How a run works, start to re-attack.
30-minute call · rules of engagement before anything runs · a run takes 2 to 4 weeks · reports at close
Radius runs the same loop an attacker runs (observe, reason, attack, validate, report) inside the rules of engagement you signed. Then, once you fix a path, it attacks that path again.
Five steps. One order.
Every run follows the same five steps, whether the environment is a cloud tenant, a corporate network or a plant floor. Radius does the technical work; Piscium scopes the run, drafts the rules of engagement and stays on the call.
- Passive first: nothing is written to a controller unless you authorize it
- The real chain, run inside the rules you signed
- Three reports at three levels, then a re-attack once you fix it
Observe
Radius discovers and watches the surface: assets, services, identities and dependencies, including what was never in the inventory. It starts passively, so nothing is written to a controller.
- Assets, services, identities and dependencies, as well as hosts
- Finds what the inventory missed
- Passive by default, with active probing only where you authorize it, asset by asset
Reason
Radius builds the attack graph and decides what to try first, by where each path leads, not by severity score. It starts from what it already knows about your environment from the last run.
- Every path traced to what it reaches
- Chains that share a hop share a fix
- Findings mapped to MITRE ATT&CK techniques
Attack
Radius runs the real chain against your environment, inside the rules of engagement you signed. It does not simulate it. The rules live in the engine: every action is checked against them before it runs.
- Per-asset rules of engagement, enforced before every action
- Non-bypassable safety patterns above your own blocklist
- A stop button that works mid-run
Validate
Radius confirms whether the path worked and how far it got. It stops before the destructive payload. Every action is logged with the decision, the reason and the rules in force at that moment.
- How far the chain got, hop by hop
- Stops short of impact
- Command, timestamp and decision recorded
Report
Radius delivers reproducible evidence, the fix and the priority in three reports, each at three levels. Critical findings are communicated the moment they are validated, not at the end. After you fix a path, it attacks the same path again.
- Executive, technical and compliance reports
- Each at run, asset and finding level, nine documents in all
- Re-attack of every fixed path
Nine documents per run
What you are left holding
Most testing leaves you with a PDF. A run leaves you with evidence, a trail and memory.
Executive
Executive report
What was exposed, what it would cost an attacker, and what changed after remediation. Written to be read by people who do not run the tooling.
For the board and the exec team
Technical
Technical report
The validated attack paths themselves: reachability, the chain at each hop, and the evidence captured when a path was proven exploitable.
For your security engineers
Compliance
Compliance report
The same run expressed as control evidence: what was tested, when, under whose authorization, and what the outcome was.
For your auditor and your supervisor
Trail
Safety audit trail
Every action an agent attempted, the decision taken on it, the reason, and a snapshot of the rules of engagement in force at that moment.
For anyone who asks what we did to your environment
Memory
Knowledge base
Configuration as found, how things connect, what was found before, what was fixed and what reopened. The next run starts from here, not from zero.
For the next run, and the board decision it feeds
Each report exists at three levels (the whole run, a single asset, a single finding), so the person who needs one line does not have to read the document written for someone else.
Where it plugs in
Radius connects to the environment you authorize, runs the loop, and delivers findings into your SIEM and ticketing flow with the validated chain behind each one. You supply the AI model key, or we do.
Ready to see it against your environment?
A 30-minute call, a scoped proposal with a draft of the rules of engagement and a fixed price. The run starts only after you sign.