Your last pentest was a photograph. Crucible is the film.
Does it actually work? Every control you bought rests on the assumption that it fires when it matters. A scanner tells you what might be wrong; an annual pentest tells you what was true on one day, months ago. Crucible is a continuous, autonomous, authorized adversarial-validation engine that runs against your own estate and answers the only question that counts: when a real technique is used against you, does your stack catch it and stop it?
The mechanical work is automated; the judgment is delegated to a reasoning model with a deterministic fallback — so the pipeline keeps moving even if the model is unavailable mid-run.
recon ──► surface mapping ──► vulnerability correlation ──► safe validation ──► post-analysis ──► report
With categorized public proof-of-concept references, refreshed continuously.
Severity grounded in the national vulnerability database, not a vendor guess.
Anything actively exploited is promoted to top priority automatically, ahead of higher-CVSS-but-dormant issues.
Findings speak the language your detection team already uses.
For each candidate, the reasoning layer reads the vulnerability description against the target's actually discovered version and returns {applies, confidence, rationale, version_match} before anything proceeds — so you don't drown in "vulnerabilities" that were never reachable.
Findings validated for real exploitability, separated from the noise a scanner leaves behind.
Exploited-in-the-wild issues surfaced ahead of everything else.
Each finding correlated to current intelligence and mapped to ATT&CK.
Concrete, ranked next actions, with the evidence each recommendation rests on attached.
A defensible, timestamped record you can take into an audit or an insurance conversation.
A technique Crucible lands that your detection didn't see becomes a coverage_gap for Phoenix Nest — closing the circle from "an attacker could do this" to "and we now detect it when they try."
Crucible proves it's exploitable ─┐
├─► coverage_gap ─► Nest detection improves
Nest didn't detect the technique ─┘
| Capability | Status |
|---|---|
| Recon → safe validation → reporting pipeline | Available |
| CVE intel: local database + NVD + CISA KEV | Available |
| MITRE ATT&CK mapping · KEV-first ranking | Available |
| Model-reasoned applicability (deterministic fallback) | Available |
| Durable, timestamped evidence bundle | Available |
| Continuous / scheduled campaigns across the fleet | Rolling out |
| Annual human pentest | Vulnerability scanner | Phoenix Crucible | |
|---|---|---|---|
| Cadence | Once a year | Continuous | Continuous |
| Proves exploitability | Yes (on that day) | No | Yes, safely, ongoing |
| Prioritized by real-world exploitation | Manual | Rarely | KEV-first, automatic |
| Cost model | Five figures per engagement (typical range) | Per-asset license | Below a recurring red-team retainer |
| Your target data leaves your walls | On a consultant's laptop | Often to cloud | Never |
Váš poslední pentest byl fotka. Crucible je film.
Funguje to doopravdy? Každá ochrana, kterou jste koupili, stojí na předpokladu, že se spustí, když je potřeba. Skener vám řekne, co možná není v pořádku; roční pentest vám řekne, co bylo pravda jeden den, před měsíci. Crucible je průběžný, autonomní, autorizovaný engine adverzární validace, který běží proti vašemu vlastnímu prostředí a odpovídá na jedinou otázku, která se počítá: když je proti vám použita reálná technika, zachytí ji váš stack a zastaví ji?
Mechanickou práci děláme automaticky; úsudek je svěřen uvažujícímu modelu s deterministickou záložní cestou — takže řetězec běží dál, i když model uprostřed běhu vypadne.
recon ──► mapování povrchu ──► korelace zranitelností ──► bezpečná validace ──► poanalýza ──► report
S kategorizovanými odkazy na veřejné proof-of-concept, průběžně aktualizováno.
Závažnost opřená o národní databázi zranitelností, ne o dohad dodavatele.
Cokoli aktivně zneužívané je automaticky posunuto na nejvyšší prioritu, před položky s vyšším CVSS, ale spící.
Nálezy mluví jazykem, který váš detekční tým už používá.
Pro každého kandidáta uvažující vrstva přečte popis zranitelnosti proti skutečně zjištěné verzi cíle a vrátí {applies, confidence, rationale, version_match}, než cokoli pokročí — takže se netopíte v „zranitelnostech“, které nikdy nebyly dosažitelné.
Nálezy ověřené na reálnou zneužitelnost, oddělené od šumu, který skener zanechá.
To, co se reálně zneužívá, je vidět dřív než cokoli jiného.
Každý nález propojený s aktuální inteligencí a namapovaný na ATT&CK.
Konkrétní, seřazené další kroky, s přiloženými důkazy, o které se každé doporučení opírá.
Obhájitelný záznam s časovými razítky, který vezmete do auditu nebo k jednání s pojišťovnou.
| Schopnost | Stav |
|---|---|
| Řetězec recon → bezpečná validace → reporting | Dostupné |
| CVE intel: lokální databáze + NVD + CISA KEV | Dostupné |
| Mapování MITRE ATT&CK · řazení podle KEV | Dostupné |
| Modelem posouzená platnost (deterministická záloha) | Dostupné |
| Trvalý balík důkazů s časovými razítky | Dostupné |
| Průběžné / plánované kampaně napříč flotilou | Zavádí se |
Technika, kterou Crucible provede a vaše detekce ji nezachytí, se stává coverage_gapem pro Phoenix Nest — tím se kruh uzavírá od „útočník by tohle mohl“ k „a my to teď při pokusu detekujeme“.
Crucible prokáže zneužitelnost ─┐
├─► coverage_gap ─► detekce Nestu se zlepší
Nest techniku nezachytil ─┘
| Roční lidský pentest | Skener zranitelností | Phoenix Crucible | |
|---|---|---|---|
| Kadence | Jednou ročně | Průběžně | Průběžně |
| Prokazuje zneužitelnost | Ano (ten den) | Ne | Ano, bezpečně, průběžně |
| Priorita podle reálného zneužívání | Ručně | Zřídka | Podle KEV, automaticky |
| Cenový model | Řádově statisíce za zakázku (typicky) | Licence za aktivum | Pod opakovaným retainerem red teamu |
| Data o cílech opouští vaše zdi | Na notebooku konzultanta | Často do cloudu | Nikdy |