The SwarmHack story

SwarmHack™ takes its architecture from nature: many small specialists share state and coordinate toward one goal. A deterministic core executes and validates attacks, while optional frontier models can broaden exploration and help propose the next path.

Why the hybrid architecture works

Specialized agents keep execution focused and verifiable, run in parallel across surfaces, and let a credential discovered on a web host become an Active Directory pivot seconds later. Models can expand reconnaissance and attack hypotheses, but every proposed path returns to deterministic execution and the evidence gate.

From colony behaviour to a kill chain

In a colony, no individual holds the map. Coordination emerges from shared signals left in the environment. SwarmHack works the same way — agents write findings, credentials and host facts into shared engagement state, and a GOAP A* planner reads that state to select and order the next actions deterministically. When an action fails, the planner re-plans rather than aborting, which is exactly how a human tester behaves when an exploit does not land.

Proof as the organizing principle

The other inheritance from nature is ruthlessness about what counts. Every finding is graded Exploited, Observed, AttackPathIdentified or Simulated, and an "Exploited" claim without captured target output is downgraded automatically. The swarm is built to bring back evidence, not opinions.

See how the engine works, read how hybrid pentesting keeps an evidence gate, or explore agentic pentesting.