Name the objective.
Get the chain it took.
AutoAttack is autonomous penetration testing: an adversary you deploy as one container inside your network. You name one objective in plain English, and it goes after that objective across your estate. Active Directory, cloud, SaaS, endpoints, Linux and databases, chained in a single run.
Deployhow it works
goal Domain Admin. Customer data. Executive inbox. Source code. You decide the goal; the adversary works toward it.
deploy One container, one token. Anywhere reachable from your network, whatever you run: Active Directory or no directory at all, any mix of operating systems, any size or topology. Every reachable host, no asset cap, nothing to inventory first and nothing to install — and what it goes after is bounded by the objective you named. Tear it down when you’re done.
run The adversary maps the network, earns credentials, escalates, pivots, then picks the path most likely to reach the goal you set.
cross-domain It crosses layers: from a web-facing login page to Domain Admin, from a leaked SaaS token to your data store, chaining across your estate in a single run. Coverage of surfaces is a commodity; crossing them to reach what you named is not.
what you get
hops Every access and credential the adversary gained, in the order it gained them. How to read one
trails When the path crosses more than one domain, it groups into per-domain trails — each one headed by the domain and whether your objective fell there. One route across the whole estate, and you never lose which domain a step landed in.
one report The attack path it built, hop by hop, from first foothold to your objective. No severity levels, no CVSS, no separate findings list. A proven path orders remediation by attack sequence: the fix for each weakness sits beside the step where it was exploited, so you work the route in the order it was walked; what remains is governed by your own risk process.
objective-based Judged against the objective you named: satisfied, or not. A run that comes back not satisfied is not a failed run.
proof The evidence behind every hop. Verify it yourself.
run again Changed something? Deploy again. Every campaign is a fresh adversary and a fresh report of what that run reached. See a published run
ground rules
lockouts The adversary throttles credential attempts under your domain’s lockout policy. No one gets locked out.
disruption No service installs. No policy changes. No payload that trips antivirus.
footprint Nothing written to your hosts’ disks. Proof streams straight to the platform.
scope Targets only what you authorize. Stops the moment you say stop.