Kuala Lumpur, MY GMT +8

We find what others miss. Before attackers do.

4rthur is an AI-driven offensive security firm. We combine proprietary tooling with specialist-led validation, delivering security assessment that is faster and more consistent than anything else in the market.

// AI-DRIVEN OFFENSIVE SECURITY
// OUTCOMES, NOT MAN-DAYS
// HUMAN-VALIDATED, FULLY TRACEABLE
/// The guarantee

Pay on success.

If we find nothing that can be exploited in the agreed scope, you owe us nothing. Full refund. No questions.

Full refund if no Medium, High, or Critical finding is produced.

Low-severity findings, informational issues, and hardening recommendations do not count toward the threshold.

We put our tooling, our methodology, and our commercials on the line. Every engagement.

01 / The problem

The Malaysian pentest market is outdated.

"Checkbox" Mentality
0%
of pentest performed is solely to satisfy annual requirements, or for audit.
Kickoff Time
0days
average kickoff session scheduling. Clients have to wait for the pentest to even start.
Man-Days Billing
0Hours
A day, that is what clients are paying for. Pentesters' time, not result.
02 / The solution

We kill the man-day.

Companies spend a lot of money on pentests and still get breached because testers ran out of billable days, not attack paths. 4rthur goes from paying under man-days to result-oriented outcomes.

The old model
4rthur
Pay for hours worked
Pay for goals achieved
Constrained by human capacity, time, and fatigue.
Scales continuously with 24/7 autonomous testing capabilities.
Typically requires months for engagements.
Accelerates delivery to days or weeks.
Results may vary depending on tester expertise and conditions.
Provides consistent, repeatable testing with standardized processes.
03 / The tooling

AI-assisted, Offensive Security.

Proprietary AI tooling covering the full external surface from reconnaissance, dynamic analysis, to static review. Built to feed each other. Validated by humans before it reaches your inbox.

// TOOL 01 — L4NCELOT

Attack Surface Discovery

Maps the full external footprint before a single manual test begins. Subdomains, exposed services, misconfigured cloud buckets, before the adversary gets there.

  • External asset enumeration at scale
  • Internet-facing exposure mapping
  • Quick validation of obvious weaknesses
L4NCELOT // RUNNING
$ l4ncelot recon --target ejenali.com [*] resolving subdomains… [+] 12 subdomains discovered [*] getting IPs via DNS resolution [+] Unique IPs identified: 6 [*] exposure analysis [!] EXPOSED admin panel found on ejen.ejenali.com [*] Cloudflare detected [*] saving findings to ejenali_com_note [+] recon completed
// TOOL 02 — G4LAHAD

Autonomous Web App Pentest

Tests web applications like a pentester, fully automated. Logic review, exploit validation, full evidence chain. Achieves autonomous exploitation on XSS, IDOR, Web Cache Deception, and more to come.

  • OWASP Top 10 + API Top 10 coverage
  • Fully black box
  • Proven success in XBOW Lab
G4LAHAD // RUNNING
$ g4lahad --rhost https://app.target --agent idor [*] loading agent IDOR [*] checking target liveness [+] https://app.target confirmed alive and reachable [*] reading agent plans [*] plan a loaded [*] plan b loaded [*] reading web app [*] generating exploit [*] running plan a [!] Vulnerability 1: IDOR on Archive Endpoint [!] Endpoint: GET /order/order_id/archive [+] Exploit chain generated and verified [!] Vulnerability 2: IDOR Chain - Archive-to-Receipt [!] Endpoint 1: GET /order/order_id/archive [!] Endpoint 2: GET /order/order_id/receipt [+] Exploit chain generated and verified [*] plan a completed - 2/2 findings verified [-] Plan A Result saved to result_project_target_planA.json [*] running plan b [*] plan b completed - 0/0 findings verified [-] Plan B Result saved to result_project_target_planB.json
// TOOL 03 — G4WAIN

Agentic Vuln Analyzer

Finds real security flaws in source code, not just pattern matches, but exploitable vulnerabilities traced through actual data flows.

  • Multi-agent pipeline, Agents orchestrated through pydanticAI
  • Adaptive analysis, automatically detects frameworks and architecture patterns
  • Taint analysis with dynamic rules
G4WAIN // RUNNING
$ g4wain scan ./demo-store --output results.sarif --waves 1,2,3,4 [*] Mode: taint-based dynamic fan-out + persistence [*] phase │ recon │ profiling project graph [*] phase │ scope_review │ pruning 38 entrypoints to reachable set [+] agent │ scope_review │ 9 entrypoints retained, 29 pruned [+] phase │ scope_review │ done [3.8s] [*] phase │ wave_1 │ recon-driven hypothesis sweep [*] taint │ recon │ tracing api/orders.py sources=1 sinks=2 [*] taint │ recon │ tracing api/render.py sources=1 sinks=1 [!] agent │ recon │ CRITICAL Authenticated SQL Injection in Order Search @ api/orders.py:42 [!] agent │ recon │ CRITICAL SSTI in Invoice Template Preview @ api/render.py:78 [+] agent │ recon │ 2 finding(s) [+] phase │ wave_1 │ done [15.1s]
[*] phase │ wave_2 │ taint-guided hunter sweep [!] agent │ hunt_sqli │ MEDIUM Second-Order SQLi via Order Tags @ api/orders.py:120 [!] agent │ hunt_ssrf │ HIGH SSRF in URL Preview Service @ api/preview.py:55 [!] agent │ hunt_xss │ HIGH Stored XSS in Profile Bio @ api/profile.py:88 [+] agent │ hunt_sqli │ 1 finding(s) [+] agent │ hunt_ssti │ 0 finding(s) [+] agent │ hunt_ssrf │ 1 finding(s) [+] agent │ hunt_xss │ 1 finding(s) [+] phase │ wave_2 │ done [12.7s]
// TOOL 04 — G4RETH

Assisted Server Exploitation

Goes after the services, hosts, and the network in between. Exploits real weaknesses, and escalates privilege, then turns the whole engagement into a structured VAPT report.

  • Network and service exploitation across the host
  • Privilege escalation and lateral movement
  • Vulnerability chaining with validated proof-of-concept
G4RETH // RUNNING
$ g4reth 192.168.80.144 [*] pinging 192.168.80.144... [+] host is alive. [*] running nmap [*] nmap completed, output at 192.168.80.144.json [*] reading nmap output [+] 5 open ports, 4 services fingerprinted, OS detected: Ubuntu/Linux [+] services detected: [+] 21/ftp [+] 22/ssh [+] 443/https [+] 8080/http [*] running service scan [!] unauth RCE on port 8080 (Total CMS v1.7.2) [+] foothold established — shell on 192.168.80.144
04 / AI-enhanced delivery

Faster execution. Lower cost basis. Higher success rate.

01Information Gathering
days or weeks
within hours
02Attack path discovery
manual enumeration
automated discovery
03Exploit Execution
static tool uses
adaptive exploitation
04Impact Assessment
inflated impact
fully tracable impact
05Report generation
days of writing
ai-generated, human-verified
05 / Pricing

Pay for scope, not man-days.

// Build your estimate Pay-on-success eligible
Attack Surface AssessmentExternal recon
Included · free
Free
Web App
/ endpoints
up to 50
RM 10,000
Mobile App
/ screens
RM 0
Server
/ IPs
RM 0
Network
/ devices
RM 0
AI / LLMRM 30k base + RM 10k per tool-use
Base LLM · RM 30k
Tools
RM 0
Estimated total RM10,000

Standalone attack-surface recon is RM 1,000 — and free the moment you add any package. Full-scope or a bespoke engagement? We'll scope it with you.

Talk to us

Ready to see what we find in your stack?

Book a attack surface assessment. We'll show you the external footprint your attackers already have before you pay for a pentest.