Hunt your
network the way
an adversary would.
Kestrel runs autonomous breach-and-attack simulations built on MITRE ATT&CK — so the gaps in your defenses are found by you, in a test, and not by someone else for real.
Most assessments test your patches. Almost none test your adversary.
Patch levels and control coverage tell you what should be safe. They say nothing about what happens when a real intruder is already moving — pivoting between hosts, escalating quietly, exfiltrating on a channel no rule was written for.
Kestrel closes that distance. It represents adversary behavior as a chain of ATT&CK-mapped abilities and runs it end to end inside your own environment, so you watch an intrusion unfold and see, action by action, precisely where it is caught and where it walks straight through.
The result is not a hypothetical score. It is evidence: what your defenses stopped, what they missed, and what to fix first.
Six modules, one operation.
Each module has its own page — open any of them to go deeper.
01Adversary Emulation
Replay how real threat groups operate — technique by technique, inside your own environment, on demand.
Open module02ATT&CK Coverage
Every action is tagged with its MITRE ATT&CK technique, producing a coverage map your whole team already reads.
Open module03Autonomous Operations
Launch an operation and let the decision engine chain techniques on its own — or take the controls by hand.
Open module04Detection & Response
Every emulated action doubles as a detection test — see what fired, what was missed, and how long it took.
Open module05Plugins & Agents
A lean, modular core surrounded by plugins for agents, interfaces, and custom TTPs. Extend it to fit your program.
Open module06Reporting & Analytics
Timelines, coverage maps, and gap analysis that turn a dense operation into something leadership can act on.
Open moduleHow a Kestrel operation runs.
A genuine sequence — each phase produces what the next one needs.
Choose a profile
Start from a curated threat-group profile or assemble your own from a library of ATT&CK-mapped abilities.
Deploy agents
Lightweight agents check in from your test hosts and wait for tasking over an encrypted channel.
Run the chain
The decision engine executes techniques in sequence, adapting to what each host actually permits.
Measure & report
Every action is scored against your detections and rolled into a coverage and gap report.
The whole framework, on one grid.
Every action Kestrel runs is tagged with its technique and tactic. The blank cells are your backlog; the red cells are what to fix first.
Explore coverageOne platform, every side of the table.
Scale your offense
Automate the repeatable parts of an engagement so your operators spend time on the hard, creative problems.
- Chain full attack paths on demand
- Reuse and version your TTPs
- Bounded, authorized execution
Prove your detections
Test whether the alert actually fires, the log actually lands, and someone actually responds — with evidence.
- Per-technique detection verdicts
- Measure time-to-detect
- Tune rules and re-test in minutes
Close the loop
Put offense and defense on the same scorecard so every operation makes the next one measurably better.
- Shared, evidence-based results
- Track coverage over quarters
- Turn findings into a backlog
Open by default.
A documented REST API and agents in three runtimes mean Kestrel drops into the tooling you already run.
“You cannot defend against behavior you have never watched happen. So watch it happen — on your terms, in your lab, before it happens for real.”
Common questions.
Operations are scoped to the hosts, subnets, and time windows you define, and agents are built to leave a clean, testable trail. Most teams run first in a dedicated lab, then in tightly bounded production windows once they trust the profile.
No. Start from curated adversary profiles and a library of ATT&CK-mapped abilities. When you want something specific, you can compose or author your own and package it as a reusable plugin.
Every emulated action is also a detection test. Kestrel reports whether each technique was detected, partially detected, or missed — and how long it took — so your blue team tunes rules against real behavior instead of guesswork.
A chronological timeline of every action, an ATT&CK coverage matrix of what was tested and caught, and a prioritized gap list — export-ready for both engineers and leadership.
Run your first operation today.
Stand up a server, deploy an agent, and watch a full attack chain execute against your own environment in minutes.