DrochaidHorizon3.ai
NodeZero/AI approach
AI approach

How NodeZero actually uses AI

Not hype. Not hallucinations. NodeZero applies graph-based reasoning, deterministic logic and scoped generative AI to think like an attacker, act with purpose, and prove real impact.

NodeZero does not use AI for show. It thinks like a skilled adversary — but with engineering discipline, not a single large language model left to improvise inside your network.

01Autonomy

The “AI” in NodeZero

NodeZero is an autonomous platform — it executes self-directed actions to reach an objective. In a pentest, that objective might be becoming Domain Admin, compromising sensitive data, or reaching a critical system. Knowledge-graph analytics, inference engines and learning loops mean the more pentests NodeZero runs, the smarter it gets.

The alternative — hardcoding every possible attack path as a script — does not scale. There are far too many variations, and the scripts break every time an environment changes. That is why scripted, automated pentesting stalled, while NodeZero’s autonomous approach serves organisations from global enterprises to a regional council or hospital.

NodeZero Insights tracking weaknesses across successive autonomous pentests.
Findings tracked across successive autonomous pentests
A proven attack path across the cyber terrain — the knowledge graph at the heart of NodeZero, used to plan and chain attacks.
An attack path across the cyber terrain — NodeZero’s knowledge graph of your environment
02Architecture

A reasoning-driven architecture

NodeZero is not a large language model dressed up as a pentester, and it is not a rigid rules engine. It is a reasoning-driven architecture — structured to plan, adapt and prove.

Structured to plan, adapt and prove

NodeZero operates like a skilled adversary — guided by goals, shaped by feedback, driven by outcomes. It builds a cyber terrain map of your environment, plans attack paths across it, and makes decisions based on what it sees, not just what it is told.

Precision prompting, not trial-and-error

Unlike generative agents that burn tokens in endless loops, NodeZero generates deep, task-specific prompts from a graph of validated facts. That lets scoped generative AI reason efficiently about business risk, stolen data or user context — instead of flailing toward an answer and hoping it lands.

Multiple agents, one cohesive system

NodeZero is not one model. It is an integrated AI system: graph reasoning powers attack planning, classical machine learning classifies files and behaviours, deterministic logic executes exploitation — every attack module pre-built, pre-validated and tested by Horizon3’s attack team before it ships — and scoped generative AI supports the bounded jobs that follow.

03Capabilities

How NodeZero uses AI in the real world

Generative AI is scoped to specific, bounded jobs — never to creating or firing exploits.

High-value targeting

Large language models weigh job roles, access privileges and naming patterns to tag compromised users and systems as high value — reprioritising deeper testing and raising risk scores where it counts.

Executive narratives

NodeZero generates business-aligned attack summaries that translate technical findings into plain language a board or executive can act on.

Exploit suggester and Try Harder agent

When NodeZero stalls, scoped generative AI proposes the next-best step — mimicking the persistence of a seasoned red teamer, inside a controlled loop rather than an open-ended one.

Advanced data pilfering

A two-stage approach: classical machine learning identifies the files worth reviewing, then a language model reads the contents to surface credentials, intellectual property, personal information or financial data an attacker could exploit.

Real-time view chatbot

Ask questions mid-test — “which known-exploited vulnerabilities are still open in production?” — and get natural-language answers grounded in real-time attack behaviour, not a generic threat feed.

Generative AI for web application testing

Language models analyse modern web applications for logic flaws such as broken access controls — the kind of issue automated scanners routinely miss.

04Operations

Agentic workflows that operationalise risk-based vulnerability management

Risk-based vulnerability management only works when it is based on what an attacker can actually exploit — not CVSS scores and scanner noise. NodeZero powers an agentic model combining real-world exploitation, AI-driven prioritisation and machine-speed remediation.

Through the NodeZero MCP Server, proven attack paths flow into the tools your teams already use — JIRA, GitHub, Argo, or your security orchestration platform — so agentic workflows can push remediations, deploy compensating controls and automatically verify that a fix actually worked.

Into production, not a spreadsheet
  • Infrastructure-as-code remediation loops
  • Credential rotation after compromise
  • Tripwire-triggered security orchestration (SOAR) playbooks
  • Endpoint detection and response (EDR) tuning
  • Known-exploited-vulnerability exposure validation
  • Policy hardening from attack-path trends

This is how risk-based vulnerability management gets out of spreadsheets and into production — where risk is eliminated, not just reprioritised.

05Safety & control

Designed for production, built for control

Never the exploiting

AI is only useful if it is safe to run in production. NodeZero never uses generative AI to create or execute exploits. Every action taken against your environment is deterministic, pre-validated and tested by Horizon3’s attack team before it ships.

A precise line on data

Exploitation data never leaves your environment. The bounded generative-AI tasks — targeting, narrative writing and data analysis — run only through secure, isolated cloud infrastructure, including Amazon Bedrock, with data residency and isolation controls. The part an attacker would touch stays in your network; the part that reasons about meaning runs in a controlled, isolated place.

Inference, not training

NodeZero does not train foundation models on your data. It builds structured prompts from live findings and runs inference against models like Claude, LLaMA or Mistral — choosing the best fit for each task. Your environment’s data is never absorbed into a model.

Built for your obligations

For organisations under DISP, IRAP, Essential Eight, CPS 234, SOCI/CIRMP or NZISM obligations, deterministic execution, exploitation data held in your environment and full command logging produce the reproducible, auditable record a compliance assessment actually asks for.

06Philosophy

The right tool for the job

Graph reasoning plans. Machine learning classifies. Deterministic logic attacks. Generative AI explains.

AI in NodeZero is not one-size-fits-all. Every decision is scoped, explainable and tuned to its task, and structured prompts ensure repeatability and control — not hallucination or guesswork.

07The loop

Hack, fix, verify — powered by AI

The payoff is a loop you can run continuously, not a report you read once a year.

Hack
01

Prove what’s exploitable

AI safely runs real attacks in production, chaining weaknesses the way an attacker would — so you see what could actually be exploited, not a scanner’s full backlog of maybes.

Fix
02

Auto-deploy deception

NodeZero drops Tripwires across your environment, alerting you if an intruder returns along a path you have already tested.

Verify
03

Prove it worked

One-click retesting replays the exact attack path and verifies the fix held — with evidence you can hand to an auditor.

Repeat, continuously
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

See the AI in NodeZero work against a live environment.

NodeZero thinks like an adversary and proves impact with evidence you can rely on — safely and continuously. See it with the Drochaid team.