AUTOATTACK
Deploy

Name the objective.

An autonomous adversary goes after it.

Select your objective

Press Enter to run, or pick an objective above

What happens
when you run it

You deploy it as one container inside your own network, and you name an objective in plain English.

System check Boot readout
  1. AUTOATTACK SYSTEM CHECK
  2. DEPLOY UNIT ................ 1 CONTAINER
  3. CREDENTIALS ........... NONE / BLACK BOX
  4. OBJECTIVE ................. USER DEFINED
  5. CLOCK ................. STARTS ON DEPLOY
  6. ALL SYSTEMS GO

Every line is a real deployment fact: one container, no credentials, an objective you write, and a clock that starts on deploy.

01 Deploy in minutes

One command. The adversary phones home and the clock starts.

02 It chains to your objective

One foothold becomes the next, machine to machine, toward the objective you set.

03 Every step is proven

Each move is backed by evidence you can verify.

Benchmark

Versus

Two published matchups on a GOAD lab, scored on time to Domain Admin. AutoAttack started every run with no credentials.

Black box Neither tool given credentials

All three Domain Admins in 45 seconds.

A black-box GOAD lab: two forests, three domains, five Windows hosts. Neither tool was given credentials.

Nessus Professional exposure inventory
AutoAttack autonomous adversary
MetricNessus ProfessionalAutoAttack
Run time24m 04s2m 37s
First Domain Adminnot reached0:41 K.O.
Domains compromised0 of 33 of 3 Perfect
Credentials recovered0124
Confirmed compromisenone3 Domain Admin

Black-box comparison: neither tool was given credentials. Same GOAD vanilla snapshot, same network position, 2026-06-24.

Hardened stage Ten independent runs

Ten runs on hardened GOAD: 51-second median.

Time to all three Domain Admins on the hardened spec NodeZero published: two forests, three domains, five Windows hosts.

NodeZero automated pentest
AutoAttack autonomous adversary
MetricNodeZeroAutoAttack
Time to 3/3 Domain Admin14m 00s0:51 About 16× faster
Domains reached3 of 33 of 3
Independent runs1 published10

Same hardened GOAD spec NodeZero published: Windows Defender enabled, LLMNR disabled, Windows patched through March 2026. AutoAttack: median of 10 independent runs, fresh rollback each time, range 0:28 to 1:01. NodeZero published its 14:00 result in August 2025. AutoAttack reaches the same objective about 16× faster.

See the full benchmark
How a run unfolds

Move list

What comes back is one report: the whole attack path it built, hop by hop, evidence attached. No severity levels, no CVSS, no separate findings list.

It works across your estate — Active Directory, cloud, SaaS, endpoints, Linux, data stores — chaining between them in a single run.

Chain shape What a run chains through
Hit 1 Web app
Hit 2 Host
Hit 3 Network
Hit 4 Domain Admin

It is not an exposure-inventory tool: every finding is a confirmed compromise, reached and proven. The four hits above are the shape a chain takes, not one run. A measured run's own steps and times are in the benchmark tables.

Reach

Domain Admin across your Active Directory forests.
Sensitive data at rest and in motion.
Executive inboxes and the messages inside.
Identity
Network
Applications
Data

Select your objective

Four that visitors pick most, and one slot that takes anything you can say in plain English.

compromise our domain controllers. “Take Domain Admin on our Active Directory forest.”
read the CEO inbox. “Get into the CEO's email and pull anything sensitive.”
show what an insider reaches. “Assume a malicious insider on a developer laptop. Show what they reach in 24 hours.”
get Domain Admin from 10.10.1.11. “Starting from 10.10.1.11, get Domain Admin on the corp domain.”
Name your own. Free text, plain English. Whatever you would tell a pentester on day one.

Every slot runs the same product: no plans, no tiers, no feature gating. Identity, network, applications and data, on every reachable host.

Per discovered host

Priced per discovered host, billed annually. No plans, no tiers, no feature gating: one product, a graduated rate.

Rate card Billed annually
HostsRate$ / host / yr
1–100$49
101–500$34
501–2,500$19
2,501–10,000$9
10,001+Enterprise, contact sales
Worked example, 750 hosts
100 × $49 + 400 × $34 + 250 × $19
= $23,250 / yr
Included in every band
  • Unlimited campaigns and agents
  • Every reachable host attacked, no asset cap
  • Identity, network, applications and data
  • The evidence behind every step
  • One report per campaign, the whole causal chain on one page
Free play

Deploy and run a complete campaign at no cost, and read the whole run: every step it took. Subscribing reveals the target names, the captured proof and the fix, and the host count you discovered sets the price.

Billing is annual and auto-renews at the then-current rate. Host count is unique hosts discovered during your billing period, and increases are prorated. Seven days grace on a failed payment before the account goes read-only. Cancel anytime from the Stripe portal, and your campaigns and their reports stay accessible.

Challenge round

It is not a scanner

Every finding is a confirmed compromise, reached and proven.

No asset cap

Every reachable host attacked.

Black box by default

AutoAttack was given no credentials in either published benchmark.

Run it again after a fix

Campaigns are unlimited, so deploy again and read what the new run reached.

Free to run

The whole run is yours to read for nothing. You pay to reveal the target names, the proof and the fix, and the host count you discovered sets the price.

State your objective.

Deploy and run a complete campaign at no cost, and read the whole run: every step it took. Subscribing reveals the target names, the captured proof and the fix, and the host count you discovered sets the price.

Press Enter to run · an adversary on demand