01
Open the live campaign
Public sample. No account. Pick the exploitable or hardened fixture.
Point Provenant at an agent, a system prompt, a retrieval corpus, or an MCP export. It runs adversarial campaigns — jailbreak, extraction, indirect injection, agency abuse, tool poisoning, grant attacks — and returns EXPLOITABLE or HARDENED with the payload that landed.
Red-team walkthrough · target, attack, verdict
Campaign loop
Four stages. No architecture diagram. No control catalogue. An attacker workflow.
Where to start
Same order every time. The live campaign is the product; the video is the briefing.
01
Public sample. No account. Pick the exploitable or hardened fixture.
02
Target in, packs fire, hit/miss log, verdict. That is the product.
03
Jailbreak, extraction, indirect injection, agency, MCP, grants — in one campaign.
04
Paste a system prompt, RAG corpus, or MCP tools/list and attack that.
05
When you want us on production agents, request a campaign.
Attack surface
Provenant does not inventory your cloud account. It attacks the text and grants the model will ingest.
Campaign packs
Each pack is a battery of techniques. Together they are the red team.
Pack 01
Instruction override, developer-mode role-play, delimiter and markup breakout against the system prompt.
Pack 02
Force the model to recite hidden instructions and any secrets that were planted in the prompt or tools.
Pack 03
Poisoned RAG documents and agent memory the model treats as trusted context — no user jailbreak required.
Pack 04
Skip confirmation, fire write or egress tools, replace the agent’s goal with the attacker’s.
Pack 05
Adversarial text inside tool descriptions: injection, concealment, exfil, shadow tools, invisible Unicode.
Pack 06
Wildcard scopes, unsigned manifests, static secrets, live tools nobody declared. Privilege, not paperwork.
Evidence
A finding is a technique that landed. A miss is a technique that did not. The report is that log, signed.