Services Partners Blog About Us
Login

Pentest AI-First

The pentest methodology that combines artificial intelligence and human expertise. Created by HackerSec.

Pentest must evolve
ahead of the adversary

For years the market sold automated pentesting as if scanners were real penetration testing. Now, other platforms promise to replace pentesters with AI. Neither is real pentest. Pentest AI-First is the model where AI accelerates and human pentesters go deeper, each doing exactly what they do best.

From scope to validated fix

Methodology structured in four main steps.

01

Scope definition

Scope is defined based on needs, attack surface and business objectives. Ensures Yaga and pentesters act exactly where it matters.

02

Yaga runs the pentest

The AI agent performs reconnaissance, real exploitations within scope, contextual target analysis and confirmed vulnerability identification.

03

Specialist validation

Every Yaga finding goes through a rigorous technical validation layer. Inconsistent signals are discarded and only relevant findings move forward.

04

Human deepening

The human pentester explores complex attack chains, evaluates business logic and investigates scenarios that require real offensive experience. Finds what AI alone wouldn't.

How AI-First sets itself apart

  Pentest AI-First Scanner / Automation
Reconnaissance Real application context List of ports and services
Exploitation Attacks adapted to environment Fixed payloads
Validation Human and technical Automated, prone to false positives
Depth Real attack chains Surface-level
Business logic Human identifies and exploits Doesn't detect

Two roles, one methodology

Yaga (AI Agent)

Runs the first offensive layer of the pentest. Speeds up recon and exploration, freeing human pentesters to act where only experience solves.

Meet Yaga

Human Pentesters

Certified specialists who validate every Yaga finding and go deeper on attack chains, business logic and complex scenarios that require human reasoning.