30
Integrated Modules
500+
Attack Vectors
37
Compliance Frameworks
7
Specialised Categories

Browse by category.

Every module is powered by the same GraphRAG + RLM + MoE engine. Switch between categories to explore coverage, attack vectors, and frameworks.

M01
Web Application Security
Full OWASP Top 10:2021 coverage — injection, broken auth, XSS, SSRF, and beyond.
M02
Network Security
Comprehensive network attack simulation covering 68 vectors across all layers.
M03
Mobile Security
iOS and Android static/dynamic analysis, reverse engineering, and runtime threat detection.
M04
Cloud Security
AWS, Azure, GCP misconfiguration detection and privilege escalation across 46 attack vectors.
M05
VoIP & Telecom Security
SIP protocol analysis, VoIP eavesdropping, toll fraud, and signalling attacks across 16 vectors.
M06
IoT Security
Firmware analysis, default credential exploitation, and RF protocol attacks across 17 vectors.
M07
API Security
REST, GraphQL, and gRPC testing covering OWASP API Top 10 across 13 attack vectors.
M08
Hardware Security
JTAG/UART exploitation, side-channel attacks, and hardware Trojan detection across 31 vectors.
M09
Vehicle & Automotive Security
CAN bus fuzzing, OBD-II exploitation, V2X attacks, and ECU compromise across 46 vectors.
M10
OT / ICS Security
SCADA, Modbus, DNP3 protocol attacks and industrial control system exploitation across 17 vectors.
M11
Prompt Injection
Direct and indirect prompt injection, jailbreaking, and system prompt extraction across 13 vectors.
M12
LLM Security
Comprehensive large language model security across 45 attack vectors including data poisoning and model inversion.
M13
Agentic AI Security
AI agent security — tool misuse, memory poisoning, and autonomous system exploitation across 24 vectors.
M14
Malware Analysis
Static and dynamic malware analysis, sandbox detonation, IOC extraction, and MITRE ATT&CK mapping.
M15
Phishing & Email Security
Spear-phishing simulation, email header analysis, BEC detection, and credential harvesting identification.
M16
Threat Intelligence
Real-time IOC enrichment, threat actor profiling, and strategic intelligence powered by Satyam dark web feeds.
M17
Secure SDLC
Shift-left security — threat modelling, secure code review, and SAST/DAST integrated into development pipelines.
M18
Vulnerability Management
Continuous asset discovery, CVSS-scored vulnerability prioritisation, and remediation workflow tracking.
M19
Healthcare Security
Medical device, EHR, and clinical network security across 327 attack vectors with HIPAA compliance mapping.
M20
Satellite & Space Security
Ground station, uplink/downlink, and satellite bus security across 187 attack vectors.
M21
Software Application Security
Comprehensive application binary and source-level security assessment across 89 attack vectors.
M22
MCP Security
Model Context Protocol security — tool poisoning, context injection, and privilege escalation across 14 vectors.
M23
Quantum Security
Post-quantum cryptography readiness, Shor/Grover algorithm risk analysis across 11 attack vectors.
M24
Communication Security
Encrypted communication protocols, TLS/mTLS analysis, and inter-service communication hardening.
M25
OS Security
Windows, Linux, and macOS hardening — privilege escalation paths, kernel exploits, and CIS benchmark compliance.
M26
Robotics Security
ROS/ROS2 attack surfaces, robot firmware exploitation, and kinematic manipulation attacks across 14 vectors.
M27
Blockchain Security
Smart contract audit, reentrancy and flash loan attacks, bridge exploits across 14 attack vectors.
M28
DevOps & Infrastructure Security
Container escape, Kubernetes RBAC, CI/CD pipeline poisoning, and IaC misconfiguration detection.
M29 · NEW
OSINT & Recon Intelligence
Passive reconnaissance, DNS enumeration, certificate transparency, Shodan/Censys, and Satyam dark web integration.
M30 · NEW
Compliance Automation
37 frameworks, 1,718+ controls, automated evidence collection, gap analysis, and 90% audit prep reduction.
Web Application Security
M01

Full coverage of OWASP Top 10:2021 — SQL injection, broken access control, cryptographic failures, XSS, security misconfiguration, SSRF, and insecure design. Combines automated scanning with AI-driven manual exploit reasoning.

