sheet 01general arrangementfig. 01 · 3 stages · 1 pipeline
continuous offensive security

your infrastructure.under constant attack.by us.

one continuous offensive-security system working your attack surface — recon, exploitation, triage — within your agreed rules of engagement and rate limits. every finding validated and demonstrated with a working proof-of-concept by our offensive team. dedicated infrastructure. zero noise.

fig. 01 — general arrangementscale nts
projectmastermind
sheet01 / 11
drawntrace37
checkedoffensive team
sheet 02bill of materialsparts as ballooned on fig. 01
itemqtydescriptionremarks
1
110+
specialist methodologies
each carries a complete attack methodology
2
310+
security tools
orchestrated as one — recon, exploitation, triage
3
60+
vulnerability classes
injection · auth · client-side · infra · data/logic · framework
4
5
proprietary engines
enigma XSS · enigma SSRF · parallax cache · JS taint analysis · token entropy prediction
projectmastermind
sheet02 / 11
drawntrace37
checkedoffensive team
trace37t37 disclosures
sheet 03 the problem

annual pen tests are a checkbox, not a strategy

  • your attack surface changes frequently
  • new JavaScript deployed, APIs updated, integrations added
  • a point-in-time assessment is out of date the next day

stale coverage

traditional pen tests are snapshots. by the time the report lands, your codebase has changed. new endpoints, new JS, new attack surface — untested.

scanner fatigue

automated scanners produce noise, not findings. they catch CVEs and misconfigurations but miss business logic flaws, auth bypasses, and chained vulnerabilities.

expensive spikes

dedicated red team engagements cost £30–100K+ per exercise. most organisations can only afford this annually, leaving 11 months of blind spots.

projectmastermind
sheet03 / 11
drawntrace37
checkedoffensive team
sheet 04 how it works fragments refer to fig. 01

ai-coordinated offensive pressure, human-validated results

  • mastermind-ai analyses your attack surface
  • runs recon, exploitation and triage as one continuous pipeline
  • every finding validated by our offensive team before it reaches you
  1. 01

    scope & deploy

    we agree rules of engagement and configure your attack surface. all tooling runs locally on a hardened server — zero SaaS platforms processing or storing your data. your findings, scan results, and credentials never leave the environment. encrypted mesh network, SSH-only access.

    hardened infrastructure scoping call RoE signed
  2. 02

    monthly focus

    each month we agree where to concentrate human effort. pre-production releases, new rollouts, areas of concern, compliance-driven priorities — you set the direction, we execute. ai scans the full stack continuously; human strategy targets what matters most right now.

    human strategy agreed priorities release testing risk-driven
  3. 03

    ai-driven reconnaissance

    mastermind-ai continuously monitors for new subdomains, endpoints, code changes, and exposed secrets. when your attack surface changes, the pipeline re-tests it within hours — no manual trigger.

    subdomain monitoring change detection endpoint discovery tech fingerprinting
  4. 04

    intelligent triage

    mastermind-ai prioritises targets based on risk signals — unprotected endpoints, parameter reflection, authentication gaps, JS sinks. it routes each target to the right specialist — xss-hunter, auth-hunter, cspt-hunter, websocket-hunter — each drawing on a live knowledge base of real-world bug reports, current CVEs, and published research. every finding we report feeds back in. the system gets sharper with every engagement.

    mastermind-ai specialists live knowledge base pattern recognition
  5. 05

    human-validated exploitation

    we review every ai finding before it reaches you. then go deeper — vulnerability chaining, WAF bypass, business logic abuse. impact is proven with evidence, not theoretical risk scores. every reported vulnerability is real.

    manual testing PoC development vuln chaining WAF bypass
projectmastermind
sheet04 / 11
drawntrace37
checkedoffensive team
sheet 05 the engine7 layers · top to bottom

one coordinated system. seven layers deep.

every hunt flows top to bottom — and every finding flows back up. hover any layer to explore it.

