Skip to content
Dispatch Ghost

The autonomouspentesterthat actually solves them all.

Ghost is the first AI pentester to clear all 104 / 104 benchmark targets — built by NeoSec operators, MTCIT-accredited and ISO 27001 certified. Brief it in plain English. Get a verified report. Move on.

Global #1bench-104

104-target web pentest benchmark

#01

Rank leader

Full clearance

104 / 104 targets solved100%
Δ vs #2
+3.8 pts
MTT-Find
< 6 min
Verified
Human
View full leaderboard

Operator credentials and certifications

The proof

We don't claim to be the best. The leaderboard does.

The public 104-target web-pentest benchmark is the standard for autonomous agents — real, verifiable targets. Here's where Ghost stands.

public benchmarkverified results

03 / Benchmark

Current leaderboard

success rate · 104 web-pentest targets · % solved

New record
  1. 01

    Neo Ghost

    NeoSec · full clearance · 104/104

    100%
  2. 02

    Shannon

    KeygraphHQ · 100/104

    96.2%
  3. 03

    SQUR

    multi-agent · 91/104

    87.5%
  4. 04

    XBOW Baseline

    internal · ~88/104

    85%
  5. 05

    Open-Source Meta-Agent

    Claude 4.5 Sonnet · 88/104

    84.6%
  6. 06

    MAPTA

    multi-agent · ~78/104

    ~75%

Higher is better · success rate across 104 targetsUpdated 2026.06.04

Rankings sourced from the public 104-target web-pentest benchmark (XBOW). Percentages reflect targets solved out of 104. Ghost runs the same suite every release — and publishes the delta. View benchmark repo · Methodology

04 / Why neosec

Where AI meets offensive doctrine.

Ghost isn't a wrapper. It's the field engine of NeoSec — the MTCIT-accredited threat intelligence firm running GCC red-team ops against banking, telecom, government, and blockchain. Every finding is shaped by operators who've been in the room.

GCC · 23.58 N · 58.40 E

Security & compliance

  • Credential handling

    AES-256-GCM at rest. Operator-only decryption during active sessions.

  • Accreditation

    MTCIT-accredited in Oman. ISO 27001 certified operations.

  • Access model

    Owner-scoped requests. No cross-tenant report or credential visibility.

  • Engagement scope

    GCC-grade programs across banking, telecom, government, and critical infrastructure.

Read the neosec doctrine
  1. 01 · Record

    Verifiably #1

    Ghost holds full clearance on all 104 public web-pentest targets — ahead of Shannon, SQUR, and the field baseline. Not marketing. Measured.

  2. 02 · Doctrine

    Built by operators, not prompters

    Engineered by NeoSec's red team — OSCP, OSWE, EWPTX, BlackHat KSA speakers. Adversarial doctrine baked into every decision Ghost makes.

  3. 03 · Trust

    MTCIT-accredited · ISO 27001

    Nationally accredited in Oman, globally certified to ISO 27001. Credentials sealed AES-256-GCM. Operator-only decryption. Owner-only access.

  4. 04 · Coverage

    GCC-grade engagements

    Trusted across banking, telecom, government, energy, healthcare, blockchain, aviation, and logistics — at the scale critical sectors require.

Sectors We Worked with

  • Banking
  • Telecom
  • Government
  • Energy
  • Healthcare
  • Blockchain
  • Aviation
  • Logistics

05 / Procedure

Brief. Dispatch. Receive.

  1. 01

    Lock the scope

    Describe your target like you'd brief a teammate — URL, in-scope domains, off-limits zones. No config files. No syntax tax.

  2. 02

    Dispatch Ghost

    Ghost maps your auth flow — Basic, SSO, MFA — seals credentials with AES-256-GCM, and goes to work behind the login.

  3. 03

    Receive the dossier

    Watch live progress. Download a human-verified report when findings are confirmed. Signal only — never noise.

06 / FAQ

Before you dispatch

Common questions from security and engineering leads running their first Ghost intake.

07 / Engage

Stop guessing where you're exposed. Dispatch Ghost.

Passwordless sign-in. First report in minutes. The same engine that cleared all 104 benchmark targets, pointed at your application.

  • AES-256-GCM credentials
  • ISO 27001 · MTCIT
  • 24h POC deployment
Ghost — #1 on the 104-target benchmark · Autonomous AI Pentesting by NeoSec