Skip to main content
Start with one application you want to test. This guide walks through submitting a target, running tCell, and following up on any vulnerabilities it discovers.
1

Submit a target for approval

In Settings → Targets, add your application’s hostname, such as app.example.com. A target defines what an agent is allowed to test.The Antigen team reviews every new target to confirm that your organization owns it or has permission to test it. You can check its approval status in Settings → Targets.
2

Connect your infrastructure

While your target is being reviewed, open Settings → Integrations and connect the services that support your application. For example, connect AWS for cloud resources, Vercel for deployments, or Okta for identities and permissions.These integrations build your Asset Map, a graph of your infrastructure and the relationships between its resources. Open the map to see the context available to your agents.Infrastructure connections use read-only access. You can also start with an external assessment and connect your infrastructure later. See Connecting infrastructure for setup details.
3

Run tCell

Once your target is approved, your Antigen expert can plan the engagement and run tCell, Antigen’s pre-built offensive security agent, for your team. Use Office hours in the platform sidebar or schedule a session to discuss what you want tested.Open the run in the platform to follow its progress. tCell investigates the approved target and collects evidence as it tests for vulnerabilities.To launch runs from your own code or terminal, start with the Antigen SDK or CLI.
4

Review the results

Open the run to review what tCell tested and any vulnerabilities it discovered. Each vulnerability describes the issue and its severity, with evidence showing what happened, such as HTTP requests and responses, screenshots, or exploit recordings.Vulnerabilities also appear on the Vulnerabilities page, where your team can track their status and assignment as work continues. A report summarizes an engagement and captures the relevant vulnerabilities and evidence at the time it is written.
5

Review fixes and verify deployed changes

With the default hooks enabled, a new vulnerability starts Antigen’s pre-built triage-agent. It investigates the issue and determines what is needed for remediation. When it has enough information and access, it assigns the vulnerability to the pre-built remediation-agent to prepare a fix.Connect GitHub so remediation-agent can work on the affected code and open a pull request. For infrastructure changes, it can prepare instructions for your team. If an agent needs your help, it creates a human task. Connect your messaging or issue tracking tools to receive and respond to these requests where your team works.Review the proposed changes and deploy the fix. Once it is deployed, move the vulnerability to Remediated. The default verification hook starts tCell to test the original exploit again. A successful fix moves the vulnerability to Verified; an unresolved issue returns to Open with new evidence.

Next steps

Vulnerability lifecycle

Learn how statuses, assignments, and hooks coordinate the work after discovery.

Concepts

Learn the terms used throughout the platform, SDK, and API.