AutoAttack
vs Nessus.
Nessus Professional inventories exposures and ranks them. AutoAttack is an autonomous adversary: it exploits, chains, and proves. Black-box on the same GOAD lab, neither tool was given credentials.
DeployBlack box Neither tool given credentials
All three Domain Admins in 45 seconds.
A black-box GOAD lab: two forests, three domains, five Windows hosts. Neither tool was given credentials.
Nessus Professional exposure inventory
AutoAttack autonomous adversary
| Metric | Nessus Professional | AutoAttack |
|---|---|---|
| Run time | 24m 04s | 2m 37s |
| First Domain Admin | not reached | 0:41 K.O. |
| Domains compromised | 0 of 3 | 3 of 3 Perfect |
| Credentials recovered | 0 | 124 |
| Confirmed compromise | none | 3 Domain Admin |
Black-box comparison: neither tool was given credentials. Same GOAD vanilla snapshot, same network position, 2026-06-24.
the ground
env Black-box GOAD: the vanilla snapshot, neither tool hardened.
start Network position only. Neither tool given credentials.
goal Domain Admin on all three domains.
scoring Third-party GOAD range: the same snapshot and network position for both tools. See the run logs
what differs
different jobs Nessus inventories exposures and hands you a ranked list. AutoAttack runs the attack and hands you one account of the attack path, start to finish, with the evidence attached.
0 vs 3 domains Nessus reached zero of three domains in 24m 04s. AutoAttack reached Domain Admin on all three by 0:45 and recovered 124 credentials.
nothing to install One container deployed for the engagement and torn down after; nothing left on your hosts.
use both Exposure inventory and adversary emulation answer different questions. AutoAttack does not replace vulnerability management. It is the proof that a real attacker gets through anyway.