Why we built the infrastructure behind continuous testing — and what it says about where application security is headed.
Arcane Security Engineering Blog
February 2026
The Two Camps That Defined — and Limited — Our Industry
If you’ve spent any time in application security, you’ve seen the same debate play out a hundred times. Somebody on the engineering side says “we should just automate our security testing,” and somebody on the security side says “automated scanners miss everything that matters.” They’re both right. And they’re both wrong.
Camp 1: Automated scanners. They’re fast. They scale. They’re great at catching infrastructure-level issues — misconfigurations, missing headers, known CVEs. But they’re noisy. They produce mountains of false positives. And they’re completely blind to business logic flaws, which tend to be the vulnerabilities that actually get exploited in the real world.
Camp 2: Manual penetration testers. They’re thorough. They think creatively. They understand context in ways no automated tool can. But they’re slow, expensive, and don’t scale. A great pentester might spend two weeks with your application and produce a phenomenal report — and then your dev team ships 47 commits the following Monday and the report is already stale.
But here’s the part nobody talks about: even within Camp 1, there’s a massive problem that goes beyond just missing business logic. The scanners themselves are drowning their operators in noise.
The Dirty Secret of Security Scanners: The Noise Problem
Run Burp Suite against a modern web application. You’ll get back dozens, sometimes hundreds, of findings. Now sit down and actually triage them. You’ll discover that a significant percentage are false positives, informational noise, or findings that are technically accurate but carry zero real-world risk.
The same thing happens with cloud security. Run ScoutSuite against an AWS account and you’ll get flagged for default VPC security groups in 15 regions — but only 2 of those regions have any running resources. You’ll get flagged for an open SSH security group that isn’t attached to a single EC2 instance. Technically a finding. Practically meaningless.
Some real examples from our own scanning:
- Burp flags “Input returned in response (reflected)” on a .css file. That’s not XSS. It’s a stylesheet.
- Burp flags “Frameable response (potential Clickjacking)” on an API endpoint that serves JSON. You can’t clickjack a JSON response.
- ScoutSuite flags an IAM user without MFA — but the user has no console access. It’s an API-only service account.
- ScoutSuite flags S3 bucket policy issues, but public access is fully blocked at the account level. The findings are moot.
This is the noise that security engineers spend hours manually triaging after every scan. It’s the reason automated scanning has a credibility problem. Not because the scanners are bad — Burp Suite and ScoutSuite are both excellent tools — but because nobody has built the intelligence layer on top of them to separate signal from noise automatically.
Until now.
The Thesis: AI-Augmented Human Judgment, Running Continuously
At Arcane Security, our bet is that the future of pentesting isn’t about choosing between automation and humans. It’s about building infrastructure that lets them work together in a continuous loop, each doing what they’re best at, with AI helping prioritize, correlate, and reduce noise between the two.
Here’s what that looks like in practice:
- Automated discovery runs continuously — scanning web applications and cloud configurations on an ongoing basis.
- Intelligent triage eliminates the noise — false positive reduction through pattern-based rules and cross-reference validation.
- Human pentesters validate and go deeper — focusing their time on real issues.
- AI accelerates everything in between — prioritizing findings and eventually validating them autonomously.
This isn’t a theory. It’s the architecture we’ve built. And it’s called Project Theta.
Why We Built Our Own Security Scanning Platform
If the vision is continuous automated discovery feeding into intelligent triage feeding into human validation, the first thing you need is a scanning platform you actually control.
We looked at what was available. Nothing fit.
The Landscape We Evaluated
Enterprise SaaS platforms like Qualys, Rapid7, and Tenable are powerful, but they’re built for compliance teams and SOCs. They produce dashboards for CISOs. They don’t integrate naturally into a pentester’s workflow.
Open-source DAST tools are getting better, but they lack the scanning depth of Burp Suite Professional.
Burp Suite and ScoutSuite themselves are excellent — but they’re standalone tools, not orchestration platforms.
So we built the infrastructure to run them the way we needed.
Project Theta: A Unified Security Scanning Platform
Project Theta is a Python-based platform that provides a unified REST API and CLI wrapping two types of security scanning under one roof:
- Web Application DAST — powered by Burp Suite Professional
- Cloud Configuration Security Reviews — powered by ScoutSuite
On top of both scanners sits the key innovation: a false positive reduction layer.
The Architecture
| Component | Role |
|---|---|
| Server 1: Theta Client + API | Runs the FastAPI server, CLI, and ScoutSuite orchestration. |
| Server 2: Burp Server | Runs Burp Suite headlessly and exposes its REST API. |
A single POST /scan endpoint dispatches to either Burp or ScoutSuite depending on the scanner type.
The Unified API
| Endpoint | Purpose |
|---|---|
| POST /scan | Start a scan |
| GET /scan/{id}/status | Poll scan status |
| GET /scan/{id}/report | Download HTML report |
| GET /scan/{type}/{id}/findings | Retrieve findings JSON |
| POST /scan/{type}/{id}/runbook | Apply false positive reduction rules |
| POST /scan/scoutsuite/{id}/validate | Run active cloud validators |
These capabilities move scanning from a manual task to a repeatable workflow.
The Intelligence Layer: False Positive Reduction
Scanning is a solved problem. Figuring out which findings matter is not.
Theta approaches this using two techniques:
Approach 1: Runbooks
Runbooks are static JSON rule files encoding patterns of known noise.
- “Input returned in response” on .css or .js files
- “Frameable response” on /api endpoints
- “Strict transport security not enforced” on http
- Informational severity with tentative confidence
Approach 2: Active Validators
Active validators analyze scan data contextually to confirm or reject findings.
| Validator | What It Checks | Example False Positive |
|---|---|---|
| Security Group Open Ports | Is SG attached to an instance? | Open SSH on unused SG |
| Default VPC | Does region have resources? | Empty region flagged |
| IAM User Without MFA | Console access? | API-only account |
| S3 Public Access | Is public access blocked? | Account-level block enabled |
In one test run we reduced 45 findings to 22 confirmed issues.
What used to take hours now takes seconds.
The Hard Problems Nobody Talks About
Running Burp headlessly in the cloud required license activation via X11 forwarding followed by systemd-managed operation.
The Java compatibility wall forced us to replace the standard Burp API wrapper with a custom Python adapter.
ScoutSuite runs as a subprocess because it cannot be imported as a library.
Unifying two scanners and multiple APIs into one platform required careful abstraction.
First Blood: The Proof of Concept
On February 10, 2026, Theta completed its first automated scan against scanme.nmap.org.
| Metric | Result |
|---|---|
| Crawl Requests | 48 |
| Unique Locations | 7 |
| Audit Requests | 4,082 |
| Vulnerabilities Found | 15 (1 Low, 14 Informational) |
The real value is that the entire pipeline ran automatically from command to report generation.
Where This Is Going
Theta currently covers phases 1–3 of our roadmap.
Next phases include AI-powered validation, queue-based orchestration, containerization, Kubernetes deployment, and observability.
The Bigger Argument
The companies that will lead the next era of security will combine automation, intelligent triage, and human expertise into one continuous pipeline.
Scanners won’t replace pentesters. AI won’t replace either.
But pentesters augmented by AI and continuous discovery will outperform everyone else.
Theta is how we’re building toward that future.
And we’re just getting started.
—
Built by Arcane Security. For questions, collaboration, or to learn more about Project Theta, get in touch.