OWASP A01–A10:2021
  • Full OWASP A01–A10:2021 coverage including server-side request forgery
  • AI-generated exploitation proofs and remediation code
  • Authentication bypass, session management, and CSRF testing
Network Security
M02

68-vector network attack simulation spanning reconnaissance, enumeration, exploitation, and lateral movement. Covers TCP/IP stack attacks, routing protocol manipulation, VPN vulnerabilities, and wireless network exploitation.

NIST SP 800-115 68 vectors
  • ARP spoofing, VLAN hopping, and network pivoting
  • BGP and OSPF routing protocol attacks
  • Wireless: WPA3 downgrade, PMKID, evil twin
Mobile Security
M03

iOS and Android security assessments aligned with OWASP MASVS. Static binary analysis, dynamic instrumentation, certificate pinning bypass, and insecure data storage identification.

OWASP MASVS iOS · Android
  • Frida-powered dynamic instrumentation and hook detection
  • Insecure local storage and weak cryptography identification
  • Deep link injection and intent-based attack vectors
Cloud Security
M04

Multi-cloud security posture management and attack simulation across 46 vectors. Covers IAM privilege escalation, exposed S3/Blob storage, Lambda/Cloud Functions misconfigurations, and container orchestration weaknesses.

CIS Cloud Benchmarks 46 vectors
  • AWS, Azure, and GCP IAM privilege escalation paths
  • Storage misconfiguration and public bucket detection
  • Kubernetes RBAC and pod security policy analysis
VoIP & Telecom Security
M05

16 VoIP attack vectors covering SIP protocol abuse, media stream interception, caller ID spoofing, toll fraud, and telephony denial-of-service. Aligned with OWASP VoIP Top 10.

OWASP VoIP 16 vectors
IoT Security
M06

17 attack vectors targeting IoT ecosystems. Firmware extraction and analysis, default credential exploitation, Bluetooth/Zigbee/Z-Wave protocol attacks, and cloud backend testing for connected devices.

OWASP IoT Top 10 17 vectors
API Security
M07

REST, GraphQL, gRPC, and WebSocket API testing across 13 OWASP API Top 10 categories. Includes BOLA/IDOR discovery, mass assignment, and API key exposure scanning with automated OpenAPI spec parsing.

OWASP API Top 10 13 vectors
Secure SDLC
M17

Security integrated across the entire development lifecycle — from threat modelling and architecture review to code-level SAST and DAST testing. Shift-left security with CI/CD pipeline integration.

OWASP SAMM
Vulnerability Management
M18

Continuous asset discovery, vulnerability scanning, CVSS 4.0 scoring, and risk-prioritised remediation workflows. Integrates with ticketing systems and provides developer-ready fix guidance.

CVSS 4.0
Software Application Security
M21

89-vector application security testing covering binary exploitation, memory corruption, deserialization, and OWASP ASVS Level 3 controls. Supports web, desktop, and CLI applications.

OWASP ASVS 89 vectors
Communication Security
M24

TLS/mTLS configuration analysis, certificate management, inter-service communication hardening, and encrypted protocol assessment covering NIST SP 800-52 guidelines.

NIST SP 800-52
OS Security
M25

Windows, Linux, and macOS security hardening aligned with CIS Benchmarks. Privilege escalation path analysis, kernel exploit identification, and automated hardening script generation.

CIS Benchmarks
DevOps & Infrastructure Security
M28

Container escape techniques, Kubernetes RBAC misconfiguration, CI/CD pipeline poisoning, supply chain attacks, and IaC (Terraform/Helm) security analysis against CIS Kubernetes benchmarks.

CIS Kubernetes
Hardware Security
M08

31 hardware attack vectors including JTAG/UART debugging interfaces, side-channel power analysis, fault injection, and hardware Trojan detection. Covers PCB-level and chip-level assessments aligned with NIST SP 800-193.

NIST SP 800-193 31 vectors
  • JTAG/UART boundary scan and firmware extraction
  • Differential power analysis (DPA) and electromagnetic side-channels
  • Glitch attacks and voltage/clock fault injection
Vehicle & Automotive Security
M09

46 automotive attack vectors covering CAN bus fuzzing, OBD-II exploitation, V2X (vehicle-to-everything) communication attacks, keyless entry relay attacks, and ECU firmware exploitation. Aligned with UN R155 and ISO/SAE 21434.

UN R155 ISO/SAE 21434 46 vectors
  • CAN bus injection, spoofing, and fuzzing
  • V2X DSRC and C-V2X protocol attacks
  • Telematics unit and infotainment system exploitation
OT / ICS Security
M10

17 OT/ICS attack vectors targeting SCADA systems, PLCs, and industrial control networks. Covers Modbus, DNP3, EtherNet/IP, and Profinet protocol vulnerabilities aligned with IEC 62443 industrial security standards.

