CREST accreditedCreated by Below0DayInternal and External Penetration Testing

AI-driven continuous penetration testing

Below the surface.Beyond the obvious.

AI-native continuous penetration testing that reasons, adapts, and pivots like a real attacker—then gives your team proven risk and a clear path to fix it.

The system does not stop thinking when the first scan ends.

Discover · Validate · Remediate · Retest

01 / Meet Darko

The decision engine
behind zer0cipher.

zer0cipher is an AI-native continuous penetration testing platform that finds and proves the attack paths putting your environment at risk.

Darko is the decision engine at zer0cipher's core. It learns from each result, chooses what to test next, and stays within the scope and rules you set.

Real attacks do not follow a fixed checklist. Each discovery can open or close a different path. Darko lets zer0cipher adapt as new evidence appears, without stepping outside your controls.

Explore the Darko engine

What Darko considers

  • Live resultsWhat the testing has discovered
  • Your rulesWhat Darko may test and when approval is required
  • Attack knowledgeWhich paths could lead to meaningful impact

How Darko decides

  • LearnWhat changed?
  • PrioritizeWhich path matters most?
  • TestRun the next approved action or ask permission
Live
ENGAGEMENT · 00:00:00
DarkoAutonomous Pentester14:35:42
NTDS Extraction192.168.10.12
Extracting NTDS from the domain controller.
Domain Compromise
Pwn3d!
DarkoAutonomous Pentester14:36:15
Trust Enumerationessos.local
Trust enumeration from essos.local complete.
DarkoAutonomous Pentester14:37:07
AD Graph Collection192.168.10.12
BloodHound collection for essos.local complete.
DarkoAutonomous Pentester14:38:19
Host Credential Harvest192.168.10.10
Credential harvest from 192.168.10.10 — nothing found.
Autopilot — runs approved tests automaticallyGuided — waits for your review before acting
Evidence in · next move out

02 / Adaptive attack story

Every fact changes the next move.

01Recon

Mapped the attack surface.

Darko learned
masscan surfaced WinRM, SMB, LDAP and MSSQL open across the 192.168.10.0/24, then BloodHound mapped the directory.
Next move
Probe the exposed services for a way to capture a credential.

Discovered · 16 recon events

Attack PathRecon16 events
#119:55
Scanned target — Port 389/tcp open
192.168.10.11 · masscan
#1527:14
BloodHound collection on 192.168.10.10
AD GraphLDAP
FLAG20:03
Recon complete — surface mapped
Credential Access
02Credential Access

Captured a credential.

Darko learned
LLMNR/NBT-NS poisoning captured a NetNTLMv2 hash for ROBB.STARK, which then cracked offline.
Next move
Validate the recovered password against reachable hosts.

Proved · password cracked

Attack PathCredential Access20 events
#522:19
LLMNR/NBT-NS poisoning — listening for hashes
LLMNR/NBT-NS Poisoning
#1425:03
Cracked password for ROBB.STARK
north.sevenkingdoms.local\ROBB.STARK
Password Cracking
FLAG25:20
Credentials Discovered
Lateral Movement
03Lateral Movement

Proved access on a host.

Darko learned
The cracked credential validated across north.sevenkingdoms.local over SMB — access confirmed as one claim.
Next move
Pivot toward an account with local-admin rights.

Proved · validated on target

Attack PathLateral Movement8 events
#923:56
smb_login attempt
SMB / Windows Admin Shares
#2333:06
Validated ROBB.STARK on north.sevenkingdoms.local
Password Guessing
FLAG25:20
Domain User Compromised
Privilege Escalation
04Privilege Escalation

Reached local admin.

Darko learned
A validated session escalated to Local Admin on the target — the route into privileged territory.
Next move
Use privileged access to reach the domain's secrets.

Proved · local admin achieved

Attack PathPrivilege Escalation1 event
#2333:06
Validated session on target
SMB Session
FLAG33:17
Local Admin Achieved
north.sevenkingdoms.local
Domain Compromise
05Domain Compromise

Owned the domain.

