Recon to proof, one unbroken chain.
No exports between tools. No cloud required. One engine carries the whole engagement, from first packet to a proven exploit to a re-test, with no handoffs in between. On an industrial network it carries the same chain across the Purdue boundary, reading controllers rather than writing to them.
Five phases, one continuous operation.
Point Nexich at a network and it runs the full chain the way a red teamer would: map the terrain, decide what matters, break in, prove it, and stand ready to verify the fix. Each phase feeds the next inside a single tool.
See the whole surface.
In autonomous AI modes, a full TCP and UDP port and service sweep on every host, so nothing is missed; deterministic modes map a targeted port set. Web and banner-emitting services are identified by protocol, not by port, so a web app on :8770 is still found and tested as a web app. Once Nexich holds credentials, it also reaches the endpoints that only appear after login.
The AI picks the real paths.
The reasoning ranks what is actually exploitable and chainable: weak or default credentials, exposed admin surfaces, known-vulnerable software with a working exploit, misconfigurations that lead somewhere. It plans from findings and references; the harvested secrets stay in the engine. On a plant network it plans inside a smaller set of allowed moves, because the write function codes are not implementable, a named host closes the aggressive classes, and a short list of channels can never receive a datagram whatever any component asks for.
When no exploit exists, it writes one.
Where a known exploit exists, it fires. For the gaps no list covers, Nexich writes one on the spot and proves it in a hardened sandbox, never against your production data. Coverage runs across every service class an attacker touches, from web and identity to OT and IoT, with 397 native attack modules behind it. See the coverage.
Evidence, or it stays back of house.
In AI-driven modes, a finding is surfaced as a trusted result only after a real exploit reproduces it: a captured shell, a dumped table, a replayed credential owning the next host. Unproven claims are held back from the report, not padded into it, and every engagement closes with an AI-authored executive summary.
Close the loop after a fix ships.
Re-fire proven web and network findings on demand. Nexich reproduces the original exploit path and the AI returns a verdict (still vulnerable, fixed, or inconclusive with the reason) plus a plain-language note on what changed. Validation becomes a one-click loop, not a fresh engagement.
No exports. No stitching by hand.
Most programs lose their momentum at the handoffs: a recon tool feeds a spreadsheet, which feeds an exploit tool, which feeds a report. Nexich keeps the whole engagement in one place, so the credential looted in one phase is already fueling the next. You watch it move from a live map of hosts to scored, proven paths in a single operations center.

A finding is a rumor. A proven path is the truth.
Anyone can hand you a list of maybes. Nexich forges the exploit, detonates it in a hardened sandbox, and captures a real session on a real host. A finding that cannot be independently confirmed is marked inconclusive rather than reported as proven. Looted secrets then recirculate to build cross-host chains, each hop reproduced, evidenced and scored, and on an industrial network that chain is stated in the terms an engineer thinks in: which Purdue level it started at, which level it reached, and what the controller at the end reported about itself.
> level 4 office share · service account readable [proven] > level 3.5 DMZ relay · credential reuse [session] > level 3 engineering ws · project archive read > level 3 historian · production record > level 1 plc-line1 · protection level 1 terminal CRITICAL · path scored 9.8 writes 0 issued to any controller egress 0 bytes off-network (air-gapped) > proof written · reproducible

It reasons. The engine holds the keys.
Nexich runs on any OpenAI-compatible model. Keep it fully air-gapped on a local model for zero egress, or connect a frontier cloud model when your policy allows. Either way the reasoning ranks, plans and drives the operation, while the harvested credentials stay in the engine and replay from there by reference. In hands-on modes the AI advises; in autonomous modes it drives.
Proof your defenders and your auditors accept.
A proven attack path is only useful if the rest of your organization can read it. Every finding lands in the vocabulary your detection team and your assessors already use.
Your defenders' language.
Every proven finding is mapped to the tactics and techniques it exercises, so an attack path Nexich proves lines up directly with the coverage your detection and response team is measured on. Reconnaissance to impact, one shared vocabulary. Export the mapped findings in six formats, including SARIF 2.1.0 for your code-scanning and ticketing pipelines.
Proof your auditors accept.
Red teaming is a control requirement, not a nice-to-have. Nexich maps every proven path to the controls in the frameworks you report against and exports the evidence as Markdown or JSON. Nexich gives you the proof; your assessor signs off.