XBOW Profile Banner
XBOW Profile
XBOW

@Xbow

Followers
1,635
Following
6
Media
12
Statuses
38

Bringing AI to offensive security by autonomously finding and exploiting web vulnerabilities. Watch XBOW hack things:

Seattle, Washington, USA
Joined May 2007
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@Xbow
XBOW
20 days
XBOW is the world’s first fully automated web pentester. It previously scored an unprecedented 75% on renowned web pentesting benchmarks from @PentesterLab and @PortSwigger . So we decided to give it a harder challenge: competing against humans.
26
54
315
@Xbow
XBOW
1 month
XBOW finds and exploits vulnerabilities in 75% of 647 renowned web benchmarks. Given a short description of the benchmark, it autonomously pursues high-level goals, executing commands and interpreting their output to achieve exploitation. Check it out:
Tweet media one
6
23
88
@Xbow
XBOW
1 month
XBOW, from the minds who previously brought you GitHub Advanced Security and GitHub Copilot ( @oegerikus ) legendary security researchers ( @nicowaisman ) and pioneers at the intersection of AI and security ( @moyix ).
4
9
64
@Xbow
XBOW
20 days
In 28 minutes, XBOW matched 40 hours of work by the most experienced pentester, who has 20 years of experience, with both solving 85%.
Tweet media one
3
4
44
@Xbow
XBOW
1 month
What if an AI’s “brilliant” solution to a problem is just memorized? Modern AI systems have seen the whole web, so there’s only one way to be sure—we created 104 novel benchmarks. Now we can be certain that beautiful solves like this one are real:
Tweet media one
0
6
43
@Xbow
XBOW
1 month
Real vulnerabilities don’t come with hints—so we asked XBOW to solve this task without giving it even a description of the benchmark. It performed just as well, finding exploiting an GraphQL-based IDOR vulnerability entirely autonomously:
Tweet media one
1
5
41
@Xbow
XBOW
26 days
How did XBOW create an offensive security agent that solves 75% of web security benchmarks? With the best team and investors! Delighted that @sequoia is leading our $20M seed round, with participation by @oegerikus @amasad @pirroh @oliveur & others.
Tweet media one
2
9
36
@Xbow
XBOW
1 month
Can’t find a working PoC? No problem, says XBOW—and it proceeds to read 22,000 words’ worth of GitHub issues to understand the vulnerability before writing its own exploit. Check out the trace:
Tweet media one
0
7
33
@Xbow
XBOW
20 days
We created 104 novel benchmarks that include every web vulnerability class you see in the wild: from SQL injection through IDOR to SSRF. We hired 5 pentesters from well-established pentesting companies.
Tweet media one
1
1
27
@Xbow
XBOW
20 days
If you’re interested in seeing how XBOW performs on a specific benchmark - either a public one like PortSwigger or a novel XBOW one - let us know below, and we’ll try to share some traces! You can see a full list of benchmarks XBOW has solved here:
2
0
18
@Xbow
XBOW
1 month
XBOW not only finds critical vulnerabilities like SSTI, it also writes its own payloads customized to the target:
Tweet media one
0
2
16
@Xbow
XBOW
20 days
Here are some things experiment participants have said:
Tweet media one
1
0
14
@Xbow
XBOW
1 month
Tweet media one
0
3
14
@Xbow
XBOW
1 month
To read this new post by @moyix , please enter the following characters. Or click here:
Tweet media one
0
6
12
@Xbow
XBOW
20 days
@binalkp91 @PentesterLab @PortSwigger Pick out a challenge from this list and we can share XBOW's solution!
0
0
6
@Xbow
XBOW
20 days
@shido__________ @PentesterLab @PortSwigger We'll be open-sourcing our benchmarks soon! In the meantime, if you're curious about how XBOW tackled specific benchmarks, feel free to reach out. We'd be happy to share the details with you. Just let us know which ones you're interested in from here:
0
0
5
@Xbow
XBOW
20 days
@aoighost Thanks – that's how we see it as well. Huge moment for AI and offensive security.
1
0
3
@Xbow
XBOW
19 days
@KostaBuhler Thanks for your support @KostaBuhler !
0
0
3
@Xbow
XBOW
19 days
@CyberQueenMara @PentesterLab @PortSwigger Thanks! Agreed, the more time humans can spend hunting the really cool bugs the better :)
1
0
2
@Xbow
XBOW
20 days
@aoighost Our hope – and goal – is to automate away the boring parts, and let humans focus on the cool and creative parts of bug bounty hunting. :)
1
0
2
@Xbow
XBOW
19 days
@2DCrypto Happy to share the XBOW solutions for any of the challenges on that spreadsheet it solved. We're still packaging up the challenges for release but they're coming soon.
1
0
1
@Xbow
XBOW
20 days
0
0
1
@Xbow
XBOW
19 days
@2DCrypto Great, we'll look out for your email!
0
0
1