Services Partners Blog About Us
Login

Yaga runs real
offensive tests

An AI agent with its own harness, operating in hours. Every result backed by the guarantee of HackerSec's specialists.

Pentest executed by real AI

Yaga operates within the defined scope, like a human pentester would, but in hours.

Technical reconnaissance

Surface analysis, service enumeration and asset discovery within scope.

Real exploitation

Offensive attacks adapted to the environment and the application's behavior.

Contextual analysis

Understands application behavior and adapts tests to what makes sense.

Confirmed findings

Only delivers what's exploitable. Every finding passes technical criteria before moving forward.

Inspired by John Wick

During development, we built several internal agents and ran a competition to see which was best. One was codenamed 007. Another, John Wick. In the end, John Wick won. Since we couldn't officially use that name, we went with his nickname in the movie: Baba Yaga, the figure associated with real danger and facing risk head-on. That's how Yaga was born.

Yaga operates in any environment

From modern apps to complex infrastructure.

Web Applications
REST and GraphQL APIs
iOS and Android
AI/LLM systems
AWS, Azure, GCP
External Networks
Internal Networks
IoT devices
yaga · pentest app.company.com
pentest app.company.com --scope api,web
Reconnaissance · 2.4s
reconmapping app.company.com attack surface completed
recon47 endpoints identified in scope completed
Exploitation · 6.1s
exploittesting IDOR on /api/v2/users/{id} completed
findingSQL Injection confirmed · critical critical
Attack chain validated · 1 exploitable critical
SQLi in /api/v2/users → 14 records exposed (PII)

The difference is the harness.

Yaga's harness is the proprietary offensive layer that
turns an AI model into a real pentester.

Proprietary

Built in-house by HackerSec, purely for offensive operations. It's what sets Yaga apart from any tool on the market.

Model-agnostic

The models underneath change; the harness is what stays. Yaga gets far more out of each model than it delivers alone.

Proven

The gain is in the benchmark: the same model performs far better inside Yaga than on its own.

And every result still passes through the guarantee of HackerSec's specialists.

See the benchmark

How much Yaga's orchestration delivers

The same AI model performs far better inside Yaga's harness than on its own. The gain shows up in every test mode.

Model Black box Gray box White box
Yaga · 4 models combined 91.2% 94.6% 93.5%
GPT-5.6 40.5% 49.5% 61.9%
Opus 4.8 39.7% 48.2% 61.8%
Grok 4.5 39.5% 47.6% 59.1%
Sonnet 5 28.4% 37.5% 50.6%

HackerSec internal evaluation over a fixed set of scenarios, measuring confirmed and exploitable vulnerabilities.
Each model is evaluated alone, without Yaga's harness.