MITRE ATT&CK

Test your attack surface against real attacker techniques

Attackers start with reconnaissance and initial access. Hadrian runs the same kind of discovery and exploitation against your internet-facing assets, so your team sees which techniques would work today.

Customer story

Internal defenses could not stop an ongoing data leak. Hadrian's outside-in view found the single exposed asset, and the exfiltration stopped once it was patched.

Aroma360
Read the story →
Requirements

MITRE ATT&CK techniques Hadrian addresses

MITRE ATT&CK is a free, public knowledge base of adversary tactics and techniques built from real-world observations. It is not a regulation and has no certification. Security teams use it as a shared language for threats and to check which techniques their controls detect, prevent or test.

0
1
TA0043 Reconnaissance: T1595 Active Scanning, T1593 Search Open Websites/Domains, T1596 Search Open Technical Databases

Scanning and open-source reconnaissance

Attackers scan your IP ranges and search public sources such as DNS, certificate logs and websites to find targets and learn what software you run.

How Hadrian helps

Hadrian's discovery uses the same kinds of sources: passive scans of the IPv4 space, DNS changes, WHOIS records and certificate transparency logs. Scans typically run every hour or when an event triggers them.

Evidence you can show

An inventory of what an attacker can find about you, with the technologies and services on each asset.

0
2
T1190 Exploit Public-Facing Application (TA0001 Initial Access)

Exploiting internet-facing applications

Attackers exploit a software bug, glitch or misconfiguration in an internet-facing system to get into your network.

How Hadrian helps

Atlas runs tests that match the technologies it finds and confirms exploitability before alerting. Nova runs pentests of web apps and APIs on demand.

Evidence you can show

Validated findings with step-by-step reproduction details and retest status for each public-facing application.

0
3
T1133 External Remote Services (TA0001 Initial Access)

Exposed remote access

Attackers use internet-facing remote access, such as VPNs and Citrix gateways, to get in or stay in, often with stolen credentials.

How Hadrian helps

Atlas inventories the services each internet-facing asset exposes, so remote access gateways you did not know about show up, and raises the exposures on them that it can validate.

Evidence you can show

A list of internet-facing services by asset, with any validated exposures and their remediation status.

0
4
T1078 Valid Accounts (TA0001 Initial Access)

Stolen and leaked credentials

Attackers log in with stolen credentials for VPNs, webmail and other external services, which lets them get past access controls.

How Hadrian helps

Hadrian's infostealer detection, an Atlas add-on, shows compromised credentials and stolen session cookies tied to your domains, with the infected device and malware type.

Evidence you can show

Records of leaked credentials found for your domains and when each was remediated.

0
5
T1584.001 Compromise Infrastructure: Domains (TA0042 Resource Development)

Subdomain takeover

Attackers take over subdomains whose DNS records point to resources you no longer control, then use the trust in your domain for phishing or malware.

How Hadrian helps

Hadrian's DNS monitoring finds unclaimed or poorly managed subdomains that could be taken over, and keeps scanning as your DNS changes.

Evidence you can show

A list of subdomain takeover risks and when each was resolved.

Hadrian maps its external testing to these ATT&CK techniques for reference. ATT&CK has no certification, and Hadrian does not claim coverage of every technique.

How Hadrian helps

Reconnaissance the way an attacker runs it

Hadrian starts where attackers start: the internet. It runs passive scans across the IPv4 space, tracks DNS changes, WHOIS records and certificate transparency logs, and uses AI agents to predict forgotten subdomains. You see the same target list an attacker would build.

See attack surface management
01

Initial access, tested and validated

Atlas chains and exploits vulnerabilities on public-facing applications the way a skilled attacker would, and only alerts on exposures it has validated. Nova goes deeper on the web apps and APIs you choose, covering the OWASP Top 10 from the outside.

See adversarial exposure validation
02

Leaked credentials and hijackable subdomains

Stolen logins and abandoned subdomains give attackers an easy way in. Hadrian monitors the dark web for infostealer data tied to your organization and finds unclaimed or poorly managed subdomains that could be taken over.

See infostealer detection
03
Case studies

More from customers

All case studies
Case study

Damen Shipyards Group

After a forgotten marketing webpage was exploited for SEO poisoning, Damen mapped its full attack surface with Hadrian, including forgotten assets and shadow IT.

Read the story →
Case study

Breeze Airways

Breeze gets findings confirmed as exploitable before they reach the team, including in APIs and Content Security Policy configurations.

Read the story →
FAQ

Frequently asked questions

Which ATT&CK techniques does Hadrian focus on?
+

Hadrian tests from the outside, so it focuses on what an attacker does before and during initial access. That includes reconnaissance such as Active Scanning (T1595) and initial access such as Exploit Public-Facing Application (T1190), External Remote Services (T1133) and Valid Accounts (T1078). The Hadrian MITRE ATT&CK overview shows the full mapping.

Does Hadrian run real exploits or only simulate them?
+

Hadrian's agents attempt exploitation in a controlled way to confirm that a finding is exploitable. They only run tests that match the technologies found on an asset, so WordPress tests do not run against SAP systems. Every validated finding comes with step-by-step reproduction details your team can check.

How does this help our SOC?
+

Hadrian shows which external techniques would work against you today. Your SOC can use that to check detections for the same techniques and to prioritize fixes. Findings can go to Jira, ServiceNow, Slack, Microsoft Teams and Datadog, and Hadrian's API connects to other tools.

Is MITRE ATT&CK a compliance framework?
+

No. ATT&CK is a knowledge base of real-world adversary behavior maintained by MITRE. There is nothing to certify against. Teams use it to describe threats, plan testing and spot gaps in coverage.

Get a 15 minute demo

See which attacker techniques would work against you today

Book a demo to watch Hadrian run reconnaissance and validation against your internet-facing assets, and see what your team gets back.