Tutorials / Getting Started

What is Prancer?

Prancer is an autonomous penetration-testing and continuous attack-validation platform. It plans, executes, chains, and proves real attacks across applications, APIs, identity, networks, cloud, and security controls, then tells you what an attacker actually reached and which defenses actually held.

  • * *

The platform in one picture

PRANCER
  ↓
MODEL ROUTER        selects deterministic logic or AI intelligence for each step
  ↓
SWARMHACK           PLAN → EXECUTE → PIVOT
  ↓
EVIDENCE ARCHITECTURE
  ↓
PROVEN · CONTROL-BLOCKED · UNREACHABLE

Customers use it in two ways:

  • Autonomous penetration testing covers the pentest you need, across web applications, APIs, identity, network, and cloud.
  • Continuous attack validation re-runs demonstrated attacks after change or remediation to prove the path is still closed.
  • * *

What is SwarmHack?

SwarmHack is Prancer's attack engine. It plans the next step from the current state of the engagement, executes real, authorized attack actions against the target, and pivots by using what a successful step produced (a credential, a token, a session, a new host) to test the next path.

SwarmHack is organised into capability modules across web and API, network services, Active Directory and Entra ID, cloud and containers, and other supported surfaces. Each module can run many individual attack and test variations. Module counts and variation counts measure different things, so they are not directly comparable.

What is a pivot?

A vulnerability is where an attack starts. A pivot is what happens next: using access gained in one step to reach something new.

Vulnerability → Exploit → Credential → Identity → Pivot → Security boundary → Critical asset

Prancer follows successful pivots within the authorized scope, so the result shows the real blast radius, not just the first finding.

How evidence works

The Evidence Architecture separates an attack *hypothesis* from a demonstrated *outcome*:

Hypothesis → Execution → Target response → Evidence → Verdict

Every result is assigned a verdict:

| Verdict | Meaning |

| --------- | --------- |

| Proven | The attack executed successfully and the target response was captured. |

| Control-blocked | Prancer reached a deployed security control and the control stopped the attack. |

| Unreachable | No viable path reached the target from the tested attacker position. |

If it isn't proven, it doesn't publish. Findings are backed by captured target responses, not by inference or generated prose.

Continuous validation vs. a one-time finding

A one-time finding tells you what was true on the day of the test. Prancer turns a demonstrated attack path into a repeatable test:

Attack → Prove → Remediate → Re-run the same attack → Proven closed

That moves the conversation from "we patched it" to "the attack no longer works."

Where optional AI fits

AI is optional and routed, not the foundation of every decision:

  • The Model Router can use deterministic logic, efficient models, private or local models, or, where approved and useful, frontier models to propose paths and priorities.
  • SwarmHack performs the actual execution.
  • The Evidence Architecture decides the result. A model can propose an attack; only execution evidence can prove it.

The model layer can be disabled. The evidence requirement cannot.

  • * *

Other platform capabilities

Prancer also includes established capabilities that remain available where relevant:

  • Pentest as Code (PaC), a patented framework (USPTO US-11843627-B2) for turning pentest knowledge into reusable, customizable tests.
  • Cloud posture (CSPM) and Infrastructure-as-Code scanning.
  • Integrations with Jira, ServiceNow, CI/CD pipelines, Microsoft Sentinel, Splunk, and OCSF-compatible reporting.
  • Deployment options, including SaaS, private cloud, and on-premises environments for regulated industries.
  • * *

Typical use cases

  • Autonomous penetration testing across web applications, APIs, identity, network, and cloud.
  • Security-control validation to test whether segmentation, Zero Trust, and SASE/SSE controls actually stop the attack.
  • Frontier attack validation to check whether an AI-proposed exploit actually works in your environment.
  • Post-change and post-remediation retesting.
  • Managed service delivery for MSPs and MSSPs.
  • * *

Summary

Prancer does penetration testing, goes beyond the first vulnerability, follows successful pivots, tests whether security controls stop the attack, produces evidence, and re-runs the attack after remediation.