Skip to content

Knowledge Base ​

The knowledge base provides reference material that AI agents query during assessments. It gives agents domain-specific context that improves testing decisions.

What Goes in the Knowledge Base ​

Knowledge base entries are markdown notes containing information relevant to your assessments:

  • Application architecture and technology stack details
  • Known authentication flows and session management patterns
  • Business logic descriptions and critical workflows
  • Previously discovered vulnerability patterns
  • Environment-specific configuration details
  • Testing methodology notes and custom techniques

Managing Entries ​

From the Knowledge Base panel:

  • Add new entries with a title and markdown content
  • Edit existing entries to keep information current
  • Delete entries that are no longer relevant

Knowledge base panel with entries

Screenshots use fictional demonstration data.

How Agents Use the Knowledge Base ​

During an assessment, the agent searches and retrieves relevant entries to:

  • Understand the target application's architecture before testing
  • Apply domain-specific testing techniques
  • Avoid repeating tests documented as dead-ends
  • Focus on areas known to be high-risk

The strategist model also draws from the knowledge base when recommending next steps.

Coverage Templates ​

Knowledge base documents can be linked to coverage templates: keyword-triggered test class assignments. When the agent encounters certain technologies in the target, coverage templates point it to the relevant KB entries and testing procedures.

This creates a feedback loop: as your team documents findings and testing approaches, future AI assessments become more targeted.

TIP

Treat the knowledge base as a living document. Update it after each assessment with lessons learned, new attack patterns, and application changes.

Hashiro. Continuous Threat Exposure Management.