THE CORVUS TECHNOLOGY

Intelligent Orchestration.
Full Operator Control.

Most firms resell the same off-the-shelf offensive tooling. We built our own. Corvus is our proprietary, LLM-assisted red-team technology: the AI handles the exhaustive, repeatable work, discovery, technique chaining, and adaptation, while our operators keep judgment, approve every state-changing action, and run the creative attacks a machine can't. Human-in-the-loop, scope-enforced, and fully audited on every step.

140+
Offensive Techniques
Modular
Playbook Library
4-Tier
Human Approval Gate
100%
Actions Audited
AD · Web · AI
Surface Coverage

Our own technology, not a pile of tools.

A boutique firm that builds its own AI-driven, human-gated red-team technology understands the modern attack surface from both sides. That matters most for our AI Security practice: we don't just test AI systems, we build AI security tooling, so we know where these systems break.

The design invariant: the LLM proposes, deterministic code disposes.

Every action any part of Corvus takes passes through a single choke point. Before anything runs, that gate checks the target against a hard scope allowlist, classifies the action by risk, and pauses for a human operator's approval on anything that changes state, then records it. The AI adds speed and adaptivity; it can never widen scope, skip a gate, or act unlogged. This is the proof that we're rigorous, not reckless.

Three reasoning roles. One deterministic gate.

Corvus separates AI reasoning into three focused roles, a Planner that picks the next technique, an Operator that builds its arguments from what's been discovered, and an Analyst that turns results into the next recommendation. Every proposed action is forced through one gate that enforces scope, risk tier, human approval, and audit before any real tool runs.

Local LLM on host planner · operator · analyst roles (local-first, degrade offline) Playbook, the engagement as data scope · techniques · eligibility · tiers · success Planner picks next technique Operator synthesizes its args The Gate scope · tier · approval · audit pauses for a human on state change Toolpack runs real tooling Analyst insights · ranks · summary Engagement State + Ledger targets · findings · redacted results · decision log Operator (human) approve / edit / deny / abort Audit sink, one record per action (scope decision, tier, approver, exact command, redacted output, integrity digest) recommendation ledger → LLM

Recon and discovery run exhaustively first, no vector skipped. The selective kill chain only fires techniques whose prerequisites were actually found, and every role reads the same redacted ledger, so the run adapts to what really happened. View the full architecture →

Built for coverage, control, and evidence.

Adaptive

Findings-Driven Chaining

Techniques only become eligible when discovery actually surfaced them. No blind execution, Corvus chains multi-step attack paths that time-boxed manual tests routinely miss.

Control

Four-Tier Gated Approvals

Read-only recon runs automatically; anything that changes state pauses for operator review, and the highest-impact actions require a typed confirmation. The human decides.

Coverage

Exhaustive Discovery

Every recon and enumeration vector runs first, deterministically, before the selective kill chain, so coverage is repeatable and complete, engagement after engagement.

Evidence

Full Audit Trail

Every action is logged with timestamp, technique, target, risk tier, approver, exact command, redacted output, and an integrity digest, a defensible, reproducible record of record.

Privacy

Local-First Inference

LLM roles run on a local model on the engagement host. No secrets ever reach a prompt, and loot and audit never leave the box, a cloud backend is an optional swap, never a requirement.

Reproducible

Live or Simulated

One switch runs genuine tooling against the authorized lab or replays deterministic fixtures offline, same gate, scope, tiers, and audit either way. Safe to demo, safe to repeat.

One engine. Every authorized surface.

The same orchestration engine retargets to any authorized environment by loading a different playbook. Capability themes below are intentionally concept-level; exact techniques are shared under NDA.

Active Directory

Forest to Domain Dominance

  • Recon & enumeration across the in-scope estate
  • Credential access via poisoning, relay, and offline cracking
  • Attack-path analysis and privilege-escalation mapping
  • Certificate-services, delegation, and ACL abuse
  • Lateral movement and domain-dominance steps (human-gated)
Web & API

Unauth Recon to Internal Pivot

  • Unauthenticated recon and authenticated spidering
  • OWASP Top 10 exploitation and logic-flaw testing
  • Credential recovery and CMS / plugin footholds
  • Local privilege escalation to shell
  • Tunneling and pivoting into the internal network
AI / LLM

Model & Agent Robustness

  • OWASP-LLM and MITRE ATLAS-aligned test batteries
  • Prompt-injection and jailbreak probing
  • Retrieval / RAG pipeline poisoning
  • Agent tool-misuse and privilege-path assessment
  • AI-to-internal pivot scenarios

The playbook library

An engagement is data, not code: each playbook is a configuration the engine loads, so the library grows by adding a file, never by rebuilding the platform. Public entries are named by outcome; techniques stay under NDA.