Seven-layer engine architecture from knowledge through triage to continuous learning01 KNOWLEDGEknowledge baseknowledge graphaccumulated intel from every engagementwhat worked · what didn't · what to try nextbypasses · techniques · WAF profilesresearch feedsalways current — not point-in-time knowledgelatest CVEs · disclosed vulnerabilitiesnew techniques · published exploitsoriginal researchwe discover new vulnerability classesnot just running known tools — originaldiscoveryzero-click takeover · auth bypass chains02 COORDINATEcoordinatorattack-surface mapmaps every reachable entry pointroutes each surface to the right specialistdispatch · team / soloattacker + researcher pair, or a solospecialistchains findings into real, demonstratedimpactworkflow fan-outparallel specialists across the surface atonceeach receives full context + provenmethodology03 SPECIALISTSspecialists · 60+ vulnerability classesinjectionxss · sqli · cmdi· ssrfxxe · rce · ssti· xpathauth / accessoauth · jwt · idor· csrfcors · race · bfla· cookieclient-sidecsp · cspt· dom-clobberprototype · spa· redirectinfrastructuredesync · cache· websocketupload · deser· path · cryptodata / logicemail · graphql· secretsbiz-logic · parser· nosqlframeworknextjs · fastapi· firebasesupabase· salesforce04 ENGINESproprietary enginesenigma XSSadapts when your WAFblocks itcontext → blockers →encodingblocked? mutates. anotherway.enigma SSRFinternal servicesscanners missdiscovery → bypass →confirmvulns only manual testingfindsparallax cachethe class most testersskipprobe → poison →weaponizeyour CDN weaponizedagainst youJS taint analysistraces sources to sinksin JSsource → flow → sink →exploitclient-side bugs grepmissestoken entropy predictionpredicts weak UUIDs andtokenssample → entropy →predictpredictable IDs becomeaccess05 TOOLS310+ tools orchestrated as onetool orchestration310+ tools orchestrated as onescan · fuzz · exploit · validateintercept proxyprofessional intercepting proxyevery request captured +replayablebrowser enginereal browser automationtests what your users seeJS analysisjavascript deep analysisfinds hidden endpoints + clientrisks06 TRIAGEtriage gate · ai-checked, human-confirmedindependent evaluationfresh context — no confirmation biasreproduces impact from scratch before itcountsadversarial red-teamactively tries to break the findingseverity, exploitability and report qualitychallengedboth must passone fail → back for more work, never to youzero noise · only validated, demonstratedimpact07 PERSISTpersistence + learninghunt historyevery finding, dead end and chain recordednothing forgotten between sessionscontinuitycontext survives across sessions +specialistspicks up exactly where it left offlearning loopsuccess + failure patterns capturedevery hunt sharpens the next onefindings → knowledgepatterns → strategyfailures → avoidanceknowledge · coordination · 60+ vulnerability classes · proprietary engines · 310+ tools · dual-gate triage · continuous learningevery engagement feeds the knowledge base. every hunt sharpens the next.
hover or focus a layer to see what it does
projectmastermind
sheet05 / 11
drawntrace37
checkedoffensive team
sheet 06 zero noise guarantee detail of fig. 01 · stage 03 · 2 passes

ai-accelerated, human-proven — before any of it reaches you

ai doesn't get the last word. every candidate finding is worked through a two-pass gate — ai accelerating, a human deciding. it has to be reproduced by hand, then survive a deliberate attack on its own validity. only what a human confirms is real reaches you; everything else is dropped.

pass 01

independent evaluation

we rebuild it from scratch — fresh context, nothing assumed from the hunt. the impact has to reproduce under our own hands, not just in the ai's logs. if it doesn't, it's gone — not queued, not re-tried.

  • fresh context — no assumptions carried from the hunt
  • reproduced by hand, not taken on the ai's word
  • impact demonstrated, not theorised
  • doesn't reproduce → gone, no escalation
must pass
pass 02

adversarial red-team review

then we go after the finding ourselves — pressure-testing severity and exploitability, hunting false positives, making sure the impact is exactly what we'd claim. the ai surfaces the angles; the call is ours.