IEC 62443 17 vectors
  • Modbus and DNP3 protocol manipulation
  • HMI exploitation and historian compromise
  • Air-gap bypass and USB-based attack detection
Healthcare Security
M19

327 healthcare-specific attack vectors — the largest domain coverage in the platform. Covers DICOM/HL7/FHIR protocol attacks, medical device exploitation, EHR system vulnerabilities, and clinical network segmentation testing with HIPAA/HITECH compliance mapping.

HIPAA HITECH 327 vectors
  • Medical device firmware and network interface attacks
  • DICOM, HL7, and FHIR protocol vulnerabilities
  • PHI exfiltration paths and access control weaknesses
Satellite & Space Security
M20

187 attack vectors across satellite ground stations, uplink/downlink communications, space segment, and mission control systems. Covers signal jamming, spoofing, command injection, and ground station compromise aligned with NIST SP 800-53.

NIST SP 800-53 187 vectors
  • GPS/GNSS spoofing and jamming detection
  • Satellite command and control injection
  • Ground station network and TT&C link attacks
Quantum Security
M23

11 quantum-era threat vectors including Shor's algorithm RSA/ECC cracking risk, Grover's algorithm symmetric key weakening, and harvest-now-decrypt-later (HNDL) attack modelling. Provides post-quantum cryptography migration roadmaps per NIST PQC standards.

NIST PQC 11 vectors
  • RSA/ECC vulnerability timeline modelling (CRQCs)
  • CRYSTALS-Kyber and CRYSTALS-Dilithium migration guidance
  • HNDL exposure assessment for sensitive long-lived data
Robotics Security
M26

14 robotics attack vectors targeting ROS/ROS2 middleware, robot firmware, kinematic control manipulation, and safety system bypass. Covers collaborative robot (cobot) and autonomous mobile robot (AMR) security.

IEC 62443 14 vectors
Blockchain Security
M27

14 blockchain and DeFi attack vectors including smart contract reentrancy, integer overflow, oracle manipulation, flash loan attacks, and cross-chain bridge exploitation. Supports Solidity, Vyper, and Rust-based smart contracts.

OWASP Smart Contract 14 vectors
  • Reentrancy and cross-function reentrancy attacks
  • Oracle price manipulation and flash loan exploitation
  • ERC-20/ERC-721 token standard vulnerabilities
Prompt Injection
M11

13 prompt injection attack vectors targeting LLM-powered applications. Covers direct prompt injection (overriding system prompts), indirect injection via external data sources, jailbreaking techniques, and system prompt extraction. OWASP LLM Top 10 LLM01 aligned.

OWASP LLM Top 10 13 vectors
  • Direct prompt injection and instruction override
  • Indirect injection via RAG data sources and tool outputs
  • Multi-turn jailbreak chaining and persona manipulation
LLM Security
M12

The most comprehensive LLM security module available — 45 attack vectors covering all 10 OWASP LLM Top 10 categories. Includes training data poisoning, model inversion, membership inference, sensitive information disclosure, and supply chain attacks on model weights and fine-tuning datasets.

OWASP LLM Top 10 45 vectors
  • Training data poisoning and backdoor trigger detection
  • Model inversion and membership inference attacks
  • Sensitive data leakage from context windows and caches
  • Model weight supply chain integrity verification
Agentic AI Security
M13

24 agentic AI attack vectors targeting autonomous AI systems that plan and execute multi-step tasks with tool access. Covers tool misuse, memory poisoning, goal hijacking, privilege escalation via tool chaining, and unsafe code execution paths.

OWASP LLM Top 10 24 vectors
  • Tool misuse and permission escalation via chained calls
  • Agent memory poisoning and long-term context attacks
  • Goal hijacking through environmental manipulation
MCP Security
M22

14 Model Context Protocol (MCP) attack vectors — the first dedicated security module for MCP-based AI systems. Covers tool poisoning, context injection, server impersonation, privilege escalation, and cross-server attack paths.

OWASP LLM Top 10 14 vectors
  • MCP tool poisoning and malicious server injection
  • Context window manipulation via crafted tool responses
  • Cross-server privilege escalation via MCP chaining
Malware Analysis
M14

AI-assisted static and dynamic malware analysis powered by the VM Execution Layer. Automated sandbox detonation, IOC extraction, YARA rule generation, and full MITRE ATT&CK TTP mapping for every analysed sample.

