Skip to main content

Get Started

Antigen Documentation

Antigen runs cybersecurity agents that attack your infrastructure, investigate vulnerabilities, and prepare fixes. Your team reviews the results and proposed changes in the platform or through connected tools.

How Antigen works

Asset Map

Connect your services, resources, and identities in one Asset Map. Agents use their relationships to understand your environment.

Attack with tCell

Run Antigen’s pre-built offensive security agent against approved targets. It attempts to exploit weaknesses in your system and creates vulnerabilities with evidence when it succeeds.

Act on vulnerabilities

Agents investigate vulnerabilities and prepare fixes for review. Your team deploys the changes, then tCell tests whether they resolved the issue.

Follow the work

A vulnerability keeps its evidence and work history as agents investigate it, prepare a fix, and verify the deployed change. Hooks start the next step when its status or assignment changes.

Vulnerability lifecycle

Follow how triage, remediation, and verification work together, and configure the hooks that launch your agents.

Team workflows

When an agent needs access, a review, or a decision, it creates a human task. Receive these requests in your team’s messaging and issue tracking tools.

Build with Antigen

The Antigen team assembles its pre-built agents with the same SDK available to your team. Extend an agent or assemble your own, then use hooks to connect it to your workflows. You can also query your Asset Map and work with vulnerabilities, evidence, and human tasks from your own applications.

Antigen SDK

Assemble agents and work with Antigen from TypeScript.

CLI

Start runs and inspect results from your terminal or CI pipeline.

API reference

Find endpoints, request parameters, and response schemas.
For a guide to the terms used throughout these docs, see Concepts.