How the Strike agent works
Last updated: July 30, 2026
Strike's AI agent is the core component that runs Threat Emulations against assets, combining artificial intelligence with expert oversight to simulate the behavior of a real attacker.
Its design allows systems to be evaluated continuously, automatically, and under control, maintaining precision, speed, and security in every execution.
Threat Emulation engine
The engine runs continuously: when a change is detected on the attack surface, autonomous agents (and human specialists) test every asset.
There are three types of emulations:
Deep — advanced attacks on critical assets.
Change-based — targeted validation of recent changes.
Coverage — continuous monitoring of the entire surface.
Human validation of results
Every emulation goes through oversight and triaging by the Hacking Governance team. AI accelerates speed, depth, and coverage, but critical decisions are made by expert ethical hackers. 100% of critical findings are manually validated.
The Hacking Governance team:
Confirms vulnerabilities.
Removes false positives.
Reproduces findings.
Assesses real-world impact.
👉 This ensures results are accurate and actionable.
Model-agnostic engine
The engine doesn't depend on a single provider: it can run on proprietary models, open source models, or models from leading providers (OpenAI, Anthropic), choosing whichever is best suited to the task.
Isolation and data
Each customer is processed in isolated contexts: agents never access another customer's information.
Everything runs in inference mode (no training): data is not used to train models and is not retained beyond processing.
Once each run finishes, the environment is destroyed, temporary data is deleted, and sessions are closed.
Full access control and traceability.
👉 Each execution is independent and shares no state with any other.
End-to-end flow
The process follows four stages: discovery → validation → remediation → verification, backed by a proprietary data layer (thousands of hours of pentesting) that continuously improves detection.
How tests are run
The agent:
Simulates real attack paths.
Runs multiple tests in parallel.
Adapts to the asset's context.
Prioritizes based on dependencies and complexity.
👉 This makes it possible to detect both technical and business-logic vulnerabilities.
Controls and operational security
The agent is designed to operate safely in production environments.
It includes:
Execution within limits defined by the customer.
Exclusion of destructive actions.
Real-time monitoring.
Immediate stop mechanism (kill switch).
Automatic shutdown in response to anomalous behavior.
👉 This allows continuous testing without disrupting operations.
Testing scope
The agent primarily evaluates:
Web applications (public and private).
APIs and backend services.
Exposed business logic.
It can operate on private environments through:
VPN.
IP allowlisting.
👉 This covers both public and internal surfaces.
Strike's AI agent combines a continuous emulation engine, parallel execution, and expert validation from the Hacking Governance team to deliver testing that is continuous, precise, and aligned with real business risk.