VulnOdin
Hafiza Hajrah Rehman, Dawood Mustafa Minhas, Mubeen Afzal, Amit Saxena, Sujal Jadhav · Team rootAI
Submitted to Defensive Acceleration Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.
Modern enterprise software development has accelerated toward continuous integration and deployment (CI/CD), yet penetration testing remains periodic, manual, costly, and slow. Meanwhile, cybersecurity communities have observed a sharp rise in agentic-AI-driven offensive capabilities, where autonomous multi-agent systems can chain reconnaissance, scanning, exploitation, and privilege escalation with minimal human oversight. This project presents VulnOdin, an AI-powered autonomous red teaming system designed specifically for DevSecOps pipelines and enterprise environments. VulnOdin accepts live URLs and complete codebases including Dockerfiles, autonomously builds and deploys the target environment, constructs a dynamic attack graph, orchestrates traditional offensive security tools (e.g., nuclei, sqlmap, Burp extensions), and executes controlled exploitation attempts under strict governance constraints. The system continuously evaluates applications during development, automatically producing evidence-backed, compliance-ready penetration testing reports aligned with OWASP, CVSS, and ISO frameworks. Our findings demonstrate that AI-supported agentic orchestration can improve exploit chain discovery, reduce false positives through tool-verified evidence, and dramatically shorten the vulnerability discovery cycle. This work proposes a new paradigm: reproducible, continuous, environment-aware, autonomous pentesting integrated directly into enterprise build pipelines.
Reviews
No public critique yet.
Cite this project
@misc{rehman2025vulnodin,
title = {{VulnOdin}},
author = {Hafiza Hajrah Rehman and Dawood Mustafa Minhas and Mubeen Afzal and Amit Saxena and Sujal Jadhav},
year = {2025},
month = nov,
note = {Submitted to Defensive Acceleration Hackathon, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/vulnodin-235v}},
url = {https://apartresearch.com/sprints/projects/vulnodin-235v}
}More from Defensive Acceleration Hackathon
- View project: Neops - DevSecOps for the AI era
Neops - DevSecOps for the AI era
Broad Bros
NEOps is a CLI-based tool that embeds AI safety into your product lifecycle from day one. While development teams routinely build cybersecurity checks, AI-safety often comes later—or not at all. NEOps fills that gap by …
- View project: Assisted Audit of Solana Programs
Assisted Audit of Solana Programs
GLAM
Multi-agent solution that assists in auditing Solana programs, allows to consolidate audit findings into a knowledge base, and can integrate into CI/CD pipelines to prevent security regressions.
- View project: Mechanistic Watchdog
Mechanistic Watchdog
SL5
Mechanistic Watchdog is a mechanistic-interpretability-based “cognitive kill switch” for language models. Instead of only filtering final text, we monitor a model’s internal activations in real time and learn linear …