Darko learned
Secretsdump extracted the full NTDS; domain_admin_achieved landed across all three forests.
Next move
Preserve proof, record cleanup, and stop at the authorized objective.

Proved · domain compromise

Attack PathDomain Compromise10 events
#2534:07
Secretsdump on 192.168.10.11
north.sevenkingdoms.local\ROBB.STARK
NTDSarya.starkrobb.starkkrbtgt
FLAG34:36
domain_admin_achieved
sevenkingdoms.local
Authorized objective reached

Discover continuously. Remediate confidently.

The Loop is how zer0cipher turns penetration testing into continuous risk reduction: discover exposure, validate real attack paths, support the fix, and retest until the evidence shows the risk is closed.

  1. 01

    Discover

    Map assets, services, and identities across the authorized scope.

    Evidence stateScope
  2. 02

    Validate

    Prove which conditions participate in a reachable attack path.

    Evidence stateEvidence
  3. 03

    Fix

    Keep proof, affected assets, and corrective guidance together.

    Evidence stateRemediation
  4. 04

    Assure

    Retest supported fixes, preserve the result, and watch for return.

    Evidence stateRetest

Proof your team can act on.

Managers see impact and priority. Remediators get affected assets, technical evidence, corrective guidance, and supported retesting.

Product interfaceOverwatch / portfolioIllustrative data
zer0cipher Overwatch portfolio view: current posture and the findings that resolve the most attack chains (illustrative)

Portfolio posture, with the fixes that close the most attack chains ranked first.

Illustrative product interface—not a customer outcome
01 Manager

Make the risk digestible.

Impact, affected scope, proof level, and the next decision—without the raw tool noise.

02 Remediator

Make the fix actionable.

Affected assets, technical evidence, corrective guidance, prerequisites, and the supported retest.

Fixes are generated for the specific host — OS, patch level, and configuration accounted for.

Product interfaceAssisted remediationIllustrative — not production
Assisted remediation interface concept: a qualified PowerShell fix with copy and view options (illustrative, not a current production capability)

Assisted execution is qualified per script—operations, rollback, blast radius, and approval—and stays subject to review and policy.

Illustrative interface—not a current production capability
Explore findings and retesting

The models improve. So does zer0cipher.

Bring supported model access that fits your policy while zer0cipher preserves the attack knowledge, evidence, and execution controls around it.

Capability over timeSupported model frontier
TODAYNEXT MODELWHAT FOLLOWS

Change supported models without rebuilding the penetration-testing platform around them.

Model control planeCustomer configured

Bring model access that fits your policy.

Configure your keys for supported providers, then select primary and fallback models by role.

OpenAIAnthropicGoogleLocal
TACTICAL

Select the next path

ANALYSIS

Interpret collected evidence

NARRATIVE

Turn proof into clear findings

Your environment. Your boundary.

Choose SaaS, client-hosted, MSSP-managed, or air-gapped—then place Pinky nodes where authorized scope is reachable.

Managed deployment

Managed Brain. Client-side reach.

HQ, the client-specific Brain deployment, and External Pinky run in zer0cipher-managed AWS. Internal Pinkys execute from approved client VLANs.

zer0cipher-managed AWS
Control planezer0cipher HQFleet + operations
State + evidenceBrain + DarkoClient-specific deployment
ExternalPinkyInternet-facing execution
Client network boundary
Corporate VLAN
Pinky / 01PinkyInternal execution
Restricted VLAN
Pinky / 02PinkyInternal execution
Secure VLAN
Pinky / 03PinkyInternal execution

Internal Pinkys do not bridge VLANs. Each agent reports the networks reachable from its placement and polls for matching engagement work.

Managed HQ + BrainExternal Pinky in AWSOne Pinky per reachable segment

Adversary-minded, built by hackers.

Built by Below0Day. Years of real world offensive tradecraft, custom tooling, proven playbooks, hands-on experience, distilled into a continuous, adaptive AI penetration testing platform.

Read the origin story

08 / Start the conversation

See what zer0cipher finds next.

Bring the environment. We'll show you the path.

Book a Demo