Skip to content

#184 · Escape's AI Pentesting now learns from your false positives

Escape's AI pentesting engine "Cascade" already flags very few false positives. The ones that slip through are almost always context problems, not detection problems: a pattern that looks exploitable everywhere except in your app, for reasons only your team knows.

Now you only have to explain that once.

What's new

When an issue is marked as a false positive, either manually by your team or by Cascade's AI false positive detection, Cascade extracts the underlying pattern and carries it into every future assessment. Triage one instance, and every other issue sharing that vulnerability pattern stops being reported.

How it works

Cascade treats manually-triaged and AI-flagged false positives as the only source of truth for suppression. Nothing else feeds the model, which keeps the blast radius tight and predictable. Pattern extraction happens per assessment target, so business context stays where it belongs. Your triage decisions compound. The tenth assessment costs less review time than the first.

Why it matters

Triage is where continuous security programs slow down. Every repeated "we already looked at this" is time your team spends re-litigating a decision it already made. Cascade now remembers so you don't have to.

Available now for all Cascade assessments. No configuration required.