What problem does it solve?
Traditional penetration testing and attack surface management methodologies fail to cover AI-era attack surfaces including AI API egress channels, MCP server trust boundaries, RAG corpora, ephemeral cloud runtimes, and AI supply chain manifests, leaving organizations with false evidence of security posture and compliance with outdated frameworks.
Core Features & Use Cases
- Extended 7-Layer Attack Surface Inventory: Enumerates classical perimeter, AI API egress channels, MCP servers, prompt-injection footprints, RAG corpora, ephemeral runtimes, and AI supply chain manifests, addressing the blind spots of traditional ASM tools that only scan internet-facing IPs and web apps.
- Dual TTP Adversary Emulation: Maps both classical MITRE ATT&CK v19.1 and AI-class MITRE ATLAS v2026.06 tactics, techniques, and procedures to emulate mid-2026 adversary tradecraft including AI-API-as-C2 (SesameOp pattern) and prompt-injection-as-RCE.
- Legacy Framework Gap Flagging: Explicitly identifies insufficiency in outdated security and compliance frameworks including NIST SP 800-115, OWASP WSTG, PTES, NIS2, TIBER-EU, CBEST, and ISO/IEC 27001:2022 to eliminate compliance theater.
- Use Case: A financial institution preparing for DORA-mandated TIBER-EU threat-led penetration testing can use this skill to ensure its engagement covers AI-specific TTPs that are missing from official 2025–2026 scenario libraries.
Quick Start
Use the attack-surface-pentest skill to scope and execute a mid-2026 adversary emulation pen test that covers AI APIs, MCP servers, RAG corpora, and ephemeral runtimes alongside classical network and web application surfaces.