A rule count can be read off a config file. Whether it fires when the technique actually runs can only be found out by running something. We run it, against your SIEM, and hand you the table. Every step below is defined by what you have to hand over. The ladder starts with research already published, and nobody gets scanned who did not ask.
A DRI Assessment is this, run against your SIEM instead of ours. The run above is real, published in full with its own corrections, and measured on our bench — it characterises that build, not your estate.
Two ladders. Each starts with research already published that costs you nothing, and each step after that is defined by what you hand over rather than by how many features it unlocks. You can stop at any step and keep everything produced up to that point. Detection is where our work is now, so it comes first.
Having a rule for a technique can be counted from a config file. Whether it fires can only be observed by running something. This ladder measures the second thing.
Real attacker actions replayed against a SIEM build, with what fired, the rule id, whether it carried a MITRE mapping, and what stayed silent. Volumes one to three are published in full, corrections included.
We run the replay against a build you care about and hand you the table: technique in, alert out or silence, with the detection window measured rather than assumed.
Stated before you ask: this characterises a build, not your live estate. Our lab runs Wazuh, QRadar 7.3 and Splunk.
The one above, run against your SIEM instead of ours. At least twenty ATT&CK techniques replayed end to end, then the table: which ones made a rule fire, which rule, and which produced nothing. You get the denominators, not a percentage, plus the rule and configuration changes that would close what stayed quiet. Five business days from access, delivered entirely in writing.
Scope, stated before you ask: techniques are replayed against a host you nominate for it — typically a test machine reporting into your production SIEM. The SIEM under measurement is the real one. The target is not your production estate, and we do not run destructive actions on machines you depend on.
The same replay on a cycle, with a diff against the previous run. Detection decays quietly — an agent stops reporting, a rule gets tuned out, a parser breaks after an upgrade — and the only way to see the decay is to measure the same thing twice.
We hand you the rules and configuration to close the loudest gaps, you apply them, and we run the same replay again. The output is the before and after, in the same units. If you resell security work, this is the document that evidences your work rather than ours.
We only sell this to someone who has been through step two or three. Closing gaps for an estate nobody has measured is selling blind, and you would have no way to tell whether it worked.
White label. You run the measurement across your own clients under your own name, and the report goes out as your work. Priced on the size of the book, not per seat.
A second instrument, on the same principle: what a configuration claims, versus what a connection actually negotiated.
Forty five public endpoints, offered post quantum key exchange, what each one actually negotiated. Anonymous, limits stated, method and command included so you can rerun it.
Send one hostname you are responsible for. We offer post quantum key exchange to it and send back one page: what it negotiates, where that puts you against the published cohort, and the command to check us. No access, no credentials, no NDA, no call.
Capacity, not marketing: five per week, because one person writes them.
The same probe across every name you are responsible for, plus certificate inventory and trust chain, returned as a report naming which endpoints negotiate what, which certificates cannot rotate cleanly, and what to fix first.
Configuration rather than access: nginx, apache or haproxy configs, sshd_config, VPN configs, certificate bundles, source, and optionally a packet capture. You get an assessment, a migration roadmap and a cryptographic bill of materials. The capture scores harvest-now-decrypt-later exposure per flow rather than per config file.
The air gapped enterprise build, installed on your own machines, your database, your audit trail, your name on the output.
No revenue share. Percentage accounting needs audit rights, audit rights need meetings, and we do not do meetings.
Knowing your hostname means we could scan you. It is not permission to. Nothing runs until you send a hostname yourself, with a request attached.
An unsolicited assessment of your infrastructure is not a gift. It burns the only thing we have.
Questions, scoping, delivery and follow-up all happen in written English, on your clock. That is a constraint we chose, and it is why the ladder starts where it does: everything we sell has to survive being read rather than presented.
Every published figure is anonymous, and the limits of the sample are printed next to the number.
Every figure we publish names the instrument that produced it and the sample it came from. If we cannot say who counted and how, we leave the number out.
There are none to show yet. Every number on this site comes from our own bench and says so. We would rather you check the method than trust a wall of badges.
Send a hostname you are responsible for and we will run step one and send back the page. If it is useful you already know where step two goes. If it is not, you have lost an email.
Written by the person who builds the tools. Hanoi, UTC+7, so replies land overnight if you are in Europe or North America.