Approve
Before anything touches the target
Scope, rules of engagement and every active check are signed off by a tester before they run. Nothing probes a host that was not on the list.
Foxhound
Foxhound automates approved assessment steps within your scope. A tester approves active testing, investigates the results, and signs off findings before delivery.
You deploy every week. The assessment happens once a year, and what you get back is a static PDF. No live view while the work is happening, no retest loop when you fix something, no trail you can query afterwards.
The model
Automation handles the approved routine steps. Testers own the approvals, the verification, and the manual depth on top.
Approve
Before anything touches the target
Scope, rules of engagement and every active check are signed off by a tester before they run. Nothing probes a host that was not on the list.
Verify
Before any finding reaches you
A tester reproduces a finding and writes its remediation guidance before it reaches you. Anything that does not reproduce does not get delivered.
Methodology
Automated steps follow published methodology, so coverage stays consistent between engagements rather than depending on what a tester happened to recall.
Measured against
What you get
Findings land as they are confirmed, not at the end. Critical and high severity issues are flagged the day we verify them, so your team can start remediation while the assessment is still running.
A branded PDF with an executive summary in plain language for leadership, and a technical section your engineers can work from. Download it as often as you need.
A scoped REST API and a Model Context Protocol endpoint. Pull findings into your own systems, or query engagement status from your AI tooling.
Fix something, request a retest, and we confirm it and update the finding. There is no separate invoice for that.
Tailoring
There is no separate bespoke service to buy. Foxhound carries the automated work, and the parts of an engagement that need a human decision are where we shape it around your environment.
Scoped to your environment
Before the first run
We work through your architecture, your threat model, and what is genuinely off limits, then encode that as the scope the agent runs against. Blackbox, greybox or whitebox, whichever actually tells you something.
Manual depth on top
Where the agent stops
Business logic flaws, chained vulnerabilities and access control gaps that only surface once someone understands how your application is meant to work. A tester goes after those directly, in the same engagement, and the findings land in the same portal.
Your own instance, if you need it
Regulated environments
Run on Fenko’s managed platform, logically isolated per engagement, or on a dedicated deployment with no shared compute or data plane where data residency requires it.
Vulnerability research
Foxhound is pointed at client scope, but the same passes surface bugs in the software underneath. Some of this we found. Some of it we verified for the vendor after another researcher reported it. Each card says which.
Decoders across TLS, DHCPv4, sFlow, IPSec AH, VRRPv2, Diameter, GTPv1-U, ERSPAN II, LCM, RadioTap and Dot11 read or slice packet data using attacker-controlled length, count and offset fields before checking them against the buffer. A malformed packet panics the decoding goroutine, reachable through DecodingLayerParser or a direct DecodeFromBytes.
An integer underflow on the vendor header size lets a single crafted message drive an unbounded allocation of roughly 4 GiB, exhausting memory without authentication.
A 104-byte UDP datagram reaches an attacker-controlled make in the ExtendedGatewayFlow decoder and can request up to 16 GiB, exhausting memory without authentication.
Foxhound flagged a grizzly/2.4.4 banner on a pre-auth endpoint. The parser ends a header name at the first colon without checking for CR, LF or space, so a Content-Length tucked into a header name never gets treated as framing.
Further advisories are in coordinated disclosure and will be listed here once they are published.
Where the work lands
Safe by design
The agent works from an approved scope and has no way to widen it on its own. Out of scope means stop, not warn.
In context
| Measure | Annual consultant | DIY scanners | Foxhound |
|---|---|---|---|
| Speed | Weeks | Minutes, noisy | Hours, verified |
| Output | Static PDF | Raw tool output | Report and live portal |
| Coverage | What one tester knows | Whatever the signatures cover | The full methodology, every run |
| False positives | Filtered by the tester | Yours to triage | Filtered before delivery |
| Retest | Scoped and quoted again | Run it yourself | Requested in the portal, included |
Web applications, REST and GraphQL APIs, mobile apps on iOS and Android, internal and external network infrastructure, cloud configuration across AWS, Azure and GCP, source code, and AI systems including prompt injection and agent tool-use testing.
Full coverage is described on the penetration testing page.
Tell us what you want assessed and we will quote against the scope. Pricing is per trigger, not per URL or per IP, because those penalise a fair account of your own attack surface.