Sonar Launches SonarQube Hunter Agent to Catch Logic-based Security Flaws
Sonar,(opens in new tab) a global leader in AI code verification and governance, today announced the general availability of SonarQube Hunter Agent(opens in new tab), an AI-powered security agent built to catch high-impact vulnerabilities that traditional pattern-based scanning was never designed to find.
Also Read: IT Tech Pulse Exclusive Interview with Ken Claffey Chief Executive Officer and President of VDURA
Closing the gap
Deterministic scanning is excellent at catching flaws that look wrong in the code, including injection vulnerabilities, unsafe data flows, and insecure patterns. However, some vulnerabilities aren’t detectable in the code itself; they’re visible only when you understand what the code is supposed to do. Examples include things like a user who can view another customer’s records, a checkout flow that can be skipped, or a session that doesn’t expire the way it should. In these examples, the code technically runs exactly as written, but it permits something it was never meant to allow.
Traditionally, identifying these types of issues required manual security review or a penetration test. Both of these options are expensive, slow, and ultimately out of date the moment new code ships. As AI-assisted development accelerates the pace of shipping code, the window between release and exploitation is shrinking fast. Catching issues before code ships is now essential to staying ahead of the attackers.
What Hunter Agent does
SonarQube Hunter Agent analyzes a project’s entire codebase to find three categories of flaws that require reasoning, not pattern-matching: broken access control, business-logic vulnerabilities, and authentication or session-management issues.
The agent works the way a human security researcher would, by tracing how code, data, and identity move through a system, then investigating and confirming each candidate issue before it ever reaches a developer. Verified findings land directly inside the SonarQube(opens in new tab) workflow, next to the rest of a team’s issues. This means that security and development teams triage, assign, and track without learning a new tool or switching context.
Because it runs in the background, on a set schedule or on demand, SonarQube Hunter Agent never blocks a pull request or slows down CI/CD. Further, as every finding is confirmed before it surfaces, teams spend their time on real risk instead of sorting through noise.
SonarQube Hunter Agent is designed to complement SonarQube’s existing SAST, not replace it, extending Sonar’s zero-trust, multilayered verification philosophy. It plugs the logic flaw blind spot SAST was never designed to cover. Where SAST catches flaws in how code is written, Hunter Agent catches the flaws in what code is meant to do
Also Read: IT Tech Pulse Exclusive Interview with Syed Ali Founder and Chief Executive Officer of EZO
Why it matters
“AI is changing not only the speed of software development, but also the scale of the verification challenge,” said Johannes Dahse(opens in new tab), VP of Code Security at Sonar. “SonarQube Hunter Agent helps teams identify the security flaws that require reasoning about what code is meant to do, not just how it’s written. By bringing those findings into the SonarQube workflow, we give security and development teams a practical way to extend verification as the pace of AI-driven development increases.”
Unlike vendor-coupled AI review tools, blackbox pentest agents that probe a live target from the outside, or point-in-time manual audits, SonarQube Hunter Agent is an independent, verification layer that inspects the full codebase continuously and gives teams accurate findings they can trust and track over time — turning what used to be a periodic audit into a standing capability.
Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.