...

Semgrep Unveils Agentic Workflows to Automate Deep Vulnerability Hunting at Scale

Agentic Workflows

Semgrep announced a major product innovation today. The firm launched Agentic Workflows, a set of pre-built security detection pipelines.

This new technology uncovers complex business logic flaws, broken authorization, and injection risks. Consequently, Agentic Workflows finds critical security issues that traditional scanners routinely miss.

The technology combines AI reasoning with deterministic program analysis. Therefore, security teams identify high-risk code flaws without flooding their alert queues.

“Attackers are already using AI to find complex exploit chains in minutes,” said Isaac Evans, CEO and co-founder of Semgrep. “To defend enterprise codebases at scale, AppSec teams need security tools operating with that same reasoning and sophistication. Agentic Workflows gives defenders that analytical power out of the box, without the burden of building the AI system themselves.”

Advanced AI Reasoning Meets Program Analysis

The rapid influx of AI-generated code drastically inflates enterprise codebase volumes. At the same time, cyber adversaries use AI to discover vulnerabilities at unprecedented speeds.

Legacy static tools lack context, while standalone AI models generate excess false positives. Therefore, security teams require deeper analytical capabilities to protect modern applications.

The new Agentic Workflows system first uses program analysis to establish code context. Next, AI reasoning evaluates application logic to reveal hidden security risks.

Currently, pre-built Agentic Workflows addresses over ten distinct vulnerability classes. These include insecure direct object references and other OWASP Top 10 risks.

These pipelines also verify findings and guide remediation with complete visibility into the execution. Internal benchmarks demonstrated that using AI plus program analysis led to 3.5x more true positives. This combined approach also reduced costs per true positive by 19 percent.

Scalable Architecture for Application Security Teams

On day one, security teams can deploy Agentic Workflows across massive numbers of repositories. Organizations can go from proof-of-concept to full production without having to manage complex AI infrastructure.

Meanwhile, teams with custom needs can build Custom Agentic Workflows or customize pre-built pipelines. Semgrep manages system execution so enterprise security teams can focus on threat prevention.

Ultimately, Agentic Workflows enables modern enterprises to hunt for vulnerabilities at scale and in an automated fashion. The platform offers a powerful tool for defenders to fight against advanced AI-powered cyber threats. 

For related updates on digital trust and cybersecurity, explore our SOC News.

Source: Businesswire