The NodeZero platform
Autonomously find, fix, and validate real risks.
NodeZero transforms how organisations secure their environments by running unlimited pentests that uncover exploitable paths, guide remediation, and immediately verify that your fixes are effective. No agents. No waiting. Continuous, self-directed security.
A platform built for continuous security validation
Internal pentesting
Test on-premises, cloud, identity and access management, and data infrastructure from the perspective of an attacker or malicious insider.
External pentesting
Map your internet-facing attack surface and identify exploitable paths that adversaries could use to breach your perimeter.
Cloud pentesting
Find vulnerabilities, IAM misconfigurations, and exploitable attack paths across AWS and Azure environments.
Kubernetes pentesting
Test containerised workloads for exposed services, misconfigured RBAC, and lateral movement between pods, nodes, and the control plane.
Rapid Response to CISA KEVs
Targeted validation of emerging and actively exploited CVEs and KEVs — production-safe proof of your exposure, often within hours of disclosure.
AD password audit
Reveal weak, breached, and reused passwords in your Active Directory environment and the blast radius of compromised credentials.
NodeZero Insights
Organisation-wide dashboards for risk visualisation, MTTR tracking, trend analysis, and executive reporting.
NodeZero Tripwires
Autonomous decoys auto-deployed during pentests as critical risk is discovered. Real-time alerts when triggered.
Phishing impact testing
Take credentials from simulated phishing campaigns and test what an attacker could actually do with them.
Attackers don’t hack in — they log in
The most common way into an Australian or New Zealand network is not an unpatched CVE — it is a credential an attacker already holds. Weak, reused, and breached passwords, over-privileged service accounts, and stale admin logins give adversaries a quiet front door. NodeZero starts where they do: it audits your Active Directory for exposed credentials and proves the blast radius of each one — how many systems a single weak password unlocks — so you can close the path before anyone walks through it.

Find your most critical risks, fix what matters most
Uncover blind spots in your security posture that go beyond known and patchable vulnerabilities — easily compromised credentials, exposed data, misconfigurations, poor security controls, and weak policies. NodeZero pivots through your network, chaining together weaknesses just as an attacker would and then safely exploits them. You have full visibility into your pentest's progress and the exploits being executed in a real-time view. When the test is complete, the results are prioritised for your immediate action. The dashboard reveals your critical weaknesses, their impact to your organisation, and provides detailed remediation guidance for addressing them at a systemic level as well as individually.

Understand the path, proof, and impact
You have clear visibility into proven attack paths, step-by-step summaries of each path, and a clear understanding of their impact on your organisation. NodeZero provides proof of the exploit, its impact on your organisation, and mitigation recommendations. NodeZero guides you through the remediation process and simplifies your fix verification.

Use detailed fix guidance, then quickly verify that your fixes worked
Your team will save time using the detailed remediation guidance for every weakness identified and a complete Fix Action report for your reference. The platform highlights systemic issues where making one change may fix numerous issues at the same time — in one engagement, fixing a single insecure Java JMX configuration would have eliminated 36% of the identified critical paths. Once you have completed your remediations, it is easy to do a Quick Verify to ensure that your fixes are effective.

Turn every pentest into team uplift
NodeZero is run by your existing security and IT team, not a specialist red team brought in once a year — so the proof, Fix Actions, and verification behind every finding build real offensive-security judgement in your people as they work. Start by closing your highest-impact weaknesses at a systemic level, then settle into a continuous hack, fix, verify, repeat loop. Because each finding carries its own proof and a tracked Open → Mitigated → Regressed status, you can measure mean-time-to-remediate and show the trend bending the right way over time — capability you can put in front of your board, not just assert.

One place to work the queue: the Vulnerability Management Hub
The Vulnerability Management Hub centralises validated weaknesses, proven attack paths, and Fix Actions in a single workflow. It tracks each finding through an Open → Mitigated → Regressed lifecycle with regression detection if a host drifts back to a vulnerable state. Integrations push proof-backed work into the tools your teams already use — ServiceNow for tickets, SIEM for detections, SOAR for response playbooks — so security findings become operational work instead of another inbox.

Confirm the fix with Quick Verify
Once you have remediated a weakness, Quick Verify replays the exact attack path to confirm closure. If it is fixed, you download a report showing the weakness moved from Exploitable to Mitigated — audit-ready evidence of remediation. If it is not, the test reopens with specifics of what is still exploitable. No ambiguous sign-offs.

