Whitebox Agent¶
Whitebox pentesting is a Cascade capability. When you attach repository source code to an assessment, Cascade reasons over that code alongside the running application, so findings can point to the exact file and function behind a vulnerability.
What It Does¶
- Consumes source: Uses uploaded repository archives as whitebox context
- Pre-seeds recon from the repo: Maps architecture, auth model, entry points, and high-risk sinks before deep exploitation
- Combines static triage with dynamic validation: Uses source-aware findings to prioritize payloads and endpoints, then proves issues against the live target
- Keeps evidence dynamic: Static hits stay hypotheses until Cascade validates them on the running application
How It's Used¶
In the New Profile form, open Whitebox Configuration (Optional) and upload a repository archive (.zip, .tar.gz, .tgz). Other context (prior reports, OpenAPI specs, documentation) belongs in Fine-Tune (Optional) > Artifacts.
Attaching source code enables whitebox testing automatically.
Related¶
- Quickstart: Attach source code during pentest creation
- The Cascade Engine: How Cascade plans and validates findings
- Proof of Exploit: Evidence, including code-file attachments
- Regression Testing Agent: Replay prior findings from uploaded reports