DEV Update: Bringing Agentic AI to Cybersecurity Validation

|

Artificial intelligence is fundamentally changing the cybersecurity landscape. Large language models and agentic AI systems are accelerating software development, enabling engineers to create code faster than ever before. At the same time, these technologies are equally accessible to attackers, who increasingly use AI to identify vulnerabilities, automate exploit development, and scale offensive security research.

The result is a growing imbalance. More software is being produced in less time, vulnerabilities are discovered faster, and engineering teams are faced with an ever-increasing volume of cybersecurity findings – from SBOM analyses identifying newly published CVEs to TARA results and SOC or VSOC alerts. The challenge is no longer collecting this information; it is validating it quickly enough to keep pace.

The latest HydraVision development update introduces Agentic AI Workflows, bringing the same automation capabilities to cybersecurity validation. Rather than replacing engineering expertise, Agentic AI assists with transforming security findings into executable validation workflows that can be executed deterministically on real systems. The result is a scalable approach to cybersecurity validation that reduces manual effort while preserving repeatability, traceability, and governance.

“The challenge of the future is no longer developing software, but validating it efficiently. By applying agentic AIto security testing workflows, HydraVision enables organizations to keep pace with the rapidly growing volume of AI-generated software while maintaining the traceability, repeatability and quality required for cybersecurity validation”

Dr. Nils Weiss,
Senior Manager @ dissecto

Connecting Cybersecurity Engineering with Security Validation

Modern cybersecurity engineering already produces a wealth of valuable information throughout the product lifecycle. Threat Analysis and Risk Assessments (TARA) identify potential attack paths, Software Bill of Materials (SBOM) analysis identifies vulnerable components by mapping newly published CVEs to the software inventory, while SOC and VSOC operations uncover operational security events.

Traditionally, these activities have been largely disconnected from the validation process. Engineers must manually interpret findings, decide whether they apply to a specific product, create suitable test procedures, execute them, and finally document the results. As the number of findings continues to grow, this manual translation becomes increasingly difficult to scale.

Agentic AI Workflows bridge this gap by transforming cybersecurity artifacts directly into executable validation activities within HydraVision.

agentic_ai_workflow
Typical compliance workflow after the new update

Instead of starting with a blank page, Agentic AI analyzes the available cybersecurity artifacts, understands their context, and generates reusable validation assets. These workflows can originate from TARA results, SBOM findings, SOC or VSOC incidents, vulnerability advisories, or other cybersecurity inputs.

HydraVision then takes over the deterministic part of the process. Using HydraProbe or HydraProbe mobile, the generated validation workflows are executed on the physical system under test, automatically producing validation results and evidence. Depending on the outcome, organizations can continue with incident reporting, mitigation verification or vulnerability documentation – all within a consistent and repeatable workflow.

Rather than introducing another isolated AI assistant, HydraVision integrates Agentic AI directly into existing cybersecurity engineering processes, creating a continuous workflow from security finding to validated evidence.

A Sustainable Approach to AI-Assisted Validation

One of the defining characteristics of HydraVision’s implementation is its sustainable approach to Agentic AI. Many AI-assisted engineering solutions generate temporary output that requires repeated interaction with the underlying language model whenever the same task needs to be performed again. This not only increases operational costs but also makes long-term automation difficult to scale.

HydraVision follows a different approach.

While Agentic AI accelerates the creation of test cases, automation logic, and validation workflows, the generated assets become permanent components of the HydraVision project. Once created, they can be executed repeatedly without requiring additional AI interaction or consuming further AI tokens.

This significantly reduces the operational cost of AI-assisted cybersecurity validation. Organizations invest once in creating reusable validation assets that can subsequently support software update validation, security regression testing, and recurring compliance activities throughout the product lifecycle.

Combined with HydraVision’s target-agnostic architecture, the same validation assets can also be reused across multiple systems under test, further reducing engineering effort while ensuring consistent cybersecurity validation across product variants.

Standardizing Security Validation Workflows

Beyond AI-assisted workflow creation, the latest update introduces predefined one-click workflows for common cybersecurity validation tasks. By combining intelligent workflow generation with HydraVision’s established automation framework, engineering teams can eliminate repetitive manual activities while ensuring consistent execution and reproducible results.

At the same time, automated reporting and audit-ready documentation help development, cybersecurity, and validation teams collaborate more efficiently while supporting regulatory requirements and modern cybersecurity engineering practices.

Bringing Agentic AI to the Defensive Side of Cybersecurity

Artificial intelligence is reshaping both software development and offensive security research. As engineering teams produce software faster and attackers gain access to increasingly sophisticated AI-assisted techniques, cybersecurity validation must evolve accordingly.

With Agentic AI Workflows, HydraVision extends automated security testing beyond test execution. By connecting cybersecurity artifacts such as TARA results, SBOM analyses, SOC findings, and vulnerability disclosures with deterministic validation on real systems, organizations can significantly reduce manual effort while improving consistency, traceability, and validation coverage.

The new capabilities will be showcased at ScapyCon 2026, where we’ll demonstrate how Agentic AI Workflows help accelerate cybersecurity validation for automotive, embedded, industrial, and other cyber-physical systems.

Do you have questions or need support?

We’re here to help! Contact us with any questions about our HydraVision Security Test Environment or our penetration testing services for ECUs, vehicle networks, and embedded systems.

Skillpoints to spend? Check out our Cybersecurity Workshops and ScapyCon, our annual conference for cybersecurity aficionados!