---
title: "Security & fraud AI agents · defensive, fraud and offensive · Agent Fieldbook"
url: https://agentfieldbook.org/catalog/security_fraud/
description: "AI agents pointed at security itself: defensive triage and threat hunting, fraud detection, and offensive security that automates pen-testing and vulnerability discovery. A dual-use category read alongside the Fieldbook incident log, each specced against primary sources."
section: "Catalogue · Security & Fraud"
source: Agent Fieldbook — generated from the published page
---

# Security & fraud agents

Agents pointed at security itself: defensive triage and threat hunting, fraud detection that adapts as tactics shift, and offensive security that automates pen-testing and vulnerability discovery. All operate against an adversary, and offensive tooling is dual-use by definition. Read alongside the incident log; click a card for its full spec.

## 10 agents Live data · click a specimen for its anatomy

## Field notes

Defensive, fraud and offensive: a dual-use category

Security agents cluster on the work that scales badly with headcount: triage, enrichment, log correlation and first-pass investigation. These are high-volume, pattern-heavy tasks where an analyst's time is the binding constraint.

The honest tension in the category is that reach cuts both ways. An agent able to investigate systems is an agent able to act on them, and offensive tooling is dual-use by definition. This catalogue is meant to be read next to the incident log, where the same capabilities appear with their documented attack class and defence.

- [Brandon Chaplin](https://www.linkedin.com/in/brandon-chaplin-digital-marketing-strategist)

## Common questions

### What does an AI agent do in cyber security?

Mostly first-pass investigation: triaging alerts, gathering context from logs and systems, and correlating signals into something an analyst can act on. It targets the queue that scales badly with headcount, not the decisions at the end of it.

### How does AI detect fraud?

By scoring transactions and behaviour against patterns learned from past activity rather than fixed rules. That catches novel schemes a rule written last year would wave through. It also produces false positives, so flagged cases usually go to a human before anything is blocked.

### Can AI agents do penetration testing?

Yes, within limits. Agents can scan, probe and chain known techniques far faster than a person, which helps with coverage. They still miss the creative attack paths an experienced tester finds, and running them against systems you do not own is a criminal offence.

### Can attackers use AI agents too?

Yes, and the same tooling works for both sides. The specific risk to defenders is prompt injection: hidden instructions inside content an agent reads that make it act against its operator. OWASP ranks it the top risk for LLM applications [(OWASP)](https://owasp.org/www-project-top-10-for-large-language-model-applications/).

## Next in the learning path

- [Security incidents How agents actually get compromised](https://agentfieldbook.org/security/incidents/)

- [Safety evals How these capabilities get tested](https://agentfieldbook.org/security/evals/)

- [Governance The controls that cap the blast radius](https://agentfieldbook.org/security/governance/)

- [Auth & secrets The credential defence most incidents argue for](https://agentfieldbook.org/security/auth/)

## Entries

_10 entries listed on this page._

| name | description | subjectOf |
| --- | --- | --- |
| CrowdStrike Charlotte AI | Agentic SOC at the endpoint, Charlotte moved past copilot to autonomous detection, triage and response; AgentWorks lets teams build custom security agents. | https://www.crowdstrike.com/en-us/press-releases/crowdstrike-launches-charlotte-ai-agentworks-ecosystem-for-building-secure-agents/ |
| Microsoft Security Copilot | Investigates incidents and executes security workflows; Agent 365 is the enterprise control plane with shadow-AI discovery and network-level prompt-injection blocking. | https://techcommunity.microsoft.com/blog/securitycopilotblog/from-alert-overload-to-decisive-action-how-security-copilot-agents-are-transform/4504213 |
| Dropzone AI | Autonomously investigates every security alert end-to-end, producing analyst-grade conclusions without playbooks. | https://www.dropzone.ai |
| Prophet Security | Agentic AI SOC analyst that triages and investigates alerts at machine speed, cutting alert overload. | https://www.prophetsecurity.ai/blog/top-5-ai-soc-analyst-platforms |
| Simbian | Autonomous AI security agents that automate SOC workflows from detection to response. | https://www.simbian.ai |
| Apate.ai | Deploys swarms of conversational decoy "victims" that engage scammers in real time: wasting their resources and harvesting live threat intelligence. A Macquarie University Cyber Security Hub spin-out. | https://www.apate.ai/ |
| Sardine | Fraud, compliance and AML platform deploying risk agents that investigate and decision transactions in real time. | https://www.sardine.ai |
| XBOW | First non-human to top HackerOne's US leaderboard. Autonomous pen-tester founded by Oege de Moor (creator of GitHub Copilot / CodeQL); Pentest On-Demand turns 35–100-day engagements into clicks. | https://xbow.com/blog/top-1-how-xbow-did-it |
| Horizon3.ai NodeZero | Autonomous penetration-testing agent that continuously finds and chains exploitable attack paths across an environment, then verifies real impact. | https://www.horizon3.ai |
| ZeroPath | Agentic application-security scanner that finds and triages exploitable code vulnerabilities with low false positives. | https://zeropath.com |
