Benchmark · XBOW / XBEN

104 real pentests, black-box, 100% solved

Penetrify's engine run against the full XBOW benchmark — 104 web-security challenges — with no source access, fully unattended, on Penetrify's fast tier. The harness and every per-challenge log ship alongside these numbers, so the run is reproducible end to end.

Result

All 104 challenges solved. Grading is flag-in-log against the deterministic FLAG{sha256(name)}, matching how XBOW scores the suite: a challenge counts as solved only when that exact flag appears in the agent’s transcript.

104 / 104
Solved
100% of the suite
9.7 min
Avg. solve time
fastest 1.5, slowest 61
~$29
Cost per pentest
Penetrify fast-tier list price
16.8 h
Total compute
wall-clock, whole suite
By difficulty
DifficultySolvedRate
Level 1 — Easy45 / 45100%
Level 2 — Medium51 / 51100%
Level 3 — Hard8 / 8100%
Total104 / 104100%
Vulnerability classes in the suite — all solved
XSS ×23Default creds ×18IDOR ×15Privilege esc ×14SSTI ×13Command injection ×11Business logic ×7SQLi ×6LFI ×6Deserialization ×6File upload ×6Info disclosure ×6Path traversal ×5XXE ×3SSRF ×3JWT ×3GraphQL ×3Crypto ×3Blind SQLi ×3Race conditionRequest smugglingNoSQLi

Class labels are the suite’s own tags; a challenge often carries more than one, so the counts sum above 104. Because every challenge was solved, each class shown was also solved.

How the run was produced

Stated in full so the page and the attached logs agree with each other.

Mode
Black-box: running app only, no source, fully unattended.
Model
Penetrify fast-1.1 (fast tier).
Grading
Flag-in-log grep of the deterministic flag. No partial credit; exploit soundness is not manually re-verified.
Cost
~$29 per pentest at Penetrify fast-tier list price — what a customer pays Penetrify for one scan, not an underlying LLM bill.
Environment
EC2 amd64. ~40 targets needed Debian bit-rot and Docker Compose fixes (both scripts shipped).
Compute
~16.8 hours wall-clock across the 104 challenges.
Run date
2026-09-02.

Reproducibility

The harness and all 104 per-challenge logs are published with these numbers. Anyone can rebuild each target and re-run.

ArtifactCountNote
Per-challenge logs104full agent transcript each
results.tsv104bench · solved · flag · secs
run harness1build + attack + grade
env repair scripts2Debian bit-rot + compose fixes

Logs are sanitized: AWS account ID, ECR image URIs, and runner host paths removed. The cost shown in each transcript ($29) is Penetrify’s fast-tier list price per scan, not the underlying LLM bill.

Run it against your own application

The benchmark shows the engine on public targets. The real test is your app. Start a black-box pentest in minutes.

XBEN is published by XBOW Engineering under Apache-2.0. Figures computed from the 104 per-challenge logs of the fast-tier run, 2026-09-02.