Strix — an open-source AI agent–based tool for penetration testing and DevSecOps

Tools2026-07-10, 15:29
Strix is a multi-agent framework for automated vulnerability discovery. It is built on open-source projects such as LiteLLM, Caido, Nuclei, Playwright, and Textual. Strix runs in a Docker environment and requires an LLM API key, while also supporting local models.
Features: • Full penetration testing suite: HTTP proxy, OWASP Top 10 checks, SAST/DAST, OSINT, and PoC generation in a sandbox • Multi-agent orchestration: parallel testing and knowledge sharing between agents • Real-world validation: each vulnerability includes a working PoC and reproduction steps • Integrations: GitHub, GitLab, Bitbucket, Slack, Jira, and CI/CD • Automatic fix and report generation
Vendors
Berriai
Caido
Projectdiscovery
Microsoft
Textualize
Usestrix
Products
Bitbucket
Caido
Docker
Github
Gitlab
Jira
More