Invicti Security launched Invicti Agentic Pentest, a new application security capability that combines autonomous AI reasoning with proof-based dynamic application security testing.
The company said the product is designed to discover, validate and report exploitable vulnerabilities in web applications and APIs, giving organizations another option for penetration testing as software teams release code more frequently.
Hybrid Testing Instead Of AI Everywhere
Invicti positioned the release as a hybrid approach. Specialized AI agents reason about application behavior, identify attack paths and adapt testing strategies, while Invicti’s DAST engine handles established vulnerability checks through deterministic validation.
That design choice matters because AI-only security testing can become expensive and inconsistent when large models are applied across every testing step. Invicti said its approach uses autonomous reasoning selectively while relying on proof-based DAST for simpler vulnerabilities.
Application Context Is The Target
Invicti said Agentic Pentest maps an application’s attack surface, analyzes authentication flows and builds a contextual understanding of application behavior before generating customized attack plans. When source code is available, the system can incorporate code-level context while still validating findings from an external attacker perspective.
The company said specialized AI agents operate in parallel across vulnerability classes including SQL injection, remote code execution, cross-site scripting, server-side request forgery, XML external entity injection, insecure deserialization, path traversal and NoSQL injection.
The Bottom Line
Invicti’s Agentic Pentest reflects the broader push to bring AI into security workflows without removing the need for validation. For enterprise security teams, the useful measure will be whether agentic pentesting can expand coverage and speed remediation while producing evidence developers can trust.

