Random agents vs. disciplined engagements
Enterprises rightly distrust “AI that just tries things.” Offensive security only earns a seat when behavior is:
- phased like a professional test;
- explainable against shared vocabularies;
- repeatable across missions;
- bounded by authorization.
AgentRidge’s Mission Control loop is not free-form chat with tools. It is an engagement engine whose default strategy tracks the spirit of the Penetration Testing Execution Standard (PTES) and whose observed actions can be narrated in MITRE ATT&CK terms for purple-team and detection engineering peers.
This article shows the shape of that alignment. It does not publish a private playbook of exploits or module knobs.
PTES as the agent’s rhythm
PTES describes how serious testers move from prep to reporting. AgentRidge mirrors that rhythm in autonomous form:
1. Pre-engagement interactions → Mission brief
Humans define legal scope, contacts, RoE, load limits, and Definition of Done. The agent does not invent the contract; it consumes it as immutable mission context (targets, CIDRs, domains, forbidden techniques).
2. Intelligence gathering → Purposeful recon
The agent collects DNS, mail, TLS, service, and application context on in-scope assets. Unlike a spray-and-pray scan, recon is biased toward signals that feed later threat modeling (identity, trust, data).
3. Threat modeling → Attack hypotheses
Before noisy action, AgentRidge forms hypotheses: which surfaces could combine into paths toward the engagement goal (e.g., AD-relevant impact, sensitive data exposure). Catalog knowledge (OWASP-oriented web cases, AD/lab patterns) informs prioritization—still inside scope.
4. Vulnerability analysis → Evidence-seeking, not banner worship
Candidates are analyzed for relevance to the graph, not merely CVSS from a feed. Version smells may open a lead; they do not auto-become critical without context.
5. Exploitation → Guided, validated, RoE-limited
Exploitation is guided: bounded proofs, prefer non-destructive demonstration, escalate depth only when the mission mode and RoE allow (auditor vs. attacker profiles). Success is a validated hop, not a trophy shell for its own sake.
6. Post-exploitation → Controlled chaining
When permitted, the agent explores lateral and privilege paths that complete the business question—then stops when DoD or RoE halt conditions hit. Looting and destructive actions stay off-menu unless explicitly authorized (they are not in default enterprise profiles).
7. Reporting → Decision artifacts
Findings, graphs, remediations, and reproduction trees are assembled for COMEX and engineering (see our companion article on deliverables).
The point: phase discipline is visible in Mission Control timelines even when individual tool invocations stay under the hood.
MITRE ATT&CK: a shared language for coverage
ATT&CK does not replace PTES; it labels adversary-relevant techniques so defenders can map tests to detections. AgentRidge missions, especially in Pro attacker mode on enterprise scopes, routinely exercise techniques across the tactics below.
Coverage here means: the agent is designed and observed to attempt or simulate these technique classes under authorization—not that every technique succeeds everywhere, and not that every sub-technique ID is a guaranteed exploit.
Coverage map (enterprise-oriented palette)
Representative technique IDs (illustrative, non-exhaustive)
For purple teams who want ATT&CK IDs in detection engineering backlogs, missions commonly touch classes such as:
- T1595 Active Scanning
- T1592 / T1589 Gather Victim Host / Identity Information
- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1046 Network Service Discovery
- T1087 / T1069 Account & Permission Group Discovery
- T1482 Domain Trust Discovery
- T1021 Remote Services
- T1550 Use Alternate Authentication Material (when applicable and allowed)
- T1068 Exploitation for Privilege Escalation
Exact success depends on the target. The methodological claim is that the agent plans with these classes in mind, then records outcomes in a way defenders can map—not that it is a clone of every APT group’s toolkit.
OWASP alongside PTES / ATT&CK
For web and API scopes, AgentRidge’s catalog and prompts are explicitly OWASP-aware (injection classes, SSRF, XSS, access control, etc.). OWASP informs what to look for on apps; PTES informs how the engagement flows; ATT&CK informs how to describe adversary-relevant behavior to blue teams.
Three lenses, one mission.
What “coverage” is not
To keep this publication honest:
- Coverage ≠ 100% of ATT&CK (no product has that in a meaningful sense).
- Coverage ≠ automatic bypass of every control.
- Publishing IDs ≠ publishing exploits.
- Lite domains (deep cloud CSPM, RF wireless, full SE campaigns) remain thinner than web/AD/network cores—as reflected in our capability scorecard work.
How buyers should use this alignment
- Procurement — Ask vendors which phases and ATT&CK tactics their agent actually drives; reject “AI magic” without phase language.
- Purple team — Import AgentRidge reproduction trees into detection gap analysis labeled with ATT&CK IDs.
- Audit — Show PTES-shaped timelines as evidence of structured testing, not ad-hoc scanning.
- Risk committee — Tie residual risk to uncovered tactics, not raw CVE counts.
Takeaway
AgentRidge’s autonomy is methodological, not stochastic. PTES gives the engagement its spine; ATT&CK gives defenders a shared map of which adversary behaviors were exercised; OWASP sharpens the web edge.
That is what “serious” looks like when an AI agent is allowed near production: structured, namable, and accountable—never improvised for its own sake.
Cite this article
Azuro Consulting & Amara Okafor (2026). PTES Rhythm, ATT&CK Coverage: AgentRidge Does Not Improvise Its Methodology. Azuro Insights, Azuro Software. https://insights.azurosoft.com/research/agentridge-ptes-mitre-attack-methodology/
@techreport{azuro2026agentridgeptesmitreattackmethodology,
title = {PTES Rhythm, ATT&CK Coverage: AgentRidge Does Not Improvise Its Methodology},
author = {Azuro Consulting & Amara Okafor},
institution = {Azuro Software — Azuro Insights},
year = {2026},
url = {https://insights.azurosoft.com/research/agentridge-ptes-mitre-attack-methodology/}
}