Everything the platform brings to an engagement.
A grouped tour of what Nexich does, from the first packet to a proven breach to a signed-off fix. This is the capability set, in plain terms. How each part works under the hood stays where it belongs: inside your perimeter.
The capability set
Nine groups, one operation.
Every group below runs inside a single engagement. Point Nexich at a network and it moves through them in order, from mapping the terrain to handing you proof built for audit review.
01 · Discovery
See the whole surface.
- Maps every reachable host and the services that answer on it
- Identifies services by protocol behavior, not just port number, for web and banner-emitting services
- A full 1-65535 TCP and UDP sweep per host in the autonomous modes
- Authenticated crawling reaches the endpoints that only appear after login
- A live map of hosts, services and terrain as it goes
02 · Coverage
From IT to OT.
- Web apps, APIs and exposed admin surfaces
- Identity and Active Directory in depth: Kerberoasting, AS-REP roasting, DCSync, ADCS ESC abuse, RBCD, NTDS parsing, password spraying
- Databases, message queues, remote access and file shares
- VoIP, and OT / ICS + IoT on their real protocols: Modbus, S7comm, EtherNet/IP, BACnet, DNP3
- 200+ native attack modules in one platform
03 · Exploitation & Forge
Proof, not a maybe.
- Chains and detonates findings into a real, reproducible exploit
- When no known exploit exists, it authors a custom one on the spot
- Catches the variants an incomplete fix leaves open
- Every synthesized exploit is validated in an isolated sandbox where hardware virtualization is available, a constrained host runner otherwise, before it fires at the authorized target
04 · Proof
Reproduced, or held back.
- In the AI-driven modes, a finding is surfaced as a trusted result only after a real exploit reproduces it
- Proof arrives as a captured shell, a dumped table, or a replayed credential
- Per-finding evidence: the exact request and response plus a copy-paste reproducer
- Unproven claims stay back of house, never padded into the report
05 · Cross-host chains
The real path to the crown jewels.
- Looted credentials replay from host to host to build the true attack path
- Real authentication across 30 native service handlers: SSH, SMB, WinRM, RDP, and the major databases
- Every hop reproduced, evidenced and scored
- Credentials persist across operations with their origin tracked
- Rate-limited and lockout-safe, with a control that flags accept-any services instead of reporting them as a hit
06 · Operating modes
An autonomy ladder.
- Classic: deterministic and hands-on, you drive
- Smart: adaptive, automated web-application testing
- AI Hybrid: the AI runs recon and drives exploitation, you keep scope and the final say
- AI Autonomous: the AI plans and runs the whole engagement
- AI Forge: the deepest mode, researching unknown services and authoring exploits
07 · Your model, your metal
Model agnostic, sovereign.
- Runs on any OpenAI-compatible model
- Fully air-gapped on a local model for zero egress, or a frontier cloud model when policy allows
- Gated on model capability, not on a fixed vendor list
- Harvested credentials stay in the engine and replay from there by reference
- Run it air-gapped and the reasoning, the exploits and the loot all stay inside your perimeter
08 · Reporting & re-test
Evidence built for audit review.
- A live operations center: hosts, findings and proven paths in one place
- A data-driven attack graph from entry to crown jewel, laid out by MITRE phase
- An AI-authored, client-ready executive summary
- Export in six formats, including SARIF 2.1.0 with EPSS and KEV enrichment that drops into CI/CD
- Every proven path mapped to MITRE ATT&CK and the controls, exported as Markdown or JSON today
- One-click re-test after a fix, with a verdict and a plain-language note on what changed
09 · Sovereign by design
Nothing leaves your metal.
- Self-hosted, with a first-class air-gapped mode
- Zero telemetry and no phone-home on by default
- White-labeled: no third-party tool names or fingerprints on the wire
- Your topology, credentials and findings live in a database you control and can wipe
- Runs on Windows and Linux, with no agents to install on your targets
- Licensed by in-scope IP address, for authorized testing only
Coverage universe
If it answers on the wire, it is in scope.
Detection keys off protocol behavior, not the port a device sits on, so Nexich tests what a thing really is. That reach runs far past the usual IT stack, into OT, IoT and the systems that run a business.
Core IT & network
- Web apps and APIs: the application layer, login flows and admin panels
- Databases: Postgres, MySQL, MSSQL, Oracle, MongoDB, Redis, Elasticsearch and more
- Active Directory and identity: Kerberos, LDAP, ADCS, SSO and federation
- Message queues: Kafka, RabbitMQ, AMQP and MQTT
- Remote access: SSH, RDP, VNC, WinRM and Telnet
- File shares and NAS: SMB, NFS, FTP and storage appliances
- Virtualization and containers: hypervisors, Kubernetes and registries
- CI/CD and source control: build runners, pipelines and code repositories
- Monitoring and logging: dashboards, log stores and metrics endpoints
- Infrastructure: routers, switches, firewalls, VPNs, backup, out-of-band controllers, UPS and PDU
OT, ICS & SCADA
- Industrial protocols: Modbus, S7comm, EtherNet/IP, BACnet, DNP3 and PROFINET
- Building automation: HVAC, access control and building management systems
- Manufacturing and plant floor: PLCs, HMIs and historians
IoT & connected devices
- IoT fabrics: CoAP and MQTT device networks
- Smart home and hubs: connected controllers and gateways
- Cameras and NVR: IP cameras and video recorders
- Printers and MFPs: networked printers and multifunction devices
- VoIP and SIP: phones, PBX and session border controllers
- Robotics, drones and vehicles: connected and autonomous systems
Sector systems
- Healthcare: medical devices and clinical inventory systems
- Finance: banking systems, ATM and point of sale
- Telecom: carrier and network operator systems
- Public sector: government and critical services
- Retail and hospitality: point of sale and property systems
- Transport: transportation and aviation systems
Each class is served by native attack modules, not a generic port probe.