01Solutions

The tool.

An advanced, AI-powered offensive security tool, developed by ScaryByte. It models the attack surface and tests the path an attacker would take.

What it does.

  • Models an authorised attack surface and ranks the paths across it.
  • Pursues an objective you name: access, data, or a process.
  • Covers external, internal, assumed-breach, or a hybrid, inside one set of rules.
  • Returns the path, the proof, and the readout. ScaryByte stands behind all three.

02Motion

How the tool moves.

Point, Campaign, and Retainer set the depth and the cadence. The instrument stays the same.

01

Bound reconnaissance.

Learn the surface named in the authorisation.

02

Objective pursuit.

Follow a path toward a named goal: access, data, or a process.

03

Proof.

Record what was reached, the steps that got there, and the impact.

04

Closure.

A readout. Remediation stays with you. Retest follows the plan.

CatalogueThirty modules

What an engagement can name.

These are the modules the scoping pack can record. Listing one does not offer it. Selecting one does not commission it, and it does not authorise a single action. ScaryByte confirms what will run. Work starts only on the signed authorisation.

External and internal

What can an outsider, or someone already inside, reach?

External network · Internal network · Unauthenticated scan · Authenticated scan

Application

Is the application, the API, the mobile client, or the desktop client fit to ship?

Web application · API · Mobile · Desktop client · Source review · Application scan

Platform

Is cloud, identity, containers, wireless, or the tenant configured soundly?

Cloud · Wireless · Identity · Containers · Build review · SaaS tenant

Specialised

Does the work touch payment, a plant, a device, or a model?

OT and ICS · IoT and embedded · AI, LLM, and agents · PCI DSS

Adversary

Can a defined objective be reached, and would you see it?

Adversary simulation · Purple team · Assumed breach · Social engineering · Physical · Intelligence-led

Assurance

Does the control set, or the fix, hold?

Configuration audit · Retest of named findings

Cadence

Will the same surface be looked at again, on a term you name?

Recurring assessment

Exercise

Can the team decide under pressure?

Tabletop and incident-response exercise

What stays out.

  • A module that was not selected for that engagement, and then confirmed.
  • Social engineering, physical access, and denial of service, unless that module is selected and the permission register allows it.
  • A third party's systems, until the owner and the permitted action are named.
  • Anything found after the window opens, until the scope is confirmed again.
  • Remediation. The readout names what to change. The change stays with you.

PackEdition 1.1

Name it in the scoping pack.

The pack is the customer master. It asks for the organisation, the assets, the rules, and only the modules you want considered. Returning it starts a review. It does not start a test.

How authority works

What you receive.

  • Rules of engagement, agreed before work.
  • An objective record: reached, partial, or not reached.
  • Findings with evidence, marked by whether they sit on the path.
  • A technical readout. An executive readout on Campaign and Retainer.
  • A retest when the plan includes one.

03Knowledge

How much the tester is told.

Every engagement names a knowledge level. Naming it is not the authorisation.

Black box.

No internal documents and no credentials, beyond what is public and the identifiers that were agreed. “Discover everything” is not a scope.

Grey box.

Some documents, a limited account, or an authenticated role. Not full source, and not administrator access, unless that is what was written.

White box.

Source, diagrams, and configuration, only as far as the rules allow. A hybrid is allowed when the phases are written down.

Still not permission.

The knowledge level does not authorise the test. Credentials are never written into the scoping pack. The report states the level that was used.

04Compliance

How a run complies.

The same instrument. The rules of that authorisation decide which packs are loaded.

Mapped.

A finding is scored in one CVSS version, and the vector is kept. It is tied to ATT&CK at the release pinned for that engagement. PCI DSS v4.0.1, PoPIA, GDPR, HIPAA, ISO 8583:2023, and ISO 11568 are added only when that regime is named in the authorisation. A mapping is not a certificate.

Minimised.

The proof is the path. A full card number, a health record, or special personal information is not kept when a smaller proof will do.

Sealed.

An artefact is hashed, then sealed, before it is treated as the record.

Told in time.

A critical finding is notified under the rules of engagement. It is not saved for the closing report.

Read twice.

A second reader is required before delivery when a finding is Critical, or when a regulated report will be shared as an attestation.

Not a certificate.

The readout is the path and the proof. It does not attest that the organisation is compliant.

Who it is for.

Organisations that can name a surface and a person entitled to authorise testing of it.

05Developer

Kestrel.icu is developed by ScaryByte.

Contact ScaryByte
ScaryByte
Loading Kestrel.icu