Features

Everything the platform brings to an engagement.

A grouped tour of what Nexich does, from the first packet to a proven breach to a signed-off fix. This is the capability set, in plain terms. How each part works under the hood stays where it belongs: inside your perimeter.

The capability set

Nine groups, one operation.

Every group below runs inside a single engagement. Point Nexich at a network and it moves through them in order, from mapping the terrain to handing you proof built for audit review.

01 · Discovery

See the whole surface.

  • Maps every reachable host and the services that answer on it
  • Identifies services by protocol behavior, not just port number, for web and banner-emitting services
  • A full 1-65535 TCP and UDP sweep per host in the autonomous modes
  • Authenticated crawling reaches the endpoints that only appear after login
  • A live map of hosts, services and terrain as it goes
02 · Coverage

From IT to OT.

  • Web apps, APIs and exposed admin surfaces
  • Identity and Active Directory in depth: Kerberoasting, AS-REP roasting, DCSync, ADCS ESC abuse, RBCD, NTDS parsing, password spraying
  • Databases, message queues, remote access and file shares
  • VoIP, and OT / ICS + IoT on their real protocols: Modbus, S7comm, EtherNet/IP, BACnet, DNP3
  • 200+ native attack modules in one platform
03 · Exploitation & Forge

Proof, not a maybe.

  • Chains and detonates findings into a real, reproducible exploit
  • When no known exploit exists, it authors a custom one on the spot
  • Catches the variants an incomplete fix leaves open
  • Every synthesized exploit is validated in an isolated sandbox where hardware virtualization is available, a constrained host runner otherwise, before it fires at the authorized target
04 · Proof

Reproduced, or held back.

  • In the AI-driven modes, a finding is surfaced as a trusted result only after a real exploit reproduces it
  • Proof arrives as a captured shell, a dumped table, or a replayed credential
  • Per-finding evidence: the exact request and response plus a copy-paste reproducer
  • Unproven claims stay back of house, never padded into the report
05 · Cross-host chains

The real path to the crown jewels.

  • Looted credentials replay from host to host to build the true attack path
  • Real authentication across 30 native service handlers: SSH, SMB, WinRM, RDP, and the major databases
  • Every hop reproduced, evidenced and scored
  • Credentials persist across operations with their origin tracked
  • Rate-limited and lockout-safe, with a control that flags accept-any services instead of reporting them as a hit
06 · Operating modes

An autonomy ladder.

  • Classic: deterministic and hands-on, you drive
  • Smart: adaptive, automated web-application testing
  • AI Hybrid: the AI runs recon and drives exploitation, you keep scope and the final say
  • AI Autonomous: the AI plans and runs the whole engagement
  • AI Forge: the deepest mode, researching unknown services and authoring exploits
07 · Your model, your metal

Model agnostic, sovereign.

  • Runs on any OpenAI-compatible model
  • Fully air-gapped on a local model for zero egress, or a frontier cloud model when policy allows
  • Gated on model capability, not on a fixed vendor list
  • Harvested credentials stay in the engine and replay from there by reference
  • Run it air-gapped and the reasoning, the exploits and the loot all stay inside your perimeter
08 · Reporting & re-test

Evidence built for audit review.

  • A live operations center: hosts, findings and proven paths in one place
  • A data-driven attack graph from entry to crown jewel, laid out by MITRE phase
  • An AI-authored, client-ready executive summary
  • Export in six formats, including SARIF 2.1.0 with EPSS and KEV enrichment that drops into CI/CD
  • Every proven path mapped to MITRE ATT&CK and the controls, exported as Markdown or JSON today
  • One-click re-test after a fix, with a verdict and a plain-language note on what changed
09 · Sovereign by design

Nothing leaves your metal.

  • Self-hosted, with a first-class air-gapped mode
  • Zero telemetry and no phone-home on by default
  • White-labeled: no third-party tool names or fingerprints on the wire
  • Your topology, credentials and findings live in a database you control and can wipe
  • Runs on Windows and Linux, with no agents to install on your targets
  • Licensed by in-scope IP address, for authorized testing only
Coverage universe

If it answers on the wire, it is in scope.

Detection keys off protocol behavior, not the port a device sits on, so Nexich tests what a thing really is. That reach runs far past the usual IT stack, into OT, IoT and the systems that run a business.

Core IT & network
  • Web apps and APIs: the application layer, login flows and admin panels
  • Databases: Postgres, MySQL, MSSQL, Oracle, MongoDB, Redis, Elasticsearch and more
  • Active Directory and identity: Kerberos, LDAP, ADCS, SSO and federation
  • Message queues: Kafka, RabbitMQ, AMQP and MQTT
  • Remote access: SSH, RDP, VNC, WinRM and Telnet
  • File shares and NAS: SMB, NFS, FTP and storage appliances
  • Virtualization and containers: hypervisors, Kubernetes and registries
  • CI/CD and source control: build runners, pipelines and code repositories
  • Monitoring and logging: dashboards, log stores and metrics endpoints
  • Infrastructure: routers, switches, firewalls, VPNs, backup, out-of-band controllers, UPS and PDU
OT, ICS & SCADA
  • Industrial protocols: Modbus, S7comm, EtherNet/IP, BACnet, DNP3 and PROFINET
  • Building automation: HVAC, access control and building management systems
  • Manufacturing and plant floor: PLCs, HMIs and historians
IoT & connected devices
  • IoT fabrics: CoAP and MQTT device networks
  • Smart home and hubs: connected controllers and gateways
  • Cameras and NVR: IP cameras and video recorders
  • Printers and MFPs: networked printers and multifunction devices
  • VoIP and SIP: phones, PBX and session border controllers
  • Robotics, drones and vehicles: connected and autonomous systems
Sector systems
  • Healthcare: medical devices and clinical inventory systems
  • Finance: banking systems, ATM and point of sale
  • Telecom: carrier and network operator systems
  • Public sector: government and critical services
  • Retail and hospitality: point of sale and property systems
  • Transport: transportation and aviation systems

Each class is served by native attack modules, not a generic port probe.

See it on your network

Bring the red team inside the wire.

Self-hosted · Air-gapped · Authorized testing only