A scanner has a checklist. Xseth has a brain.
Recon, triage, validation and client-ready reporting today, wrapped in a cognitive core that reasons over an attack graph and chains findings into paths. Exploitation to impact is on the roadmap, and we label what's shipped versus what's coming.
Recon pipeline
ShippingSubfinder → Naabu → HTTPX → Nmap, orchestrated end to end. Maps the attack surface (subdomains, open ports, live web, service versions) into one structured profile.
AI triage: signal over noise
ShippingA security-tuned LLM ranks the raw recon, drops the noise, and writes a prioritized threat assessment with the evidence behind every finding. You decide what is real.
World-model attack graph
ShippingEvery scan is projected into a persistent graph: hosts, services, web endpoints and the edges between them. The agent reasons over this graph instead of treating each finding in isolation.
Attack-path chaining
ShippingA separate reasoning pass combines individually-low findings into multi-step attack paths. That is the difference between a scanner and someone who thinks about what one weakness unlocks next.
Bounded OODA loop
ShippingAfter each pass the agent decides whether one more focused scan wave is worth it. Observe, orient, decide, act, under a hard step budget, with every decision audited.
Vulnerability validation
ShippingHigh and critical findings get a non-destructive validation probe and come back badged CONFIRMED ✓, or honestly left unproven. It confirms a finding is real and reachable, never exploits it, so the report tells you what is verified instead of just what was guessed.
Client-ready PDF report
ShippingExport any assessment as a downloadable PDF: prioritized findings with their evidence, impact and remediation, written up in plain prose. The deliverable you can hand to a client or drop into a ticket, generated on demand.
Thoth: ask the assessment
ShippingA grounded chatbot on every assessment. Ask which findings are confirmed, or walk through the highest-impact path, and Thoth answers from the scan’s own data, citing it, read-only, and never inventing a finding or launching a new scan.
Exploitation to impact
RoadmapScope-bound, approval-gated, audited proof of impact that chains a confirmed weakness through to a demonstrated outcome. This is the roadmap: more autonomy, one capability at a time, never an unsupervised attacker.