1
Submit a target for approval
In Settings → Targets, add your application’s hostname, such as
app.example.com.
A target defines what an agent is allowed to test.The Antigen team reviews every new target to confirm that your organization owns it
or has permission to test it. You can check its approval status in Settings → Targets.2
Connect your infrastructure
While your target is being reviewed, open Settings → Integrations and connect the
services that support your application. For example, connect AWS for cloud resources,
Vercel for deployments, or Okta for identities and permissions.These integrations build your Asset Map, a graph of your infrastructure
and the relationships between its resources. Open the map to see the context available
to your agents.Infrastructure connections use read-only access. You can also start with an external
assessment and connect your infrastructure later. See Connecting infrastructure
for setup details.
3
Run tCell
Once your target is approved, your Antigen expert can plan the engagement and run
tCell, Antigen’s pre-built offensive security agent, for your team.
Use Office hours in the platform sidebar or schedule a session
to discuss what you want tested.Open the run in the platform to follow its progress. tCell investigates the approved
target and collects evidence as it tests for vulnerabilities.To launch runs from your own code or terminal, start with the Antigen SDK
or CLI.
4
Review the results
Open the run to review what tCell tested and any vulnerabilities it discovered.
Each vulnerability describes the issue and its severity,
with evidence showing what happened, such as HTTP requests and
responses, screenshots, or exploit recordings.Vulnerabilities also appear on the Vulnerabilities page, where your team can
track their status and assignment as work continues. A report
summarizes an engagement and captures the relevant vulnerabilities and evidence
at the time it is written.
5
Review fixes and verify deployed changes
With the default hooks enabled, a new vulnerability starts Antigen’s pre-built
triage-agent. It investigates the issue and determines what is needed for
remediation. When it has enough information and access, it assigns the vulnerability
to the pre-built remediation-agent to prepare a fix.Connect GitHub so remediation-agent
can work on the affected code and open a pull request. For infrastructure changes,
it can prepare instructions for your team. If an agent needs your help, it creates
a human task. Connect your messaging or issue tracking tools
to receive and respond to these requests where your team works.Review the proposed changes and deploy the fix. Once it is deployed, move the
vulnerability to Remediated. The default verification hook starts tCell to
test the original exploit again. A successful fix moves the vulnerability to
Verified; an unresolved issue returns to Open with new evidence.
Next steps
Vulnerability lifecycle
Learn how statuses, assignments, and hooks coordinate the work after discovery.
Concepts
Learn the terms used throughout the platform, SDK, and API.