Methodology
How RedPick works
RedPick runs a full six-phase penetration testing methodology, not a vulnerability scanner. Specialist AI agents verify every finding with a working exploit.
Agentic AI, not rules
RedPick does not follow scripts. It reasons about your application, plans attack paths, and adapts in real time, like an experienced pentester would.
Full-stack coverage
Web, mobile, API, desktop, LLM. One platform, every application type, including AI-powered features other tools ignore.
Black-box by default
No source code, no credentials, no setup. RedPick tests from the outside, exactly like a real attacker would.
Chained exploits
A low-severity IDOR alone might be acceptable. Combined with an SSRF and a privilege escalation? Critical. RedPick chains findings into real attack scenarios.
A real methodology
Scanners run a checklist. RedPick runs an assessment.
Vulnerability scanners run a checklist and dump results. RedPick executes a complete penetration testing methodology, the same approach a senior human pentester follows, from understanding the target to delivering verified findings.
Scanners
- Give you alerts
- Report what looks suspicious
- Stop at detection
RedPick
- Gives you proven vulnerabilities
- Proves what is exploitable
- Verifies, chains, and explains
The six-phase approach
From understanding the target to verified findings.
Context and reconnaissance
Before testing a single endpoint, RedPick spends time understanding your application, just like a human pentester would on day one.
- Technology stack identification (frameworks, servers, databases)
- Authentication mechanism mapping
- API architecture analysis
- WAF and security control detection
Discovery and mapping
Every endpoint, every parameter, every JavaScript file is catalogued. RedPick builds a comprehensive map of your application's attack surface.
- Authenticated crawling across all user roles
- API endpoint discovery (REST, GraphQL, SOAP)
- JavaScript analysis for hidden endpoints and API keys
- Parameter discovery and classification
Agentic scanning
AI-driven checks against thousands of known vulnerability patterns, misconfigurations, and exposures, calibrated to your specific tech stack.
- CVE and known exposure detection
- Misconfiguration analysis
- Web server and TLS assessment
- Results deduplicated and validated before proceeding
Intelligent testing
This is where RedPick diverges from traditional scanners. Specialist AI agents test across 17 core vulnerability categories in parallel, each an expert in its domain.
- Injection (SQL, XSS, template injection, command injection)
- Authentication and session management (JWT, OAuth, sessions)
- Access control (IDOR, authorization bypass, privilege escalation)
- Business logic (workflow bypass, race conditions, payment manipulation)
- Server-side request forgery (SSRF)
- Infrastructure (request smuggling, cache poisoning)
Multi-model AI, one mission
Most AI security tools rely on a single model. RedPick deploys multiple independent AI engines, each bringing different reasoning strengths. They do not just run in parallel; they challenge each other's conclusions.
- A primary engine handles live attack execution, deep business logic reasoning, and exploit verification
- Secondary engines provide independent analysis and open new attack angles when the primary stalls
- Every finding passes through multiple engines before confirmation
Verification
This is the phase that eliminates false positives. No working exploit, no finding. No real evidence, no report.
- Every potential finding is verified with a working proof-of-concept
- Complete HTTP request and response pairs are captured as evidence
- Baseline comparisons confirm the vulnerability is real
- Any testing artifacts (stored payloads, uploaded files) are cleaned up
What makes this different
Verification-first
Zero false positives. Every finding has a working proof-of-concept. Your development team fixes real vulnerabilities, not scanner noise.
Specialist agents
Not one monolithic scanner running every check. Specialist AI agents, each an expert in its vulnerability domain, working in parallel across your entire application.
Continuous, not annual
Run on every deployment. Integrate into your CI/CD pipeline. Security testing that moves at the speed of your development.
Safe for production
Designed for production-safe testing.
The most common concern is whether testing will break a production environment. RedPick is built to avoid that.
Non-destructive verification
SQL injection is confirmed with time-based techniques (no data modification), and XSS is verified with harmless payloads, not dangerous scripts.
Intelligent rate limiting
Testing adapts to your application's capacity, backing off automatically when throttled.
Strict scope enforcement
RedPick only tests what you authorize. Out-of-scope targets are never touched.
Immediate stop on errors
Any unexpected behavior triggers an automatic pause for review.
Automatic cleanup
Any testing artifacts created during verification (uploaded files, stored payloads) are removed, when allowed, after testing completes.
Black-box by default
No source code required. Optionally provide credentials for authenticated testing or source access for white-box analysis.
FAQ
Common questions.
What is RedPick?
RedPick is an AI-powered application penetration testing platform. Specialist AI agents test your application the way a human pentester would, from reconnaissance and mapping to exploitation and verification, and deliver findings with reproducible proof-of-concept steps.
How is this different from a vulnerability scanner?
A scanner fires fixed payloads and matches signatures. RedPick reasons about the application: it chains requests, abuses business logic, and adapts to each response. That is how it finds authorization flaws and multi-stage chains that signature-based tools structurally cannot.
How does RedPick avoid false positives?
Every finding is confirmed with a working proof-of-concept before it reaches the report: no exploit, no finding. Independent frontier models also cross-validate each result. On the ProjectDiscovery benchmark RedPick reported 74 ground-truth vulnerabilities plus 78 additional verified findings with zero false positives.
Can AI agents or an MCP client run RedPick?
RedPick already runs headless — trigger a test on demand or straight from your CI/CD via API, with no human in the loop. A Model Context Protocol (MCP) server that lets AI agents and assistants launch scans and read findings directly is available in early access; contact us to get access.
