- What Savant Pathseeker does
- Before you begin
- Autonomous testing steps-by-step
- Add a new asset without leaving test setup
- Test applications that require a login
- Push findings to your Security Inbox
- Related topics
Savant Pathseeker is Bugcrowd’s autonomous penetration testing product. It runs controlled, outside-in tests against your approved internet-facing domains, web apps, and APIs, and it produces validated findings your team can act on.
What Savant Pathseeker does
Savant Pathseeker brings together several capabilities in one testing flow:
- Autonomous testing -- launches controlled tests against your approved assets and reports validated findings with evidence.
- Asset targeting -- lets you search your approved asset inventory or add a new asset directly from test setup.
- Bot detection and WAF evasion -- adapts to perimeter controls within your authorized boundaries, so testing reflects what a real attacker could reach.
- Authenticated testing -- logs in to apps that require credentials, including apps that sign in through an external identity provider, and tests what is behind the login.
- Findings delivery -- lets you push validated findings straight into your Security Inbox, alongside your other detections and submissions.
Before you begin
- You need organization owner permissions to launch a Pathseeker test.
- Targets must be approved in your asset inventory before Pathseeker can test them.
- Pathseeker performs controlled, outside-in testing against approved, internet-accessible domains, web apps, and APIs. Internal or credentialed network testing is out of scope.
Autonomous testing steps-by-step
Here are high-level steps to run an autonomous test from your asset inventory to a set of validated findings.
- Log in and open the Assets tab. Log in with an organization owner account and select Assets at the top of the page. If you don’t see the Assets tab, refer to Enabling Asset Inventory.
- Approve your targets. If your target is already in the asset inventory, select it and click Approve. If it is not there yet, click Add Asset, enter a name and type (ex. Zone for a DNS namespace for a domain, Record for a individual DNS entry within a zone), set the asset’s criticality, and save. Then approve it. You can also group related assets into an asset group to target them together.
- Open Autonomous Tests. Go to the program where you want results to appear and select the Autonomous Tests tab, then New Autonomous Test.
- Configure your test. Name the test, add targets using an asset group or the target field, and choose whether to allow credentialed attacks.
- Review and launch. Confirm the approved assets in scope, authorize the test, and select Agree and Launch Test.
- Monitor progress. Watch status and progress indicators while the test runs. Select Stop Test if anything looks unexpected.
- Review findings. When the test finishes, open the Results tab to see what Pathseeker found.
Add a new asset without leaving test setup
You can add a target that is not yet in your asset inventory directly from Pathseeker test setup, without switching to the Assets tab.
- In the target field, type the name of the asset you want to test.
- If no match is found, select the link Create and approve a new asset?.
- Complete the required fields: name, URL, type, and business criticality.
- Save.
Pathseeker creates the asset, approves it, and adds it as a target in one action. The asset also appears in your asset inventory, so it is available for future tests without any additional setup.
Test applications that require a login
Pathseeker can log in to applications that require credentials and test what is behind the login, including apps that redirect to an external identity provider such as Okta, Entra ID, or Google to complete sign-in.
To set up an authenticated test:
- Open the credential step in test setup.
- Enter the username and password for the account you want Pathseeker to test with.
- Save your credentials.
Credentials are encrypted and stored securely. They never appear in logs, the interface, or test output.
Once a test starts, Pathseeker checks whether the target has a login page. If credentials are on file, it signs in and tests the app, including anything behind an external login redirect. If the app has a login page and no credentials were provided, the test flags this so you know why coverage was limited.
Pathseeker keeps its session active for the full test and does not sign itself out partway through.
Push findings to your Security Inbox
You can move a validated Pathseeker finding into your Security Inbox with one click, so it enters your existing vulnerability-management workflow without manual re-entry.
To push a finding:
- From the test results screen, select one or more findings you want to promote. You can also promote a finding from its individual detail screen.
- Select Push to Inbox.
- Confirm in the dialog. Promotion cannot be undone.
The finding appears in your Security Inbox within seconds, labeled as a Autonomous Test Vulnerabilities and link back to the test run that produced them. If a push fails, the finding shows a Failed status with an option to try again. A finding can only be promoted once; Pathseeker blocks and flags any attempt to push the same finding twice.