Test whether your security controls are actually working
Endpoint Security Effectiveness shows whether your EDR responds in production — not in a lab, not against a synthetic test, but against real attack techniques run against real hosts. NodeZero reveals gaps in your security controls by using tactics, techniques and procedures to test whether controls work as intended. Per-host block/allow outcomes are correlated by EDR vendor and version so you can identify workstations and servers where application control or endpoint protection either is not deployed or is not actually enforcing. Tune detection rules against attacks that actually happened in your environment, not theoretical threat models. Endpoint is one of three control-validation lenses NodeZero applies: Identity Security Validation runs credential-based attacks — harvesting, replay, privilege escalation, lateral movement — to prove whether your IAM, PAM and identity threat detection and response controls hold under real pressure, and Data Security Effectiveness uses Advanced Data Pilfering to prove which sensitive data an attacker could actually reach and take.
Vulnerability Risk Intelligence: prioritise patching by real exploitability
Vulnerability Risk Intelligence ingests exports from your existing scanners (Tenable, Qualys, Rapid7) and classifies every CVE-asset pair from the attacker's perspective — Confirmed Exploitable, Contextually Exploitable, High-Value Target Found, or Threat Actor Pressure. Instead of triaging tens of thousands of CVSS entries, your team works a short, evidence-backed list where every item has been validated against the actual attack graph of your environment. Patch-window prioritisation — whether 48 hours, one month, or longer — becomes a decision based on real attack evidence, not static scores.

Score what an attacker can actually reach
Every weakness NodeZero finds carries two scores. The Base Score is CVSS v3.1 parity — the inherent severity of the vulnerability, independent of environment. The Context Score is the adjusted severity: it reflects what an attacker can actually reach and compromise by exploiting the weakness in your specific environment. Two organisations can face the same CVE with wildly different Context Scores because one has it exposed on a domain controller and the other has it on an isolated VLAN. Prioritisation based on Context Score puts remediation effort where it measurably reduces risk, not where a static score says it should.
Reachable from the user network and one hop from domain compromise — NodeZero proves the path, so the Context Score rises well above the Base Score. Fix this first.
No attacker-reachable path to anything critical — the Context Score falls below the Base Score. Genuinely lower priority, with the evidence to defend that call to an auditor.
Segmentation testing: prove zone boundaries actually hold
Segmentation testing runs scoped NodeZero pentests across the logical and physical boundaries that your architecture relies on — between user VLANs and server VLANs, supplier interconnects and production, OT and IT, cloud accounts and on-premises networks (critical to meeting SOCI/CIRMP zone-control obligations and ISM network-segmentation controls). NodeZero enumerates IPs, ports, services, and applications reachable from each starting point and attempts lateral movement across the boundary. You see whether segmentation actually contains a breach where it is designed to — direct evidence that zone controls, firewalls, and ACLs enforce what the architecture says they enforce.

Set up and start your first pentest in minutes
Then schedule pentests to run every day thereafter for continuous risk assessment.
Get started in minutes
Book a demo to get set up, then choose from a variety of operations: internal autonomous pentesting, password audits, and more. Test safely from any network with or without credentials.
Set up a host
Internal tests run from a free Docker host or open virtualisation appliance (OVA) that you can set up in minutes — simply copy and paste the execution script. External tests are automated from the Horizon3.ai cloud.
Launch your test
Use defaults designed for safe execution, customise with open-source intelligence (OSINT), choose exploitation types, and more. Horizon3.ai sets up dedicated, ephemeral resources — a one-time-use architecture — for your test in an isolated virtual private cloud network.
NodeZero executes autonomously
NodeZero navigates through your network without scripts. It exploits weaknesses based on its discoveries just as attackers do, chaining weaknesses to demonstrate impacts far beyond CVEs. Use RealTime View to monitor the state of your test and its significant findings.
Understand the impact
Prioritised impacts show you what to fix first and how to do it most efficiently. See diagrammed attack paths, clear proof of successful exploitation, streamlined fix verification, and detailed reporting to demonstrate your progress with your C-suite and auditors.
Autonomous pentesting across your entire attack surface
NodeZero orchestrates hundreds of offensive security tools, chaining weaknesses together dynamically — without scripts, without agents, without disrupting production systems.

Test from the inside out
Deployed via Docker host within your network. Discovers hosts, harvests credentials, moves laterally, escalates privileges, and attempts to reach critical assets — proving what an insider or compromised account could actually access.

Attackers log in. They don't hack in.
Audits Active Directory for weak, breached, and reused passwords. Shows the blast radius of compromised credentials — how many systems a single weak password exposes. Identifies shared admin accounts, over-privileged service accounts, and stale credentials.

What happens after someone clicks?
Takes credentials from simulated phishing campaigns and tests what an attacker could actually do with them. Not just "they clicked" — the full chain from compromised credential to domain admin, business email compromise, or data exfiltration.

Know before the patch drops
When a new zero-day or CISA KEV is disclosed, NodeZero's attack research team builds a production-safe exploit test — often within hours. Rapid Response tests whether you're exposed before adversaries can exploit the vulnerability.
See NodeZero in action
Run your first autonomous pentest and see the exploitable paths, proof, and fix guidance NodeZero delivers.