Living map
Recursive passive recon: subdomains, DNS, IPs, services, forgotten assets — rebuilt into a "who talks to what" graph.
CyDrakk maps your external exposure, correlates it daily with global exploitation intelligence, and proves what is actually exploitable — without any data ever leaving your infrastructure.
No active packet without proof of control and a signed mandate. Every action is logged.
Instant passive preview. Then, after proof of control, a full active scan + AI remediation.
From discovery to proof, a deterministic chain. AI augments the analyst and prioritizes; sensitive actions stay behind human validation gates.
Recursive passive recon: subdomains, DNS, IPs, services, forgotten assets — rebuilt into a "who talks to what" graph.
Every tech/version is linked to CVEs, KEV, EPSS and exploit availability. Ranking follows real risk — never raw CVSS.
A deterministic validator only concludes "exploitable" with replayable proof. Strict safe-mode, never any post-exploitation.
One run, an executive summary and a technical annex. Attack paths, prioritized remediation, PDF export — white-labeled.
Product principles embodied in the code — not just the pitch.
Hosted on your own infrastructure. The only outbound flows are public intel feeds. Air-gap mode with a local feed mirror.
The rules-of-engagement engine allows, limits or denies every action — and logs it to a tamper-evident audit trail.
A flaw only becomes "exploitable" with reproducible proof. No more 4,000 theoretical CVEs to triage.
KEV › EPSS › exploit availability › exposure › business criticality. An actively exploited medium outranks a dormant critical.
Link exposure + flaw + leaked credential into a proven attack path with impact — not a flat list.
Coming · P5MSSP / host reselling: per-tenant theme, domain and reports, with strict isolation verified at the database level (RLS).
Every module activates per tenant — the console grows as you enable them.
New asset, service, finding or leak? Instant alerts to Slack, Teams, webhook or email — plus an inventory diff between scans.
Consent, proof of control (DNS TXT) and signed mandate per asset, with a global and per-campaign kill-switch. The guardrail no other offensive platform shows.
Each proven flaw carries a timestamped, cryptographically signed, audit-grade proof — safe-mode, nothing modified.
Emerging KEV/EPSS and public exploits filtered to your assets, plus credential-leak correlation (Have I Been Pwned).
Prioritizes and explains findings in safe-mode — Claude (EU, zero-retention) or a fully local model. PII minimized, never a decision-maker.
Executive + technical reports as signed PDF, and an interactive web portal via an expiring, revocable link with client↔analyst comments.
Group findings into projects with owner, SLA and verification re-scan — push to Jira / ServiceNow / webhook in one click.
Fortinet, Microsoft 365 / Entra, GitHub, AWS, SNMP — credentials in a sovereign vault, each connector an activatable module.
Start free in 60 seconds. Scale to continuous, then to your own sovereign instance.
Instant passive preview + one full active scan after proof of control (DNS). Clear report with CVE + AI fix suggestions.
Scan nowContinuous offensive testing (the snake), multi-layer active scanning, CVE correlation KEV/EPSS, change detection + alerts, signed PDF reports + shareable portal, sovereign AI analyst.
StartYour own self-hosted multi-tenant instance: ROE engine + signed mandates, local+Entra SSO, internal VPN assessment, read-only connectors, reverse engineering, white-label, air-gap, compliance mapping.
Talk to usIn France, unauthorized access to a system is a criminal offense. A written mandate and proof of control are the only protection — CyDrakk enforces them automatically, per asset type.
| Asset type | Passive | Active scan | Validation |
|---|---|---|---|
| Asset you ownproof + mandate | ✓ Allowed | ✓ Non-destructive | ✓ Safe-mode |
| M365 / SharePoint tenantshared service | ✓ Allowed | ⚠ Config / exposure | ⚠ Identification only |
| Unmandated third-party asset | ⚠ Public OSINT | ✕ Denied | ✕ Denied |
Native understanding of the M365 / SharePoint / Entra surface, with GDPR and security-policy requirements built in. NIS2 requires knowing your IT estate: CyDrakk keeps a living Technical Architecture Document up to date.
4 actually exploitable flaws this week, 2 of them on critical services. Priority: 72 h.
CVE-2021-41773 — RCE, KEV, proof attached
CVE-2023-27997 — FortiOS, EPSS 0.94
CVE-2024-21413 — ransomware campaign
CyDrakk shares its foundation (CVE ingestion, asset model, report engine) with OpenVault, the self-hosted SOC agent. A red + blue suite, 100% sovereign.
External attack surface, exploitability correlation, safe-mode validation, chaining and reporting. Coming: internal bot and breach-and-attack simulation (BAS) without breaking anything.
Self-hosted SOC agent. Detection and response on the same asset model and intel — closing the loop between what is exposed and what is monitored.
Connect one or more VPNs per client and assess the information system from within: inventory, flow mapping, hybrid AD/Entra — under explicit authorization and a signed internal mandate, fully logged.
No destructive action, no data exfiltration — the platform proves, it never pushes further.
Authenticated, read-only scanning of business applications (CRM, ERP, SaaS, M365, web apps) with a test account provided by the client — stored in Vault. Strict safe-mode: never a write, never another account's data.
IDOR, broken authentication, missing server-side session control — proven with fictitious accounts and objects whenever possible.
Over-permissive roles, exposed debug endpoints, overly open CORS, missing security headers.
Never writes or changes state, never touches another user's data, and never adds or modifies rights autonomously — that stays a human-validated admin action.
On mutualized services (M365 & co.), the ROE caps validation at identification — per Microsoft's policy, no exploitation of shared services.
CISA KEV feed, ingested daily by the platform — what attackers are exploiting right now.
Loading feed…
Connect your authorized domains and get, from the very first week, the map of what is actually exploitable.
Open the consoleA demo, a question? contact@cydrakk.io