100+ specialized agents. One binary. Proof-graded findings.

SwarmHack plans its own attack path, exploits what it finds, moves laterally, escalates privileges, harvests crown jewels, and delivers OCSF-structured evidence — all inside a signed authorization envelope.

The six-phase kill chain

PortDiscovery → Recon → Discovery → Exploitation → PostExploit → Collection, dispatched across a web lane (crawler, auth testing, ~22 deep vulnerability scanners, each exploiting inline) and a six-pass network lane (anonymous discovery → credential production → authenticated re-enum → authenticated exploitation → lateral movement → domain dominance). A GOAP A* planner selects and orders actions deterministically; failed actions replan.

Evidence-graded findings

Every finding carries one of four grades — Exploited, Observed, AttackPathIdentified, or Simulated. Critical severity is reserved for proven evidence; an "Exploited" label without captured output is downgraded automatically. Findings reach the published report only if they carry a crown jewel or are genuinely Exploited.

Capability breadth

85 registered plugins, 102 agent capabilities across web and API (24), network services, Active Directory and Windows identity (21+), cloud/container/CI-CD, Secure Service Edge validation (23), and RoboSec (9).

Live-fire proof point

A 200-host AWS lab engagement: 18 application surfaces, 45 findings, 19 Exploited, 13 Critical, unauth web RCE → service credentials → host root → IAM credential holder — with zero cloud-native attack detections. Read the engagement.

Outputs include OCSF 1.1.0 JSON, interactive HTML attack graphs, Markdown, DOT/Cytoscape/Neo4j, with compliance rollups for PCI DSS 4.0, NIST CSF 2.0, OWASP Top 10 2021, SOC 2, HIPAA, ISO 27001:2022, DORA, and NIS2. Book a demo.