Phoenix / Products / Crucible
Continuous adversarial validation over EDR · XDR · NDR

Phoenix Crucible

Your last pentest was a photograph. Crucible is the film.

Does it actually work? Every control you bought rests on the assumption that it fires when it matters. A scanner tells you what might be wrong; an annual pentest tells you what was true on one day, months ago. Crucible is a continuous, autonomous, authorized adversarial-validation engine that runs against your own estate and answers the only question that counts: when a real technique is used against you, does your stack catch it and stop it?

target & evidence data sent outside your perimeter0
From "you might be vulnerable" to "here is what actually breaks"

The validation chain.

The mechanical work is automated; the judgment is delegated to a reasoning model with a deterministic fallback — so the pipeline keeps moving even if the model is unavailable mid-run.

  recon ──► surface mapping ──► vulnerability correlation ──► safe validation ──► post-analysis ──► report
Intelligence, not guesswork

It reasons about your specific target — not a generic signature.

Corpus

159,000+ entries (as of 2026)

With categorized public proof-of-concept references, refreshed continuously.

Scoring

NVD authoritative CVSS

Severity grounded in the national vulnerability database, not a vendor guess.

Priority

CISA KEV — exploited in the wild first

Anything actively exploited is promoted to top priority automatically, ahead of higher-CVSS-but-dormant issues.

Language

MITRE ATT&CK mapping

Findings speak the language your detection team already uses.

The reasoning gate

Does this actually apply to the version you're running?

For each candidate, the reasoning layer reads the vulnerability description against the target's actually discovered version and returns {applies, confidence, rationale, version_match} before anything proceeds — so you don't drown in "vulnerabilities" that were never reachable.

We don't charge per finding. Per-finding pricing pays a vendor more the more broken you are. Crucible is a flat subscription, so our incentive matches yours: getting you to zero.
What you get back

Not a 400-page PDF. A picture you can act on the same day.

✓

Proven vs. theoretical

Findings validated for real exploitability, separated from the noise a scanner leaves behind.

✓

KEV-first prioritization

Exploited-in-the-wild issues surfaced ahead of everything else.

✓

Threat-intel narrative

Each finding correlated to current intelligence and mapped to ATT&CK.

✓

Remediation guidance

Concrete, ranked next actions, with the evidence each recommendation rests on attached.

✓

A durable evidence bundle

A defensible, timestamped record you can take into an audit or an insurance conversation.

Where Crucible fits

The "attack" lens — feeding detection directly.

A technique Crucible lands that your detection didn't see becomes a coverage_gap for Phoenix Nest — closing the circle from "an attacker could do this" to "and we now detect it when they try."

  Crucible proves it's exploitable  ─┐
                                     ├─►  coverage_gap  ─►  Nest detection improves
  Nest didn't detect the technique  ─┘
What's live today

Shipped, and what's rolling out — stated plainly.

CapabilityStatus
Recon → safe validation → reporting pipelineAvailable
CVE intel: local database + NVD + CISA KEVAvailable
MITRE ATT&CK mapping · KEV-first rankingAvailable
Model-reasoned applicability (deterministic fallback)Available
Durable, timestamped evidence bundleAvailable
Continuous / scheduled campaigns across the fleetRolling out
Why continuous beats point-in-time

Continuous validation vs. a yearly snapshot.

 Annual human pentestVulnerability scannerPhoenix Crucible
CadenceOnce a yearContinuousContinuous
Proves exploitabilityYes (on that day)NoYes, safely, ongoing
Prioritized by real-world exploitationManualRarelyKEV-first, automatic
Cost modelFive figures per engagement (typical range)Per-asset licenseBelow a recurring red-team retainer
Your target data leaves your wallsOn a consultant's laptopOften to cloudNever
Built for authorized use, by construction

An adversarial-validation tool for defenders — not an attack platform.

Scoped to assets you own and authorize

Target inventory is explicit and operator-controlled.

On-premises and local-model

Findings, evidence, and target data stay inside your perimeter.

Auditable

Every run produces a durable, timestamped record of what was tested, what was proven, and what was recommended.

Human-in-the-loop

Crucible produces the proof and the plan; your team owns the decision to remediate.

Scope & impact. Crucible tests only the assets and change windows you authorize. Public vulnerability feeds (NVD, CISA KEV) are queried for context; your target data and evidence never leave your perimeter.

Stop assuming your controls work. Prove it.