As cited
Copy frozen at (site build).
research
Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human
Elastic implemented an AI-powered triage system for bug bounty reports on HackerOne that costs approximately $2 per report and agrees with human security engineers 85% of the time. The system uses an eight-stage analysis pipeline with adversarial review on one VM and a separate reproduction VM for validation, orchestrated through Elastic Workflows with automatic 30-minute shutdowns. The approach addresses the scaling challenge created by LLMs making report generation nearly free, which increased Elastic's submissions from 600-850 annually to over 1,390 in the first half of 2026.
Why it matters: Security teams managing high-volume bug bounty programs need cost-effective triage methods as AI-generated submissions overwhelm manual review capacity. Practitioners can adopt this two-phase architecture and adversarial review pattern to reduce triage costs while maintaining human final decision authority.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
research
Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
research
Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human
Elastic built an artificial intelligence (AI) agent system to triage HackerOne bug bounty reports at approximately $2 each, achieving 85% agreement with human security engineers on a validation set of 764 reports. The two-phase pipeline uses separate compute-isolated virtual machines for analysis (which applies an eight-stage assessment with adversarial review) and reproduction (which runs submissions in sandboxed Elastic Stack environments), with humans making final decisions on all reports. The system was created to address a scaling challenge where large language models dramatically increased submission volume in the first half of 2026 to over 1,390 reports, while the cost of human triage remained constant.
Why it matters: Security teams operating bug bounty programs should evaluate AI-assisted triage to manage the operational burden of high-volume, low-signal submissions without sacrificing decision quality or security.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
research
Agents vs. agents: how we triage HackerOne reports for $2 each, 85% as well as a human
Elastic built an artificial intelligence (AI) agent system to triage HackerOne bug bounty reports at approximately $2 each, achieving 85% agreement with human security engineers on a validation set of 764 reports. The two-phase pipeline uses separate compute-isolated virtual machines for analysis (which applies an eight-stage assessment with adversarial review) and reproduction (which runs submissions in sandboxed Elastic Stack environments), with humans making final decisions on all reports. The system was created to address a scaling challenge where large language models dramatically increased submission volume in the first half of 2026 to over 1,390 reports, while the cost of human triage remained constant.
Why it matters: Security teams operating bug bounty programs should evaluate AI-assisted triage to manage the operational burden of high-volume, low-signal submissions without sacrificing decision quality or security.
- Source published
- First seen by Cybersecurity Tracker