How it works

Recon to proof, one unbroken chain.

No exports between tools. No cloud required. One engine carries the whole engagement, from first packet to a proven exploit to a re-test, with no handoffs in between. On an industrial network it carries the same chain across the Purdue boundary, reading controllers rather than writing to them.

The method

Five phases, one continuous operation.

Point Nexich at a network and it runs the full chain the way a red teamer would: map the terrain, decide what matters, break in, prove it, and stand ready to verify the fix. Each phase feeds the next inside a single tool.

01 · Discover

See the whole surface.

In autonomous AI modes, a full TCP and UDP port and service sweep on every host, so nothing is missed; deterministic modes map a targeted port set. Web and banner-emitting services are identified by protocol, not by port, so a web app on :8770 is still found and tested as a web app. Once Nexich holds credentials, it also reaches the endpoints that only appear after login.

02 · Prioritize

The AI picks the real paths.

The reasoning ranks what is actually exploitable and chainable: weak or default credentials, exposed admin surfaces, known-vulnerable software with a working exploit, misconfigurations that lead somewhere. It plans from findings and references; the harvested secrets stay in the engine. On a plant network it plans inside a smaller set of allowed moves, because the write function codes are not implementable, a named host closes the aggressive classes, and a short list of channels can never receive a datagram whatever any component asks for.

03 · Forge

When no exploit exists, it writes one.

Where a known exploit exists, it fires. For the gaps no list covers, Nexich writes one on the spot and proves it in a hardened sandbox, never against your production data. Coverage runs across every service class an attacker touches, from web and identity to OT and IoT, with 397 native attack modules behind it. See the coverage.

04 · Prove

Evidence, or it stays back of house.

In AI-driven modes, a finding is surfaced as a trusted result only after a real exploit reproduces it: a captured shell, a dumped table, a replayed credential owning the next host. Unproven claims are held back from the report, not padded into it, and every engagement closes with an AI-authored executive summary.

05 · Re-test

Close the loop after a fix ships.

Re-fire proven web and network findings on demand. Nexich reproduces the original exploit path and the AI returns a verdict (still vulnerable, fixed, or inconclusive with the reason) plus a plain-language note on what changed. Validation becomes a one-click loop, not a fresh engagement.

One tool, no seams

No exports. No stitching by hand.

Most programs lose their momentum at the handoffs: a recon tool feeds a spreadsheet, which feeds an exploit tool, which feeds a report. Nexich keeps the whole engagement in one place, so the credential looted in one phase is already fueling the next. You watch it move from a live map of hosts to scored, proven paths in a single operations center.

Live host and service mapFindings ranked in placeProof written per finding
nexich · operations center
The Nexich operations center: live hosts, findings and proven exploits across an engagement.
Forge and prove

A finding is a rumor. A proven path is the truth.

Anyone can hand you a list of maybes. Nexich forges the exploit, detonates it in a hardened sandbox, and captures a real session on a real host. A finding that cannot be independently confirmed is marked inconclusive rather than reported as proven. Looted secrets then recirculate to build cross-host chains, each hop reproduced, evidenced and scored, and on an industrial network that chain is stated in the terms an engineer thinks in: which Purdue level it started at, which level it reached, and what the controller at the end reported about itself.

LEVEL 4 TO LEVEL 1, WITHOUT WRITING TO ANYTHING Illustrative Purdue crossing. Every hop is a read or a credential replay. No write is issued to any controller. svc acct eng cred historian account controller profile LEVEL 4 · ENTERPRISE 10.10.1.20 office share service account readable LEVEL 3.5 · DMZ 10.20.0.10 DMZ relay session via reuse LEVEL 3 · SITE OPS 10.30.10.31 engineering ws project archive read LEVEL 3 · HISTORIAN Production record 3.2M tag values exported LEVEL 1 · CONTROL Line 1 control protection level 1, open NO WRITE ISSUED One office credential. Four hops. Two crown jewels an engineer recognises, and nothing written to the process. read only
nexich · engagement.log
> level 4    office share · service account readable [proven]
> level 3.5  DMZ relay · credential reuse [session]
> level 3    engineering ws · project archive read
> level 3    historian · production record
> level 1    plc-line1 · protection level 1

  terminal   CRITICAL · path scored 9.8
  writes     0 issued to any controller
  egress     0 bytes off-network (air-gapped)
> proof written · reproducible
Purdue crossingProven, then closed
Writes to the processNone
EvidenceThe exchange, per finding
Data leaving networkNone (air-gapped)
nexich · settings · ai integrations
The model-agnostic AI Integrations screen: local and cloud providers in one place.
The brain stays yours

It reasons. The engine holds the keys.

Nexich runs on any OpenAI-compatible model. Keep it fully air-gapped on a local model for zero egress, or connect a frontier cloud model when your policy allows. Either way the reasoning ranks, plans and drives the operation, while the harvested credentials stay in the engine and replay from there by reference. In hands-on modes the AI advises; in autonomous modes it drives.

Local, air-gappedFrontier cloud, optionalGated on capability, not a vendor list
Findings in a shared language

Proof your defenders and your auditors accept.

A proven attack path is only useful if the rest of your organization can read it. Every finding lands in the vocabulary your detection team and your assessors already use.

MITRE ATT&CK

Your defenders' language.

Every proven finding is mapped to the tactics and techniques it exercises, so an attack path Nexich proves lines up directly with the coverage your detection and response team is measured on. Reconnaissance to impact, one shared vocabulary. Export the mapped findings in six formats, including SARIF 2.1.0 for your code-scanning and ticketing pipelines.

ReconnaissanceInitial AccessExecutionCredential AccessDiscoveryLateral MovementPrivilege EscalationCollectionExfiltrationImpact
Compliance evidence

Proof your auditors accept.

Red teaming is a control requirement, not a nice-to-have. Nexich maps every proven path to the controls in the frameworks you report against and exports the evidence as Markdown or JSON. Nexich gives you the proof; your assessor signs off.

PCI DSSNIST SP 800-53NIST SP 800-171NIST CSFISO/IEC 27001SOC 2HIPAAGDPRDORANIS2CMMC 2.0CIS ControlsOWASP ASVS
Access

See it run on your own network.

Evaluation builds · Authorized testing only