Skip to main content

Start with an agent and targets

To launch an offensive run against your system, you need an agent and approved targets. Choose an agent. You can use tCell, Antigen’s pre-built security agent, or assemble your own with the Antigen SDK. Each run executes the agent you choose against the targets you provide. Define the targets. Targets are the domains or IP addresses the agent is allowed to test. Because you can start runs directly through the API, the Antigen team manually reviews and approves every new target to ensure responsible use of our cyber-capable models. You can view your targets and their approval status under Settings → Targets or query them through the API. Start the run. Your Antigen expert can plan the engagement and run tCell for your team. You can also start runs yourself through the SDK or API. In either case, the targets must be approved before testing begins. Your Asset Map provides context about the infrastructure behind those targets. It helps the agent understand connected services, resources, and identities. The map may describe more infrastructure than the agent is authorized to test; the approved targets still define the testing scope.

What happens during a run

The agent investigates the targets, tests potential weaknesses, and follows what it learns to decide what to investigate next. It can use the Asset Map to explore how a weakness in one service might affect another resource. When the agent confirms an exploitable weakness, Antigen records a vulnerability with its severity, description, and supporting evidence. Evidence can include the requests, responses, screenshots, or other artifacts that demonstrate the issue. Your team can review confirmed vulnerabilities in the platform while the run continues.

What happens to the results

A vulnerability is a record your team can track independently of the run that discovered it. Finishing the run does not close the vulnerability. Its status, assignment, and evidence can change as agents and your team work on it. A report summarizes an engagement and captures the relevant vulnerabilities and evidence at the time it is written. The report preserves those results while the vulnerabilities continue through their lifecycle.

How other agents continue the work

Discovering a vulnerability can trigger further work. Antigen uses hooks that respond to changes in a vulnerability’s status or assignment to start other agents. The vulnerability lifecycle explains these hooks, the built-in agents they trigger, and how you can connect your own agents.