Available

Active Directory Compromise

Full forest-to-domain-dominance kill chain, from recon through credential access, escalation, and lateral movement.

Active DirectoryKill-chain
Available

Web Application Foothold

Unauthenticated web entry through OWASP Top 10 exploitation to a shell, then a pivot into the internal network.

Web & APIKill-chain
Available

AI Surface Red Team

OWASP-LLM and MITRE ATLAS-aligned robustness battery against a target model or agent.

AI / LLMAI red team
Available

AI-to-Internal Pivot

An AI-application breach that chains into the internal network and hands off to the Active Directory path.

AI / LLMKill-chain
In development

Attack Surface Mapping

Continuous, scope-controlled discovery of exposed assets, the engine behind our ASM Snapshot and ASM Watch service.

ExternalASM
In development

Adversary Emulation

Threat-actor-specific command-and-control tradecraft, emulating the behavior of the adversaries targeting your industry.

Cross-surfaceEmulation / C2
In development

Control & Detection Validation

Purple-team assessment of whether defensive controls and detections actually fire against live attacker behavior.

Cross-surfaceControl validation
Roadmap

Cloud Compromise

Identity, misconfiguration, and privilege-escalation paths across cloud environments.

CloudKill-chain

Every playbook, shipped or planned, runs under the same gate: scope-enforced, human-gated, and fully audited.

The human-in-the-loop contract

TierMeaningGate
T0Read-only recon / enumerationAutomatic
T1Low-impact, contained mutationOperator notified
T2State-changing exploitationOperator approval required
T3Destructive / high blast radiusApproval + typed confirmation

How a Corvus-assisted engagement runs.

A sanitized end-to-end path, web foothold into full domain compromise, with no client data. Every state-changing step waits for an operator's explicit approval before it executes.

01

Unauthenticated Recon

Map the external surface, enumerate services, and fingerprint the application. Read-only, runs automatically.

02

Foothold

Exploit a surfaced web vulnerability to recover credentials and land a shell.

Operator-approved
03

Privilege Escalation

Escalate locally on the compromised host using an identified, eligible path.

Operator-approved
04

Pivot

Tunnel into the internal network and hand off to the Active-Directory chain.

Operator-approved
05

Domain Compromise

Chain the AD attack path to domain dominance, the highest-impact steps require typed confirmation.

Typed confirm

What Corvus means for our partners.

Legal

Litigation & Expert Witness

Corvus's audit trail, every command, approver, timestamp, redacted output, and integrity digest, is chain-of-custody-grade evidence. Defensible, reproducible engagement records that hold up in proceedings and back our expert-witness work.

Insurance

Underwriting-Grade Rigor

Scope-controlled, repeatable, fully-logged assessments give insurance-broker partners the consistency underwriting demands, the same coverage, documented the same way, every policy cycle.

Partners

White-Label Delivery

Partners get Corvus-accelerated assessments delivered under their own brand, faster turnaround and broader coverage without adding headcount, with your client relationship staying yours.

AI Ethics

Responsible AI, Demonstrated

Corvus is a working example of responsible AI in offensive security: human oversight on every action, no secrets in prompts, and local-first inference. That credibility carries directly into our AI ethics and compliance reviews.

This page is concept-level by design.

As a security firm, we don't publish the specifics. Corvus is used only on authorized, scope-defined engagements, it won't even load a playbook without confirmed authorization, and it refuses any target outside the allowlist.

Public

The concepts, the runtime-loop architecture, and capability themes you see on this page.

Under NDA

The full capability brief and detailed architecture, available to qualified buyers and partners after a scoping call.

Never Published

The tool manifest and exact technique inventory. Shared only inside an engagement, never on the open web.

Want the full technical brief?

Qualified buyers and MSSP, GRC, legal, and insurance partners can request the complete Corvus capability brief and architecture under NDA. Tell us about your environment and we'll set up a scoping call.