Agent de sécurité autonome

An AI agent that finds, and sometimes exploits, security flaws on its own, from recon to report. Instead of a human driving every step of a penetration test, the agent explores an application, forms attack hypotheses, tests them, and keeps only the vulnerabilities that are actually exploitable. In 2026, XBOW became the first non-human to reach number one on HackerOne in the US, with more than 200 zero-day flaws reported. The key to its success is not the language model but a deterministic validation step that confirms exploitability before declaring a flaw real.

Strengths

Limitations

Best for

Official site

View on Coeurdar