT-0250
Code Completion Agent
Software Engineering
- AGT-0251
Code Review Agent
Software Engineering
- AGT-0297
Phishing Triage Agent
Cyber
- AGT-0298
SOC Alert Investigation Agent
Cyber
- AGT-0299
Threat Hunting Agent
Cyber
- AGT-0300
Insider Risk Detection Agent
Cyber
- AGT-0301
Vulnerability Prioritization Agent
Cyber
Systems · ServiceNow ITSM · Datadog · PagerDuty · Kubernetes · GitHub · Cursor · Anthropic Claude Code · Microsoft Sentinel
Modules
Goal Decomposition
A stated testing goal broken into an ordered plan of scoped subtasks.
Sandboxed Execution
Every tool and script runs inside an ephemeral container, isolated from the target environment.
Knowledge Graph Memory
Discovered assets and relationships retained across subtasks and sessions instead of rediscovered.
Structured Reporting
Findings categorized by control area with severity and remediation, ready for a compliance file.
Use cases
Continuous Security for a Fast-Moving SaaS Startup
A Series-B SaaS startup ships product updates multiple times per week. Their engineering team of 40 developers deploys microservices across AWS ECS, but they have only one part-time security engineer. Manual penetration tests are performed once a quarter by an external vendor, costing $15,000-$25,000 per engagement, and the reports arrive weeks after the code has already changed.
Pre-Compliance Penetration Testing for a Healthcare Platform
A digital health company building an electronic health records (EHR) platform must satisfy HIPAA security requirements before launching. Their compliance officer needs evidence of penetration testing to include in the security risk assessment. The company's infrastructure includes a React frontend, a Node.js/Express API, a PostgreSQL database, and an S3 bucket storing patient documents.
Red Team Simulation for a Financial Institution
A mid-size bank with 2,000 employees conducts annual red team exercises as part of its cybersecurity maturity program. The internal red team consists of three senior security engineers who manually simulate adversary tactics across the bank's external-facing infrastructure: internet banking portals, mobile API gateways, and partner integration endpoints. Each exercise takes 4-6 weeks.
Securing a University's Research Infrastructure
A large public university runs a sprawling IT environment: student portals, research lab servers, faculty intranets, IoT devices in smart buildings, and shared HPC (High-Performance Computing) clusters. The central IT security team of two people is responsible for securing all of it. They have no budget for commercial penetration testing tools and limited time for manual assessments.
DevSecOps Pipeline Integration for a Cloud- Native Company
A cloud-native company with 200 engineers operates a CI/CD pipeline deploying containerized services to Kubernetes clusters across three cloud regions. They practice \"shift-left\" security but have found that SAST/DAST scanners (Semgrep, ZAP) produce too many false positives and miss logic-level vulnerabilities. They want to add intelligent, context-aware penetration testing as a gate in their deployment pipeline.
Bug Bounty Reconnaissance Acceleration
An independent security researcher participates in bug bounty programs on platforms like HackerOne and Bugcrowd. They target large-scope programs where the attack surface includes hundreds of subdomains, APIs, and legacy applications. Reconnaissance alone subdomain enumeration, port scanning, technology fingerprinting, content discovery consumes 60-70% of their total hunting time.
Composable Architecture · Pairs well with
Accelerators that share systems of record, exchange real-time triggers, and compose with Vedha.