MITRE ATT&CK
  • PE, ELF, Mach-O, and script-based malware analysis
  • Sandbox detonation with behavioural trace capture
  • Automated IOC extraction and VirusTotal enrichment
Phishing & Email Security
M15

AI-powered phishing detection and simulation — spear-phishing campaign analysis, email header forensics, BEC (Business Email Compromise) detection, credential harvesting page identification, and DKIM/DMARC/SPF configuration auditing.

MITRE ATT&CK
Threat Intelligence
M16

Real-time threat intelligence powered by Satyam dark web integration. IOC enrichment against VirusTotal, Shodan, and Censys, threat actor profiling, campaign attribution, and strategic intelligence reports in STIX/TAXII format.

Satyam Intel
  • Dark web credential leak monitoring and alerting
  • Threat actor TTP profiling and campaign tracking
  • STIX/TAXII 2.1 intelligence sharing format output
New in v3.0

M29 — OSINT & Recon Intelligence

Passive and active reconnaissance powered by Satyam dark web integration — delivering a complete digital exposure score for any target domain, organisation, or individual.

Digital Exposure Score
Every OSINT assessment produces a 0–100 Digital Exposure Score — a single quantified risk metric synthesising attack surface size, leaked credentials, dark web mentions, and public vulnerability exposure.
Passive Reconnaissance
Zero-footprint intelligence gathering using public DNS records, WHOIS history, certificate transparency logs, BGP routing data, and Shodan/Censys internet-wide scan databases.
DNS & Certificate Enumeration
Subdomain enumeration via DNS brute-force, zone transfer attempts, certificate transparency (crt.sh, Facebook CT), and passive DNS history for forgotten or shadow IT assets.
Shodan & Censys Intelligence
Real-time internet scan queries against Shodan and Censys — identifying exposed services, vulnerable software versions, default credentials, and misconfigured infrastructure across your IP ranges.
Social Media OSINT
Automated employee profiling, organisational structure mapping, technology stack inference from job postings, and social engineering vector identification across LinkedIn, GitHub, and public forums.
Satyam Dark Web Integration
M29 combines standard OSINT sources with Satyam's live dark web feeds — automatically correlating surface web reconnaissance with underground marketplace listings, paste site dumps, and threat actor communications.
Credential leak monitoring across dark web forums
Dark web marketplace listings for target assets
Threat actor discussion monitoring and alerting
Paste site monitoring for leaked internal data
OSINT Data Sources
Shodan
Censys
crt.sh (CT Logs)
WHOIS / RDAP
Passive DNS
GitHub Dorking
Wayback Machine
Satyam Dark Web
New in v3.0

M30 — Compliance Automation

37 compliance frameworks. 1,718+ controls. 90% reduction in audit preparation time. From SOC 2 to ISO 27001 to HIPAA — one AI engine covers them all.

37
Frameworks
1,718+
Controls Mapped
90%
Audit Prep Reduction
24/7
Continuous Monitoring
Security & Privacy Frameworks
SOC 2 Type II ISO 27001:2022 ISO 27701 NIST CSF 2.0 NIST SP 800-53 CIS Controls v8 GDPR CCPA LGPD PDPA
Industry-Specific Frameworks
HIPAA HITECH PCI DSS v4.0 PCI PIN FFIEC FedRAMP FISMA CMMC 2.0
Regional & Cloud Frameworks
CSA STAR AWS Well-Architected Azure Security GCP Security DPDP Act (India) SAMA CSF MAS TRM Essential 8
Automated Evidence Collection
AI-driven evidence gathering links security controls directly to supporting documentation, configuration exports, and scan results — eliminating manual spreadsheet work that takes weeks.
Gap Analysis & Remediation
Instant gap reports identify control deficiencies, map them to risk severity, and generate prioritised remediation plans with specific technical actions and policy recommendations.
Continuous Monitoring
Compliance posture is monitored 24/7 — automated drift detection alerts you the moment a configuration change violates a mapped control, before it becomes an audit finding.
Auditor-Ready Reports
Generate auditor-grade evidence packages in the format required by each framework — SOC 2 trust service criteria, ISO 27001 Statement of Applicability, PCI DSS Report on Compliance, and more.
All 30 Modules Included

Explore the platform in depth.

Dive deeper into each intelligence layer or book a live demo to see all 30 modules in action against your real infrastructure.

No credit card required · All 30 modules · Cancel anytime