XBOW Product Demo: How to Run an Autonomous Penetration Test
From Pentest Setup to Validated Vulnerabilities
In this 5-minute demo, XBOW Chief Information Security Officer Nico Waisman walks through how security teams can configure, launch, and review an autonomous penetration test using the XBOW platform.
The demonstration begins with assessment setup. Teams can run a full penetration test, an incremental assessment focused on changes since a previous test, or a retest of previously identified vulnerabilities. With a live environment as the primary requirement, teams can add credentials for authenticated testing, provide source code for white-box testing, or supply additional context such as API specifications, developer documentation, and previous pentest results.
Nico also demonstrates the controls available for defining how an assessment operates. Teams can specify testing windows and request rates, while a pre-flight check validates application reachability and credentials before identifying associated domains and subdomains. These can then be explicitly placed in or out of scope before testing begins.
Once an assessment is running, XBOW provides visibility into the activity performed by its autonomous agents. Teams can inspect requests and responses, group activity by attack, and review a detailed record of what occurred throughout the penetration test.
The demo then moves into vulnerability findings. Each validated finding includes a description, impact, mitigation guidance, and reproducible proof of concept showing engineers how XBOW successfully exploited the vulnerability. Rather than simply reporting a potential weakness, XBOW provides evidence that teams can use to reproduce and verify the issue.
Nico demonstrates this with an IDOR vulnerability discovered by XBOW. By manipulating an identifier, XBOW was able to access other users' billing and shipping address information, providing evidence of the vulnerability's real-world impact.
The demonstration closes with a deeper look at the attack chain behind the finding. Detailed traces show the actions performed by XBOW's autonomous agents and the resulting outputs as they navigate the application, test different approaches, and ultimately achieve exploitation. This provides security teams with both validated findings and detailed visibility into how those findings were discovered.