Automatic Penetration Tests
How scheduled Hannibal hunts run from Settings → AI, what hunt profiles add, and when the card pauses or locks.
Automatic Penetration Tests on Settings → AI is the Hannibal schedule for this account. Card copy: When on, Hannibal starts hunts automatically when AI budget headroom is available. No profiles required. Manual hunts still work when this is off.
Turn it on
- Flip the switch on the card.
- Review the confirmation dialog, which lists the hunt profiles that will run.
- Confirm. Guard shows Automatic pen tests on with the scope summary.
Turning the switch off shows Automatic pen tests off. Profile changes save as you make them.
Hunt profiles
Profiles are optional. With no profiles, Hannibal runs with its defaults. Expand the card and click Add hunt profile to create one. The Scheduled hunt profile wizard has these steps:
- Set Infrastructure Scope: All infrastructure (every active target in Guard) or Specific infrastructure.
- For specific infrastructure only: Attack surface (External, Internal, Cloud, Web, or LLM), then Select assets.
- Set Objective: Profile Name (defaults to
Hunt Nwhen blank) and Hunt Mandate. Guardrails are shown read-only; Praetorian enforces them. - Aggressiveness:
- Cautious: narrow iterations; confirms one vulnerability at a time and does not follow leads to related infrastructure.
- Balanced (default): follows high-value leads and pivots to related infrastructure when the evidence warrants it.
- Aggressive: deep multi-hop pivots and attack chaining; records confirmed chains as attack graphs in the Attack Paths tab.
Each profile row shows its agent, aggressiveness, and scope. Use the row controls to move a profile up or down, edit it, or remove it. You can add up to 50 profiles.
When the card is locked or paused
- AI Autonomy must be on to edit the card. It is a Praetorian-managed flag; see AI Feature Toggles. While it is off, the card is dimmed and shows Enable AI Autonomy first.
- When the Autonomous Penetration Testing slice of Category Allocation is $0, the card shows Paused — category budget is $0. Scheduled hunts wait for budget. The switch stays on.
- If Guard cannot read the stored schedule, the card is shown read-only so a save cannot replace it with defaults.
Who can edit
Users with permission to manage settings, while AI Autonomy is on. Others see Requires the manage settings permission.