  • adversarial stance — actively looking for reasons to reject
  • severity decided by a human, not inherited
  • false positives hunted: response analysis, auth-state checks
  • doesn't hold up → gone, regardless of pass one
must pass
the gate rule

both passes are required, and a human signs off on the result — ai for speed and coverage, a person for the final call. a finding that clears reproduction but fails the red-team is dropped; one that can't be reproduced never gets that far. no override, no escalation path around the gate.

fail either → discarded pass both → reported
projectmastermind
sheet06 / 11
drawntrace37
checkedoffensive team
sheet 07 capabilities 4 panels · each with a labs write-up

one coordinated offensive. every vulnerability class, continuously.

  • each specialist follows a complete adaptive attack methodology, not a checklist
  • specialist handoffs enable static analysis, decision trees, evolutionary payload mutation, vulnerability chaining
  • mastermind-ai thinks like an attacker. the human proves the impact

attack surface intelligence

we map everything. hidden subdomains, undocumented APIs, JavaScript sinks, leaked secrets. mastermind-ai builds a live model of your attack surface and updates it continuously.

  • hidden subdomain & API discovery
  • JavaScript taint analysis (sink/source tracing)
  • leaked credential & secret detection
  • historical endpoint recovery (wayback, archives)
  • technology fingerprinting & CVE/CWE matching
read: anatomy of an autonomous hunting platform →

deep exploitation

this is where the real bugs live. our ai hunters chain vulnerabilities, bypass WAFs, and abuse business logic. proprietary engines for XSS and cache poisoning, validated against real-world defences.

  • XSS with autonomous WAF bypass (proprietary enigma 5-rotor engine)
  • OAuth/JWT/SAML authentication chain attacks
  • web cache poisoning & deception (proprietary parallax toolkit)
  • SSRF, SSTI, deserialization, race conditions
  • AI/LLM security — prompt injection, sandbox escape, safety classifier bypass
  • vulnerability chaining & impact escalation
read: how 5 rotors crack WAF-protected XSS →

persistent surveillance

your attack surface changes frequently. we catch it the same day. we diff your site, review the impact of changes — unintended consequences, new attack vectors, removed controls. the ai flags what matters.

  • attack surface change detection & impact review
  • new subdomain & shadow IT discovery
  • CVE/CWE correlation against your live stack
  • API endpoint drift detection
  • third-party dependency risk tracking
read: how we cured our ai’s goldfish memory →

proof, not theory

every finding comes with a working proof-of-concept. we demonstrate real impact — data accessed, auth bypassed, code executed. if we can't prove it, we don't report it.

  • working PoC for every finding
  • demonstrated impact (not CVSS guesswork)
  • remediation guidance with code-level context
  • monthly intelligence summary
  • retest verification after your fix
read: zero-click account takeover via MessagePort injection →
projectmastermind
sheet07 / 11
drawntrace37
checkedoffensive team
sheet 08 built to scale 110+ skills · 6 domains · 5 panels

depth without the headcount

the platform is not a force multiplier — it is a capability that cannot be assembled from individual practitioners. here is what that means in practice.

depth
110+

specialist skills

a deep, curated library of specialist capabilities — covering reconnaissance methodology, exploitation techniques, evasion strategies, platform-specific attack patterns, and post-discovery analysis. each skill encodes hard-won knowledge from real engagements, kept current as the threat landscape evolves.

web application authentication API exploitation evasion & bypass chaining & escalation mobile

paired specialist dispatch

each engagement pairs an attack specialist with a research specialist — offensive execution and intelligence gathering run in parallel, not in sequence. findings are deeper, faster.

continuous scheduled hunting

hunting runs on a schedule, not on demand. your attack surface is re-evaluated at regular intervals — new endpoints, changed JS, drifted configuration. no manual trigger required.

