Human operators
Real AI systems
No rules
We simulate the Promptware Kill Chain end-to-end — from initial prompt injection to full exfiltration. You discover what a motivated adversary can really do, before they do.
Five phases
One coordinated operation
We work like a motivated adversary — not a scanner. Each phase has clear deliverables, and you follow the operation in real time through our dashboard.
Threat modeling
We map your AI stack, identify crown jewels, and define adversary objectives jointly with your team.
Reconnaissance
OSINT, surface enumeration, model identification, plugins, exposed data, and third-party integrations.
Exploitation
Promptware Kill Chain activated — prompt injection, escalation, credential harvesting, persistence via agent memory.
Objectives & impact
Lateral movement, simulated exfiltration, business-flow compromise. We document every path with evidence.
Report & debrief
Executive report, technical walkthrough, campaign replay, and impact-prioritized remediation plan.
The arsenal attackers use — replicated at controlled scale
Every technique below was observed in real 2025–26 incidents or academic research. All are executed with explicit authorization and blast-radius containment.
Prompt injection multimodal
Hidden instructions in images, PDFs, audio, and metadata. Breaks the trust boundary between data and instructions.
Tool / function abuse
Chaining of legitimate tool calls to reach unauthorized capabilities — file system, email, transactions.
Model & system prompt leak
Extraction of system instructions, privileged context, and model details via adversarial prompts.
Memory poisoning
Injection of persistent instructions into long-term memory, vector stores, and context shared across sessions.
Indirect prompt channel
Command-and-control channel via shared documents, comments, or content retrieved by RAG.
Agent-to-agent contagion
Propagation across agents via inter-agent calls, message queues, and shared orchestration contexts.
Data exfil via legitimate channel
Sensitive data leaving through responses, summaries, or actions that appear legitimate to detection.
Guardrail bypass
Encoding, role-play, long context, logic puzzle attacks, and safety classifier evasion.
Supply chain
Malicious packages, backdoored models, poisoned datasets — attacking before deploy.
What you receive at the end of the campaign
Executive report (15–25 pp)
Business-language impact summary, risk map, top 5 attack paths, prioritized recommendations, and estimated financial exposure.
Technical report (60–120 pp)
Each attack chain documented stage-by-stage, with payloads, screenshots, logs, and reproducible PoC for the engineering team.
Campaign replay
Interactive visual timeline of each executed stage, operator decisions, and windows where the defense would have detected had observability been active.
90-day remediation plan
Prioritized actions (high/medium/low), suggested owners, estimated effort, and dependencies between controls. We revisit at 90 days to validate.
Controlled operations
No surprises
Every campaign starts with documented rules of engagement, blast-radius containment, and a direct channel with your response team if anything escapes scope.
Surgical scope
Systems, test accounts, time windows, and action types approved in writing before any execution.
24/7 red line
Direct channel between the campaign lead and your security team — we pause the operation at any moment.
No real data exfiltrated
We demonstrate exfiltration capability with canaries and synthetic data. Nothing sensitive leaves your perimeter.
Reversibility
Every modification to memory, configuration, or state is documented and rolled back at the end of the operation.
SOC coordination
"Purple team" mode available — we operate in coordination with your SOC to validate detection and response in real time.
Compliance & legal
Contract with NDA, legal authorization, data segregation, and auditable report for regulators and auditors.
Ready to find out what a motivated adversary can actually do?
2-day threat modeling workshop to start — leave with surface map, top 5 hypothetical attack paths, and a complete campaign proposal.
Schedule workshop