The instrument
Kestrel.ICU models an authorised attack surface, ranks the paths across it, and tests the ones that can reach a named objective. The objective might be data, a privilege, or a business process. The result is that path.
It is developed by ScaryByte. The same team builds the tool and stands behind the evidence.
Where the model works
The model stays inside the authorisation. It learns the named surface, proposes the path, and stops at the objective and the rules. What leaves the engagement is evidence a defender can reproduce: what was reached, how, and what it means.
A short path to a real objective is the result.