scheduled re-checks surface change detection scheduled

self-learning platform

every confirmed finding enriches the knowledge base. patterns from one engagement inform targeting strategies on the next. the platform gets sharper with each deployment — not just more data, but better judgement.

coverage

full-spectrum offensive security

from web and mobile apps, to the APIs behind them, to native binaries, reverse engineering and cryptography — the full offensive surface, not a fixed list. the same depth, and the same two-pass gate, wherever a weakness can hide.

web & mobile
APIs
binaries
reverse engineering
cryptography
projectmastermind
sheet08 / 11
drawntrace37
checkedoffensive team
sheet 09 one system, human-gated 1 coordinator · 110+ specialists · 1 human gate
one system, human-gated

the system does the hunting. a researcher makes the call.

  • not a scanner with an ai label
  • mastermind-ai runs recon, exploitation and triage as one pipeline
  • human researcher validates, exploits, and proves impact
coordinator

mastermind-ai

analyses your attack surface, routes each target to a specialist, triages + prioritises findings

xss-hunterenigma WAF bypass engine
auth-hunterOAuth / JWT chain attacks
sqli-hunterblind / OOB extraction
cache-hunterparallax toolkit
… and more110+ specialists · 60+ vuln classes
human researcher

validates every finding

proves real-world impact, chains vulnerabilities

you get: proven vulnerabilities with working PoC. zero noise.

ai does this

the full attack cycle. reconnaissance, exploitation, WAF bypass, vulnerability chaining — not just scanning. proven methodologies for every vulnerability class, run across your entire surface.

humans do this

hunt strategy. directing agents based on experience. novel attack chains that need creativity. business logic that requires understanding your business. final validation. the report you receive.

the triage gate

every finding passes our bug-triage gate. proven impact — data leaked, auth bypassed, code executed — gets escalated urgently. lower-severity findings are still reported, just without the fire alarm.

the combination

ai makes this accessible. expertise makes it work.

  • every agent carries the methodology of a specialist — not a generalist scanner, a focused expert in its vulnerability class. probing, testing resistance, looking for the doors that open
  • built on a growing body of offensive security research — published techniques, disclosed vulnerabilities, emerging attack classes. the platform learns from the field, not just from us
  • the result: findings that neither pure automation nor manual testing alone would uncover
what ai handles
what humans handle
full attack cycle — recon through exploitation
hunt strategy & target prioritisation
WAF bypass & payload mutation at scale
novel attacks requiring creativity
vulnerability chaining & pattern recognition
business logic & real-world judgment
310+ tools coordinated autonomously
final validation & remediation guidance
projectmastermind
sheet09 / 11
drawntrace37
checkedoffensive team
sheet 10 built from the field 5 engines · see bill of materials

mastermind-ai. built from the field, not a lab.

  • mastermind-ai is the engine — one pipeline from recon to validated finding, with experienced humans in the loop
  • built by active bug hunters from real engagements and real research against real defences
  • every finding we report feeds back in — the engine gets sharper with every engagement

practitioner-built

active on major bounty platforms and publishing original research — from web application exploitation to AI sandbox security. mastermind-ai was built to solve our own problems first. now it works for you.

proprietary engines

enigma — XSS with autonomous WAF bypass, with SSRF and email-parser fuzzing siblings; parallax — web cache poisoning & deception; JS taint analysis; UUID & token entropy prediction; gRPC transcode confusion. each validated against real-world defences.

business systems background

infrastructure architecture, business systems, technology leadership. we understand the systems we're attacking — not just the vulnerabilities, but the business logic underneath.

secure by default

encrypted infrastructure, zero-trust access, mesh networking. your data handled with the same rigour we apply to testing yours.

projectmastermind
sheet10 / 11
drawntrace37
checkedoffensive team
sheet 11 get started input — your scope

ready to see what we'd find?

send us your scope. we'll probe it, send you initial findings and walk you through them on a free intro call.

projectmastermind
sheet11 / 11
drawntrace37
checkedoffensive team