Skip to content
Back to the catalog
Authorized security probes assessing a defended perimeter

WYM-ACC-vedha · Autonomous Security Testing

Vedha

vedha - piercing, going through to what is inside

Authorized penetration testing on a release cadence, not a quarterly one.

Vedha is an autonomous multi-agent penetration testing platform for authorized security work. A goal is decomposed into an ordered plan, specialist agents carry out reconnaissance, discovery, and exploitation attempts inside an ephemeral sandbox, and a knowledge graph retains what has been found so later work builds on it rather than repeating it. Findings arrive as a structured report mapped to control areas. Because agents reason about whether a finding is genuinely exploitable, false positive rates fall well below signature-based scanning.

Continuous

testing cadence instead of quarterly

Reasoned

findings assessed for exploitability, not pattern-matched

Problem

Manual penetration tests cost tens of thousands and land weeks after the code has already changed, leaving a blind spot between engagements that grows with every deploy.

Outcome

Pentest-quality findings produced continuously against authorized scope, with reasoning and evidence attached to every finding.

How it works

  1. 01

    Scope and authorize

    A target and goal are defined against scope the customer explicitly authorizes.

  2. 02

    Plan and decompose

    The goal becomes an ordered set of subtasks, refined as the environment reveals itself.

  3. 03

    Execute in a sandbox

    Tooling runs inside an ephemeral container so the target environment is never put at risk.

  4. 04

    Report with evidence

    Findings are categorized by control area with severity, exploitability reasoning, and remediation.

Bill of materials

This pack composes catalog agents. Same IDs as the rest of the catalog.

Systems · ServiceNow ITSM · Datadog · PagerDuty · Kubernetes · GitHub · Cursor · Anthropic Claude Code · Microsoft Sentinel

Modules

  • Goal Decomposition

    A stated testing goal broken into an ordered plan of scoped subtasks.

  • Sandboxed Execution

    Every tool and script runs inside an ephemeral container, isolated from the target environment.

  • Knowledge Graph Memory

    Discovered assets and relationships retained across subtasks and sessions instead of rediscovered.

  • Structured Reporting

    Findings categorized by control area with severity and remediation, ready for a compliance file.

Use cases

Composable Architecture · Pairs well with

Accelerators that share systems of record, exchange real-time triggers, and compose with Vedha.