EN
Back to the archive

The archive · Developer & Business Tools · Strategic decision · 2025–2026

Strix bets open-source AI agents that prove exploits beat scanners

Open-source pentest agent hits #1 GitHub Trending with 47k+ stars; XBEN benchmark shows 100/104 exploits at ~$3.37 each.

Strix

The betThat an open-source agent that proves each finding with a working exploit — not a scanner reporting suspects — wins developers over slow, expensive manual pentests.Live

What the business is

Strix is a San Francisco startup selling autonomous penetration testing: an Apache-2.0 agentic CLI that dynamically explores code and apps, runs exploits, and attaches a proof-of-concept to every finding, plus a hosted platform with self-hosted and enterprise options.

How it started

Ahmed Allam moved from Egypt to San Francisco after roles at Synapse Analytics and Microsoft, worried that AI-generated code — which he says studies link to serious security vulnerabilities in at least 45% of cases — was outrunning traditional testing. With a cybersecurity-expert co-founder he met at university, he built agents that could run penetration tests in hours instead of weeks, and launched Strix through Hacker News.

What happened

The HN launch hit #1 within hours (600+ GitHub stars overnight) and brought accelerator backing from Alif plus advocates inside large enterprises. The open-source repo then compounded: Runa's ROSS Index logged ~17.1k stars by Q4 2025; on July 3, 2026 the repo hit #1 on GitHub Trending with +2,137 stars in a day, reaching roughly 47k stars by mid-2026. Independent reviewers documented Strix solving 100 of 104 XBEN web-security challenges (~96%) at about $3.37 per challenge in model cost (~$337 total, ~19 minutes per challenge), with each finding shipped as a reproducible proof-of-concept. By August 2026 the company also sold a hosted platform — Pro at $29 per seat per month with pentests billed separately, plus enterprise VPC and on-premises options.

How it ended up

Live: as of September 2026 the company continues shipping (v1.4.1 on July 27, 2026) and is converting open-source traction into a hosted security business.

Background

Strix is a San Francisco startup founded by Ahmed Allam, who moved from Egypt after roles at Synapse Analytics and Microsoft, together with a cybersecurity-expert co-founder he met at university. Their premise: AI-generated code was outrunning traditional security testing — Allam cites studies linking AI code to serious vulnerabilities in at least 45% of cases — so companies needed penetration testing that could run continuously, in hours rather than weeks, inside the development workflow.

The product is an Apache-2.0, open-source agentic penetration-testing CLI. Strix orchestrates a 'Graph of Agents' — reconnaissance and OSINT, exploitation, and post-exploitation subagents that share context — against code, URLs or APIs, executes real attacks dynamically, and ships every confirmed finding with the exact request or payload that reproduces it plus a suggested fix. Unlike scanners that emit candidate findings for humans to triage, Strix reports a bug only after it has exploited it.

Open source was the go-to-market: Strix launched on Hacker News in 2025, hit #1 within hours and gained 600+ GitHub stars overnight, according to Entrepreneur UK, with accelerator backing from Alif following. The repo compounded from there — roughly 17.1k stars by Q4 2025 per Runa's ROSS Index, then #1 on GitHub Trending on July 3, 2026 with +2,137 stars in a single day and about 47k stars by mid-2026 per a dev.to review. Independent write-ups documented a 100-of-104 solve rate on XBEN web-security challenges (~96%) at about $3.37 per challenge in model spend, ~19 minutes per challenge.

By August 2026 Strix paired the free engine with a hosted platform: Pro at $29 per seat per month with pentests billed separately, and enterprise offerings with VPC or on-premises deployment, per an independent security consultancy's buying guide. The company keeps shipping — v1.4.1 arrived July 27, 2026 — and its bet is that developers who adopted the open-source agent will become the hosted platform's paying customers.

What has to be true

  • Open source from day one turned security skeptics into contributors: developers could read, run and break the tool before buying anything, and a #1 Hacker News launch validated it within hours.
  • Proving over scanning changed the buying metric: every finding arrives with the request or payload that reproduces it, making value demonstrable instead of a list of suspects awaiting manual triage.
  • Timing rode the AI-code wave: with AI-generated code linked to serious vulnerabilities, automated testing addressed a widely felt gap instead of inventing one.
  • Hosted plus open source captured both trust and budgets: the free engine built the community while per-seat pricing, per-pentest billing and VPC or on-prem options monetized companies.

What can be applied

Prove, don't report: an open-source tool that attaches a working exploit to every finding turns 'trust us' into demonstrable value — and viral GitHub growth into enterprise doors.

Aftermath

As of September 2, 2026 Strix is live and converting GitHub virality into a business. The repo, launched through Hacker News in late 2025, passed roughly 17.1k stars by Q4 2025 (ROSS Index), hit #1 on GitHub Trending on July 3, 2026 (+2,137 stars that day), and stood near 47k stars by mid-2026 (dev.to). An independent consultancy documented the repo, releases (v1.4.1, July 27, 2026), XBEN results and pricing in August 2026. The challenge now is turning a tool developers love into recurring revenue before an open-source clone appears.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases