Breach simulation and automated pen-testing
Platforms that safely emulate attacker techniques against live environments to validate whether controls work.
8 vendors · alphabetical, never ranked
- AttackIQAttackIQ sells a continuous threat exposure management platform that validates whether security controls detect and stop adversary techniques, and links vulnerabilities, configurations, identities and detections into attack paths so teams can prioritize fixes.Ownership not established
- CymulateCymulate sells a platform that runs continuous simulations of attacker techniques against an organization's security controls, then prioritizes findings and can automate updates to those controls.Ownership not established · primary category
- Horizon3.aiHorizon3.ai sells NodeZero, a system that autonomously tests an organization's defenses by attempting attacks, then prioritizes exploitable attack paths and verifies that fixes worked.Privately held · primary category
- PenteraPentera sells a platform that emulates attacker techniques against an organization's systems to test whether its security controls actually stop them, then guides remediation of the gaps found.Privately held · primary category
- Picus SecurityPicus Security sells a platform that simulates real-world attack techniques against an organization's environment to test and help tune its security controls.Ownership not established · primary category
- SafeBreachSafeBreach sells an exposure validation platform that combines breach and attack simulation with attack-path validation, adding AI agents to help discover exposures and coordinate fixes.Ownership not established · primary category
- Skyhawk SecuritySkyhawk Security sells a cloud threat detection and response platform whose Autonomous Purple Team ingests findings from a customer's existing cloud security tools and tests them against a digital twin of the production environment to confirm which ones are actually exploitable.Privately held
- XM CyberXM Cyber sells a continuous exposure management platform that maps and validates attack paths across on-premises and cloud networks, using a threat-led approach to show which exposures to fix first.Owned by Schwarz Group since 2021
No vendor pays to be listed or to change what we write. Descriptions are ours, drawn from each company's own site and filings. Corrections: /corrections.