Documentation

Crax Agent

An autonomous AI security agent that finds, tests and analyzes vulnerabilities the way an attacker would — then hands you the fix. Built for security teams and penetration testers.

Authorized use only

Crax Agent is for ethical, authorized security testing. Running it against systems you do not own or have written permission to test is illegal. Always get authorization first.

System architecture

Reconnaissance engine

Automated target discovery — port scanning, service detection and technology fingerprinting.

Vulnerability scanner

Deep analysis with CVSS scoring, severity classification and remediation guidance.

Exploit core

SQL injection, XSS, command injection and auth-bypass modules — all safely simulated.

AI analysis

Threat scoring, anomaly detection and risk assessment across every finding.

Key features

  • Automated vulnerability scanning with CVSS 3.1 scoring
  • Exploitation modules: SQLi, XSS, command injection, auth bypass
  • Real-time event monitoring and alerting
  • AI-powered threat analysis and anomaly detection
  • Full pentest lifecycle in one workflow
  • Comprehensive reports with per-finding evidence