Autonomous penetration testing for your web, API, network and cloud attack surface
Prancer Core is the flagship of the SwarmHack™ engine — a swarm of 100+ specialized security agents that maps your attack surface, exploits what it finds, moves laterally, escalates privilege, and delivers proof-graded evidence. Not a scanner. A pentester that never sleeps.
The problem
Annual pentests are a snapshot of a system that changes daily. Vulnerability scanners flood you with "criticals" that turn out to be version-match guesses no attacker could ever chain. Meanwhile the real path — the exposed web app that leads to service credentials that lead to host root that leads to your cloud keys — goes untested until a breach report finds it for you.
What Core does
- Attack-surface mapping — native port and service discovery, an intelligent web crawler (robots.txt, form analysis, SPA detection, budgeted crawl), outside-in cloud exposure mapping, and technology/version fingerprinting.
- Web and API exploitation — 24 capabilities — SQL injection with live DBMS mapping, command injection, XSS, CSRF, IDOR, SSRF, LFI, SSTI, XXE, insecure deserialization, JWT analysis, mass assignment, HTTP request smuggling and gateway/WAF bypass.
- Network and service testing — banner and handshake probes for FTP, SSH, MySQL, MSSQL and TLS, plus bounded, operator-seeded default-credential testing. Never brute force.
- Cloud, container and CI/CD — Jenkins script-console RCE, Docker Engine escape, anonymous kubelet audit, OS privilege escalation, and a full AWS IAM pivot from IMDSv2 harvest to S3 exfiltration, strictly read-then-report.
Evidence grading
Findings are graded Exploited (a real round-trip with captured target output), Observed, AttackPathIdentified, or Simulated. An Exploited label without captured output is downgraded automatically, and Critical severity is reserved for proven evidence.
What you get
OCSF 1.1.0 structured findings, Markdown reports, and self-contained interactive HTML attack-path graphs. Every finding maps to MITRE ATT&CK and rolls up against PCI-DSS 4.0, NIST CSF 2.0, OWASP Top 10 2021, SOC 2, HIPAA, ISO 27001:2022, DORA and NIS2.
Proof
In a 200-host AWS lab engagement, Core swept 18 application surfaces and returned 45 findings — 19 Exploited, 13 Critical — including the complete unauthenticated-web-RCE to service-credentials to host-root to IAM-credential-holder chain, with zero detections by the cloud provider's native threat detector. Read the engagement writeup.
Related reading
- The SwarmHack engine — the six-phase kill chain behind Core.
- Prancer Identity — Active Directory and Entra ID attack paths.
- Autonomous API security — REST and GraphQL exploitation detail.
- Cloud and container capabilities — IMDSv2, Docker escape and kubelet audit.