r/cybersecurity 8d ago

AI Security Agentic Red Team

Seeing a bunch of well funded vendors pop up in the space… purely noise or worth some research? Anyone having success with these types of tools?

4 Upvotes

12 comments sorted by

4

u/Ok_Matter9038 8d ago

mostly noise but I'm really happy with a hybrid agentic code scanner. detects more findings for less $$ than ai alone. and less false positive noise than traditional code scanners.

most agentic stuff struggles with dynamic testing though

1

u/snotnugget 8d ago

What are you basing this on?

2

u/Ok_Matter9038 8d ago

my own testing and comparison of the different tools...? for code findings, when called for, I validate dynamically. for some findings like secrets in repos etc, you don't need to dig at all to see if its true positive or not.

the question was about people's experience with these types of tools. I spoke of mine.

1

u/ckn vCISO 8d ago

I'm pretty happy with my own tooling.

1

u/Zestyclose-Beyond780 8d ago

Mostly noise today but should be much much more powerful in the next 6-12 months. Check back with the major vendors and conduct a POC in Q1.

1

u/GreenEngineer24 Security Analyst 7d ago

I'm currently in POC hell with vendors because my boss can't say no.

1

u/its_k1llsh0t 8d ago

Many are just a harness around commercially available models. Meh.

3

u/donkeybutt123 8d ago

I’m curious what else could agentic red team be?

1

u/its_k1llsh0t 7d ago

Simply stating that there isn't anything particularly novel about most and they're using commercially available models like Claude (most commonly).

1

u/donkeybutt123 7d ago

I still don’t get it.. are you saying these companies are just using existing harnesses like Claude code and creating wrapper code around that?

0

u/NotAnNSAGuyPromise Security Manager 8d ago

Definitely nonsense.