Skip to content

Web Deep Agentic Scan

The Web Deep Agentic Scan provides AI-powered penetration testing that uncovers complex logical flaws, chains multiple vulnerabilities into sophisticated attack paths, and validates findings through proof-of-concept exploits to confirm real-world impact on your web applications. With enhanced Vulnerability Chaining and Risk Prioritization, the agent helps identify relationships between weaknesses to uncover critical attack paths.

To create a Web Deep Agentic Scan:

  1. Click the "Hamburger" menu icon. Hamburger Menu Icon

  2. Click on "Scanning". Scanning Menu

  3. Navigate to the scan page by clicking "New Scan". New Scan Menu Item

  4. Enter a name for your scan in the "Title" field. This field is optional. Select Store

  5. Select either "Web App" or "Web API". Select Source

  6. Specify the target URLs / domains. Click "Continue". Specify the target

  7. Select "Web Deep Agentic Scan" as the scan type. At this point, you can create the scan by clicking "Submit" or you can choose to provide specific instructions for the Deep Scan to focus on particular areas of the web application. To do this, click on "Continue". Select Scan Plan

  8. Select the testing duration for your scan using the "Testing Depth" option, ranging from focused 1-week assessments to comprehensive 8-week penetration tests. Next, configure the AI model. You can select an Ostorlab-managed "Cyber Model" for immediate testing without managing API keys, or select one of your configured "BYOK" (Bring Your Own Key) API keys for this Agentic Deep Scan, or create a new one by clicking "ADD API KEY". Select BYOK Key

  9. Select or add new test credentials to enable the Agentic Deep Scan to perform authenticated testing. After selecting or adding the desired credentials, click on "Continue". Test Credentials

  10. Optionally provide SBOM or lock files for extended dependency detection. Click "Continue". Provide SBOM or Lock files

  11. Prompts allow you to guide the Deep Scan on what to test. You can select from existing prompts or create your own by clicking on "+ Prompt". After selecting or adding the desired prompts, click on "Continue". Select or Add Prompts

  12. You can configure advanced settings like the Queries Per Second (QPS), Proxy, and Filter URL regex (allows you to exclude specific URLs from being scanned). Click on "Submit" to start the scan. Configure advanced settings

  13. Click on "Show" to see the scan. Inside the scan results, you can explore the Transparent Attack Validation paths to see the exact decisions, tool outputs, and steps taken by the AI agent to validate vulnerabilities.

    You can also open the Scan Coverage Heatmap, which provides a visual view of testing coverage across application components and security categories. This helps teams understand which areas of the application received deeper analysis, where coverage was limited, and how coverage evolves across assessments.

    Scan Coverage Heatmap

    Note: Historical Scan Processing is enabled by default. The scanner remembers previous findings and validated attack paths, focusing subsequent scans on new or changed functionality for cumulative, incremental coverage.

This tutorial demonstrated how to create a Web Deep Agentic Scan for Web Apps and APIs.