GnomeAgent
Autonomous AI-driven penetration testing — A penetration-testing platform that launches autonomous, LLM-guided campaigns against your web, API and network targets, verifies every finding, and produces consulting-grade reports.

GnomeAgent
Pentest & Offensive Security
- Findings verified by proof of concept, average scan around 90 minutes
- Self-service SaaS (free tier, then monthly plans) or deployment on your own infrastructure
- Web, API and network targets

What GnomeAgent does
Three execution modes
traditional, ai_powered and full_arsenal. From a classic tooled scan to a fully agent-orchestrated campaign, depending on the depth you need.
100+ security tools
An isolated, containerized executor (Nmap, Metasploit, OWASP ZAP, Nuclei, SQLMap...) runs the offensive arsenal. Tools are selected phase by phase by the execution engine.
Fleet of specialized agents
Seven coordinated agents: MythosReActLoop (orchestrator), DeepExploit (attack-chain planning), Athena (verification), Vulcan (exploitation strategy) and the PTG execution trio (Sigma, Phi, Omega). Goal: 100% of published findings verified by proof of concept, cutting noise and false positives.
Deliverable reports
Generates actionable PDF reports ready to hand to the client, with LLM-written narrative built from the verified findings.
Attack graph
Attack-path analysis in a Neo4j graph database: isolated findings become chained compromise scenarios.
Real-time tracking
Scan progress streamed over WebSocket, Prometheus metrics, structured logging and tracing across the whole chain.
Key capabilities
- Findings verified by proof of concept, average scan around 90 minutes
- Self-service SaaS (free tier, then monthly plans) or deployment on your own infrastructure
- Web, API and network targets
- Per-container tool isolation (Docker / Kubernetes)
- Multi-tenant with role-based access control
- Asynchronous queue for long-running campaigns
- Shared LLM gateway (litellm) with per-provider circuit breaker
- Persistent agent memory and multi-agent orchestration
- Built-in billing, LLM budget quotas and GDPR purge
Tech stack
Who it's for
- Internal security teams without a dedicated offensive capability
- Consultancies that want to industrialize the scanning phase
- Software vendors that must test continuously between annual audits
Let's deploy GnomeAgent for you
Scope, volume and deployment mode (SaaS or on your own infrastructure) determine the price. We scope this in the first conversation.
Pricing: From $149/mo on SaaS · on-prem and Enterprise on quote
