How to do Continuous Pentesting
in DevSecOps using AI Agents
Quarterly pentests do not fit a pipeline that ships every week. See where AI agents attach to CI/CD, what runs on every commit, and how findings reach developers with a working proof of concept.
Session Details
Who It's For
DevSecOps Engineers and Pipeline Owners
Teams that own the CI/CD pipeline and decide which security checks gate a build and which only report.
AppSec Engineers
Engineers who have to turn test output into fixes developers will actually pick up and merge.
Pentest Managers
Managers moving a scheduled testing program toward continuous coverage without losing depth.
Platform and Release Teams
Teams responsible for release cadence who need security testing that keeps up with weekly shipping.
CISOs and Security Leaders
Leaders who need coverage between test cycles and evidence they can take to an auditor or a board.
Things you will walk away with
Where AI agents attach to a pipeline
The concrete integration points across commit, build, staging, and release, and which of those stages are worth gating on versus reporting on so you do not block developers over low-severity noise.
What runs on every commit versus every release
A tiered testing model: fast checks on each commit, a broader agent-driven test at release, and a scheduled deep test for business logic and chained attack paths that need more time.
How findings reach the developer who owns the code
Routing a validated finding into the right repository, branch, and ticket with a reproducible proof of concept attached, so remediation starts without a triage meeting first.
How to keep false positives out of the pipeline
Why validation before reporting is the difference between a security gate teams respect and one they route around, and what the agents do to confirm a finding is real.
Where AI owns the work and where humans own the judgment
The honest split: agents handle systematic, repeatable coverage at pipeline speed, while certified pentesters own scoping decisions, business logic, and the calls that need context.
Meet Your Speakers

Shiva Krishna Samireddy
Head of Research, Strobes Security
Shiva leads security research at Strobes, where his team builds and tests the attack techniques the AI agents run. In this session he covers what agents can genuinely cover at pipeline speed, what still needs a longer scheduled test, and how findings get validated before anything reaches a developer.

Prakash Ashok
Head of Security, Strobes Security
Prakash runs security at Strobes and has spent years inside pentest programs on both the delivery and the receiving end. He walks through the practical side of continuous testing: which pipeline stages are worth gating, how to phase the move off quarterly cycles, and where a human tester still makes the call.
Frequently Asked Questions
Watch the full session, then see it run on your pipeline.
The recording is on demand, no registration required. If you want to see continuous pentesting against a target you choose, book 30 minutes with our team.
Join 150+ security teams already reducing exposure with Strobes




