Agentic AI has arrived in offensive security faster than the controls around it. An agent running a penetration test needs credentials, network position, and the freedom to act on what it finds, which is the same configuration an attacker would want. The rules of engagement that keep a human tester inside scope exist in a document and in that tester’s judgment, and an agent can read neither. Once the engagement is underway and the agent holds live credentials, there is no mechanism to take that access back.
In this session of Offensive Engineering Live Sessions, Dan DeCloss, founder of PlexTrac, now part of Brinqa, who has worked two decades in offensive security across the US Department of Defense, Veracode, Mayo Clinic and Anthem, walks through where agents fit inside a penetration test and where they do not. He is speaking independently, and the views he shares are his own.
The conversation covers:
Why reconnaissance and enumeration are safe to delegate immediately, and what makes them different from everything that follows
Where the line moves once an exploit runs against a live machine, and why rules of engagement cannot be encoded in a prompt
How evidence handling becomes the real exposure, since penetration tests routinely dump databases and credentials that must stay inside the engagement
Why an agent granted domain administrative access has effectively granted it to whoever compromises the model
What it means to threat model the agent itself before scoping what it is allowed to do
Why senior testers get faster with agents while junior ones get slower at building the judgment that makes seniors





