DrochaidHorizon3.ai
NodeZero/The NodeZero platform
Hack. Fix. Verify. Repeat.

The NodeZero platform

Autonomously find, fix, and validate real risks.

NodeZero transforms how organisations secure their environments by running unlimited pentests that uncover exploitable paths, guide remediation, and immediately verify that your fixes are effective. No agents. No waiting. Continuous, self-directed security.

4.7 / 5
Gartner Peer Insights
Gartner Peer Insights, Voice of the Customer AEV, October 2025
01

Attackers don’t hack in — they log in

The most common way into an Australian or New Zealand network is not an unpatched CVE — it is a credential an attacker already holds. Weak, reused, and breached passwords, over-privileged service accounts, and stale admin logins give adversaries a quiet front door. NodeZero starts where they do: it audits your Active Directory for exposed credentials and proves the blast radius of each one — how many systems a single weak password unlocks — so you can close the path before anyone walks through it.

NodeZero AD password audit showing exposed credentials and their blast radius
NodeZero proves what a single weak or reused password actually unlocks — not a list of policy violations, but the systems an attacker reaches with that one credential.
02

Find your most critical risks, fix what matters most

Uncover blind spots in your security posture that go beyond known and patchable vulnerabilities — easily compromised credentials, exposed data, misconfigurations, poor security controls, and weak policies. NodeZero pivots through your network, chaining together weaknesses just as an attacker would and then safely exploits them. You have full visibility into your pentest's progress and the exploits being executed in a real-time view. When the test is complete, the results are prioritised for your immediate action. The dashboard reveals your critical weaknesses, their impact to your organisation, and provides detailed remediation guidance for addressing them at a systemic level as well as individually.

Prioritised impacts dashboard ranking exploitable weaknesses by severity
03

Understand the path, proof, and impact

You have clear visibility into proven attack paths, step-by-step summaries of each path, and a clear understanding of their impact on your organisation. NodeZero provides proof of the exploit, its impact on your organisation, and mitigation recommendations. NodeZero guides you through the remediation process and simplifies your fix verification.

Attack-path graph chaining weaknesses through to domain compromise
04

Use detailed fix guidance, then quickly verify that your fixes worked

Your team will save time using the detailed remediation guidance for every weakness identified and a complete Fix Action report for your reference. The platform highlights systemic issues where making one change may fix numerous issues at the same time — in one engagement, fixing a single insecure Java JMX configuration would have eliminated 36% of the identified critical paths. Once you have completed your remediations, it is easy to do a Quick Verify to ensure that your fixes are effective.

Fix Action report confirming a remediated weakness moved to verified
05

Turn every pentest into team uplift

NodeZero is run by your existing security and IT team, not a specialist red team brought in once a year — so the proof, Fix Actions, and verification behind every finding build real offensive-security judgement in your people as they work. Start by closing your highest-impact weaknesses at a systemic level, then settle into a continuous hack, fix, verify, repeat loop. Because each finding carries its own proof and a tracked Open → Mitigated → Regressed status, you can measure mean-time-to-remediate and show the trend bending the right way over time — capability you can put in front of your board, not just assert.

NodeZero Insights dashboard showing weakness trends declining over successive pentests
The trend you can show the board: weaknesses found, fixed, and verified across successive runs — evidence the programme is working, not an assertion that it is.
06

One place to work the queue: the Vulnerability Management Hub

The Vulnerability Management Hub centralises validated weaknesses, proven attack paths, and Fix Actions in a single workflow. It tracks each finding through an Open → Mitigated → Regressed lifecycle with regression detection if a host drifts back to a vulnerable state. Integrations push proof-backed work into the tools your teams already use — ServiceNow for tickets, SIEM for detections, SOAR for response playbooks — so security findings become operational work instead of another inbox.

NodeZero queue of proven attack paths with weaknesses, credentials, and time to compromise
One queue for the whole team: every item is a proven, exploitable weakness prioritised by real impact — not an unranked scanner backlog.
07

Confirm the fix with Quick Verify

Once you have remediated a weakness, Quick Verify replays the exact attack path to confirm closure. If it is fixed, you download a report showing the weakness moved from Exploitable to Mitigated — audit-ready evidence of remediation. If it is not, the test reopens with specifics of what is still exploitable. No ambiguous sign-offs.

Quick Verify replaying an attack path to confirm a fix has closed it
08

Test whether your security controls are actually working

Endpoint Security Effectiveness shows whether your EDR responds in production — not in a lab, not against a synthetic test, but against real attack techniques run against real hosts. NodeZero reveals gaps in your security controls by using tactics, techniques and procedures to test whether controls work as intended. Per-host block/allow outcomes are correlated by EDR vendor and version so you can identify workstations and servers where application control or endpoint protection either is not deployed or is not actually enforcing. Tune detection rules against attacks that actually happened in your environment, not theoretical threat models. Endpoint is one of three control-validation lenses NodeZero applies: Identity Security Validation runs credential-based attacks — harvesting, replay, privilege escalation, lateral movement — to prove whether your IAM, PAM and identity threat detection and response controls hold under real pressure, and Data Security Effectiveness uses Advanced Data Pilfering to prove which sensitive data an attacker could actually reach and take.

