Hoppa till huvudinnehåll

The mission lifecycle

Every AgentRidge engagement follows the same disciplined methodology. The Principal runs it as a loop, not a straight line — new discoveries reopen earlier phases until nothing in scope remains untested.

The phases

1 · Brief & mandate

The operator fills in the mission: client name, target IP and/or URL, optional virtual host and LAN range, extra scope notes, the engagement cases to cover, and the mode. Nothing runs until the written mandate is confirmed.

2 · Reconnaissance

The agent maps the attack surface — live hosts, open ports, running services, web and API endpoints, TLS and identity surfaces — starting from even a single URL or IP.

3 · Memory & leads

AgentRidge reuses what it learned about a target on previous runs: known endpoints, hidden AJAX handlers, suspected access-control flaws, admin paths, credential hints. Memory is a force multiplier that sets priorities; it never replaces a fresh scan, and every prior finding is re-verified live.

4 · Enumeration

Services and applications are probed for real weaknesses — authentication, injection, access control, server-side request forgery, file handling, misconfiguration — including deep business-logic testing on shops and apps (cart and price tampering, coupon abuse, order replay, object-reference flaws).

5 · Exploitation / verification

Confirmed with a live proof of concept. In Auditor mode this stops at the minimum proof needed for a finding; in Attacker mode it pursues full exploitation. The agent never emits a finding on a keyword match alone — it needs concrete evidence from this session.

6 · Chain & escalate

Individual findings are chained toward maximum in-scope impact: a data leak into account takeover, a foothold into privilege escalation, a single host into a lateral pivot — always within scope and mode.

7 · Confirmed findings

Each proven issue is captured as a structured finding: severity, title, affected host and endpoints, the exact commands used, the request/response evidence, business impact, a plain-language explanation, and remediation. These findings drive the live cartography and the vulnerability register in real time.

8 · Report

Once every confirmed finding is captured, AgentRidge writes the engagement narrative — recon to foothold to impact — and produces a client-ready PDF report.

What "done" means

The Principal only closes an engagement when its definition of done is satisfied: every in-scope lead has been tested, every confirmed finding has been captured with evidence, and the report reflects the actual work of this run — not a pointer to an old result. If a technique is blocked, the agent records the blocker, changes approach, and keeps working the rest of the surface.

Narrated as it goes

Throughout the run the agent narrates its reasoning in the Activity and mission views: the goal of each action, the tool chosen, the exact command, the result, and how it interprets that result. The engagement is auditable while it happens, not just afterward.

Next: engagement modes →