AI security agents
Agents that attack your own systems to find exploitable weaknesses, or investigate security alerts like a SOC analyst.
By weekly package downloads, the leaders are Strix (8,244), CAI (Cybersecurity AI) (686). By GitHub stars, the leaders are Strix (66.8K), PentAGI (25.3K), CAI (Cybersecurity AI) (9,847). As of Oct 6, 2026.
| # | Agent | Pulse | Downloads 7d | 7d | 30d | VS Code installs | Stars | Latest release | Price | Last 90 days | |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 133 |
PentAGIVXControl |
30 | — | — | — | — | 25.3K+31/day | 2.2.0yesterday | Free (OSS) | — | |
| 156 |
StrixStrix |
24 | 8,244 | up 9.7% | down 57.0% | — | 66.8K+197/day | 1.7.0yesterday | Free + $29/mo | ||
| 185 |
NodeZeroHorizon3.ai |
18 | — | — | — | — | — | — | Custom | — | |
| 209 |
XBOWXBOW |
11 | — | — | — | — | — | — | Usage-based | ||
| 210 |
CAI (Cybersecurity AI)Alias Robotics |
10 | 686 | up 58.8% | down 46.7% | — | 9,847+2/day | — | Free | ||
| 227 |
Dropzone AIDropzone AI |
0 | — | — | — | — | — | — | Custom | — | |
| 250 |
Microsoft Security Copilot agentsMicrosoft |
— | — | — | — | — | — | — | Usage-based | — | |
| No agents match that filter. | |||||||||||
Ranks are overall positions by Pulse Score. Click a column to sort by what matters to you. Methodology.
Offensive and defensive
- Autonomous pentesting (XBOW, NodeZero, PentAGI, Strix, CAI) runs real attack techniques against applications and networks and reports what is actually exploitable, with proof.
- SOC agents (Dropzone AI, Microsoft Security Copilot agents) investigate alerts across security tools and return a verdict with evidence.
Use responsibly
Only test systems you own or are authorised to test, in writing. Run offensive agents in isolated environments, scope them tightly and review their findings before acting.
Head-to-head comparisons
Related guides
Questions about AI security agents
Can AI do penetration testing?
Yes. Autonomous pentesting agents chain reconnaissance, exploitation and validation steps and report exploitable findings with proof. They complement rather than replace human testers, and must only be pointed at systems you are authorised to test.
Is there an open-source AI pentesting agent?
Yes. PentAGI and Strix are open-source and self-hosted; CAI publishes its source with its own licence terms.