THE CORVUS TECHNOLOGY
Most firms resell the same off-the-shelf offensive tooling. We built our own. Corvus is our proprietary, LLM-assisted red-team technology: the AI handles the exhaustive, repeatable work, discovery, technique chaining, and adaptation, while our operators keep judgment, approve every state-changing action, and run the creative attacks a machine can't. Human-in-the-loop, scope-enforced, and fully audited on every step.
Why We Built It
A boutique firm that builds its own AI-driven, human-gated red-team technology understands the modern attack surface from both sides. That matters most for our AI Security practice: we don't just test AI systems, we build AI security tooling, so we know where these systems break.
Every action any part of Corvus takes passes through a single choke point. Before anything runs, that gate checks the target against a hard scope allowlist, classifies the action by risk, and pauses for a human operator's approval on anything that changes state, then records it. The AI adds speed and adaptivity; it can never widen scope, skip a gate, or act unlogged. This is the proof that we're rigorous, not reckless.
How It Works
Corvus separates AI reasoning into three focused roles, a Planner that picks the next technique, an Operator that builds its arguments from what's been discovered, and an Analyst that turns results into the next recommendation. Every proposed action is forced through one gate that enforces scope, risk tier, human approval, and audit before any real tool runs.
Recon and discovery run exhaustively first, no vector skipped. The selective kill chain only fires techniques whose prerequisites were actually found, and every role reads the same redacted ledger, so the run adapts to what really happened. View the full architecture →
Capabilities
Techniques only become eligible when discovery actually surfaced them. No blind execution, Corvus chains multi-step attack paths that time-boxed manual tests routinely miss.
Read-only recon runs automatically; anything that changes state pauses for operator review, and the highest-impact actions require a typed confirmation. The human decides.
Every recon and enumeration vector runs first, deterministically, before the selective kill chain, so coverage is repeatable and complete, engagement after engagement.
Every action is logged with timestamp, technique, target, risk tier, approver, exact command, redacted output, and an integrity digest, a defensible, reproducible record of record.
LLM roles run on a local model on the engagement host. No secrets ever reach a prompt, and loot and audit never leave the box, a cloud backend is an optional swap, never a requirement.
One switch runs genuine tooling against the authorized lab or replays deterministic fixtures offline, same gate, scope, tiers, and audit either way. Safe to demo, safe to repeat.
Surface Coverage
The same orchestration engine retargets to any authorized environment by loading a different playbook. Capability themes below are intentionally concept-level; exact techniques are shared under NDA.
An engagement is data, not code: each playbook is a configuration the engine loads, so the library grows by adding a file, never by rebuilding the platform. Public entries are named by outcome; techniques stay under NDA.
Full forest-to-domain-dominance kill chain, from recon through credential access, escalation, and lateral movement.
Unauthenticated web entry through OWASP Top 10 exploitation to a shell, then a pivot into the internal network.
OWASP-LLM and MITRE ATLAS-aligned robustness battery against a target model or agent.
An AI-application breach that chains into the internal network and hands off to the Active Directory path.
Continuous, scope-controlled discovery of exposed assets, the engine behind our ASM Snapshot and ASM Watch service.
Threat-actor-specific command-and-control tradecraft, emulating the behavior of the adversaries targeting your industry.
Purple-team assessment of whether defensive controls and detections actually fire against live attacker behavior.
Identity, misconfiguration, and privilege-escalation paths across cloud environments.
Every playbook, shipped or planned, runs under the same gate: scope-enforced, human-gated, and fully audited.
| Tier | Meaning | Gate |
|---|---|---|
| T0 | Read-only recon / enumeration | Automatic |
| T1 | Low-impact, contained mutation | Operator notified |
| T2 | State-changing exploitation | Operator approval required |
| T3 | Destructive / high blast radius | Approval + typed confirmation |
Methodology
A sanitized end-to-end path, web foothold into full domain compromise, with no client data. Every state-changing step waits for an operator's explicit approval before it executes.
Map the external surface, enumerate services, and fingerprint the application. Read-only, runs automatically.
Exploit a surfaced web vulnerability to recover credentials and land a shell.
Operator-approvedEscalate locally on the compromised host using an identified, eligible path.
Operator-approvedTunnel into the internal network and hand off to the Active-Directory chain.
Operator-approvedChain the AD attack path to domain dominance, the highest-impact steps require typed confirmation.
Typed confirmWhere It Pays Off
Corvus's audit trail, every command, approver, timestamp, redacted output, and integrity digest, is chain-of-custody-grade evidence. Defensible, reproducible engagement records that hold up in proceedings and back our expert-witness work.
Scope-controlled, repeatable, fully-logged assessments give insurance-broker partners the consistency underwriting demands, the same coverage, documented the same way, every policy cycle.
Partners get Corvus-accelerated assessments delivered under their own brand, faster turnaround and broader coverage without adding headcount, with your client relationship staying yours.
Corvus is a working example of responsible AI in offensive security: human oversight on every action, no secrets in prompts, and local-first inference. That credibility carries directly into our AI ethics and compliance reviews.
Responsible Disclosure
As a security firm, we don't publish the specifics. Corvus is used only on authorized, scope-defined engagements, it won't even load a playbook without confirmed authorization, and it refuses any target outside the allowlist.
The concepts, the runtime-loop architecture, and capability themes you see on this page.
The full capability brief and detailed architecture, available to qualified buyers and partners after a scoping call.
The tool manifest and exact technique inventory. Shared only inside an engagement, never on the open web.
Qualified buyers and MSSP, GRC, legal, and insurance partners can request the complete Corvus capability brief and architecture under NDA. Tell us about your environment and we'll set up a scoping call.