What is effective security? Snehal Antani, CEO of Horizon3.ai, in conversation with ISMG
Effective security: the full webinar
09

Vulnerability Risk Intelligence: prioritise patching by real exploitability

Vulnerability Risk Intelligence ingests exports from your existing scanners (Tenable, Qualys, Rapid7) and classifies every CVE-asset pair from the attacker's perspective — Confirmed Exploitable, Contextually Exploitable, High-Value Target Found, or Threat Actor Pressure. Instead of triaging tens of thousands of CVSS entries, your team works a short, evidence-backed list where every item has been validated against the actual attack graph of your environment. Patch-window prioritisation — whether 48 hours, one month, or longer — becomes a decision based on real attack evidence, not static scores.

Vulnerability Risk Intelligence dashboard classifying CVEs by real exploitability
Scanner exports re-ranked by what an attacker can actually reach: a short, evidence-backed queue instead of tens of thousands of CVSS entries.
10

Score what an attacker can actually reach

Every weakness NodeZero finds carries two scores. The Base Score is CVSS v3.1 parity — the inherent severity of the vulnerability, independent of environment. The Context Score is the adjusted severity: it reflects what an attacker can actually reach and compromise by exploiting the weakness in your specific environment. Two organisations can face the same CVE with wildly different Context Scores because one has it exposed on a domain controller and the other has it on an isolated VLAN. Prioritisation based on Context Score puts remediation effort where it measurably reduces risk, not where a static score says it should.

Same CVE on a domain controller

Reachable from the user network and one hop from domain compromise — NodeZero proves the path, so the Context Score rises well above the Base Score. Fix this first.

Same CVE on an isolated VLAN

No attacker-reachable path to anything critical — the Context Score falls below the Base Score. Genuinely lower priority, with the evidence to defend that call to an auditor.

11

Segmentation testing: prove zone boundaries actually hold

Segmentation testing runs scoped NodeZero pentests across the logical and physical boundaries that your architecture relies on — between user VLANs and server VLANs, supplier interconnects and production, OT and IT, cloud accounts and on-premises networks (critical to meeting SOCI/CIRMP zone-control obligations and ISM network-segmentation controls). NodeZero enumerates IPs, ports, services, and applications reachable from each starting point and attempts lateral movement across the boundary. You see whether segmentation actually contains a breach where it is designed to — direct evidence that zone controls, firewalls, and ACLs enforce what the architecture says they enforce.

NodeZero attack path crossing a network boundary via an injected credential
When a boundary does not hold, NodeZero shows exactly where it crossed — the lateral-movement path through a zone your architecture assumed was contained.
How NodeZero works

Set up and start your first pentest in minutes

Then schedule pentests to run every day thereafter for continuous risk assessment.

1

Get started in minutes

Book a demo to get set up, then choose from a variety of operations: internal autonomous pentesting, password audits, and more. Test safely from any network with or without credentials.

2

Set up a host

Internal tests run from a free Docker host or open virtualisation appliance (OVA) that you can set up in minutes — simply copy and paste the execution script. External tests are automated from the Horizon3.ai cloud.

3

Launch your test

Use defaults designed for safe execution, customise with open-source intelligence (OSINT), choose exploitation types, and more. Horizon3.ai sets up dedicated, ephemeral resources — a one-time-use architecture — for your test in an isolated virtual private cloud network.

4

NodeZero executes autonomously

NodeZero navigates through your network without scripts. It exploits weaknesses based on its discoveries just as attackers do, chaining weaknesses to demonstrate impacts far beyond CVEs. Use RealTime View to monitor the state of your test and its significant findings.

5

Understand the impact

Prioritised impacts show you what to fix first and how to do it most efficiently. See diagrammed attack paths, clear proof of successful exploitation, streamlined fix verification, and detailed reporting to demonstrate your progress with your C-suite and auditors.

How NodeZero helps

Autonomous pentesting across your entire attack surface

NodeZero orchestrates hundreds of offensive security tools, chaining weaknesses together dynamically — without scripts, without agents, without disrupting production systems.

Test from the inside out
Internal pentesting

Test from the inside out

Deployed via Docker host within your network. Discovers hosts, harvests credentials, moves laterally, escalates privileges, and attempts to reach critical assets — proving what an insider or compromised account could actually access.

Privilege escalationLateral movementCloud pivotCredential harvesting
Attackers log in. They don't hack in.
AD password audit

Attackers log in. They don't hack in.

Audits Active Directory for weak, breached, and reused passwords. Shows the blast radius of compromised credentials — how many systems a single weak password exposes. Identifies shared admin accounts, over-privileged service accounts, and stale credentials.

Shared accountsOver-privileged usersStale credentialsBreach database check
What happens after someone clicks?
Phishing impact testing

What happens after someone clicks?

Takes credentials from simulated phishing campaigns and tests what an attacker could actually do with them. Not just "they clicked" — the full chain from compromised credential to domain admin, business email compromise, or data exfiltration.

KnowBe4 integrationMFA bypass testingBlast radius analysis
Know before the patch drops
Rapid response

Know before the patch drops

When a new zero-day or CISA KEV is disclosed, NodeZero's attack research team builds a production-safe exploit test — often within hours. Rapid Response tests whether you're exposed before adversaries can exploit the vulnerability.

Pre-patch detectionZero-day testingReal-time alerting
Also available:
External pentestingNodeZero TripwiresNodeZero InsightsVulnerability Management HubThreat Informed Perspectives (pentesting campaigns)Quick VerifyEndpoint Security EffectivenessIdentity Security ValidationData Security EffectivenessSegmentation testingNodeZero RAT (advanced post-exploitation)MITRE ATT&CK mapping
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

See NodeZero in action

Run your first autonomous pentest and see the exploitable paths, proof, and fix guidance NodeZero delivers.