Skip to content

#168 · Introducing Cascade: Penetration Testing That Becomes an Expert in Your Business

Availability: General Availability

Cascade is Escape's multi-agent AI pentest engine. It starts every engagement with what the platform already knows about your attack surface: APIs, web apps, schemas, tech stack, and scope from ASM and DAST. You're not pointing a stranger at a URL. You're running an assessment that compounds context across releases and gets sharper about how your business actually works.

Cascade multi-agent pentest engine architecture diagram showing ASM context flowing into the orchestrator, exploitation agents, reporter, and coverage agent Cascade starts from ASM context, coordinates a multi-agent swarm, and ships every finding with proof.

What's new:

  • Multi-agent swarm: An orchestrator plans the engagement and spawns focused exploitation agents on demand. A coverage agent closes gaps. A reporter independently reproduces every candidate before it's filed.
  • Proof of exploit: Every finding ships with the attack chain, request sequence, screenshots where relevant, and framework-specific remediation. Unproven candidates don't pollute your queue.
  • Auditable scope: Discovery maps your full configured scope before exploitation. You see exactly which endpoints, pages, and assets were assessed.

AI Pentesting documentation →\ Introducing Cascade on the Escape blog →

Questions?

Have a question? Reach out on your dedicated support channel, or email us at support@escape.tech.