Test your attack surface against real attacker techniques
Attackers start with reconnaissance and initial access. Hadrian runs the same kind of discovery and exploitation against your internet-facing assets, so your team sees which techniques would work today.
Internal defenses could not stop an ongoing data leak. Hadrian's outside-in view found the single exposed asset, and the exfiltration stopped once it was patched.
MITRE ATT&CK techniques Hadrian addresses
MITRE ATT&CK is a free, public knowledge base of adversary tactics and techniques built from real-world observations. It is not a regulation and has no certification. Security teams use it as a shared language for threats and to check which techniques their controls detect, prevent or test.
Scanning and open-source reconnaissance
Attackers scan your IP ranges and search public sources such as DNS, certificate logs and websites to find targets and learn what software you run.
Hadrian's discovery uses the same kinds of sources: passive scans of the IPv4 space, DNS changes, WHOIS records and certificate transparency logs. Scans typically run every hour or when an event triggers them.
An inventory of what an attacker can find about you, with the technologies and services on each asset.
Exploiting internet-facing applications
Attackers exploit a software bug, glitch or misconfiguration in an internet-facing system to get into your network.
Atlas runs tests that match the technologies it finds and confirms exploitability before alerting. Nova runs pentests of web apps and APIs on demand.
Validated findings with step-by-step reproduction details and retest status for each public-facing application.
Exposed remote access
Attackers use internet-facing remote access, such as VPNs and Citrix gateways, to get in or stay in, often with stolen credentials.
Atlas inventories the services each internet-facing asset exposes, so remote access gateways you did not know about show up, and raises the exposures on them that it can validate.
A list of internet-facing services by asset, with any validated exposures and their remediation status.
Stolen and leaked credentials
Attackers log in with stolen credentials for VPNs, webmail and other external services, which lets them get past access controls.
Hadrian's infostealer detection, an Atlas add-on, shows compromised credentials and stolen session cookies tied to your domains, with the infected device and malware type.
Records of leaked credentials found for your domains and when each was remediated.
Subdomain takeover
Attackers take over subdomains whose DNS records point to resources you no longer control, then use the trust in your domain for phishing or malware.
Hadrian's DNS monitoring finds unclaimed or poorly managed subdomains that could be taken over, and keeps scanning as your DNS changes.
A list of subdomain takeover risks and when each was resolved.
Hadrian maps its external testing to these ATT&CK techniques for reference. ATT&CK has no certification, and Hadrian does not claim coverage of every technique.
Reconnaissance the way an attacker runs it
Hadrian starts where attackers start: the internet. It runs passive scans across the IPv4 space, tracks DNS changes, WHOIS records and certificate transparency logs, and uses AI agents to predict forgotten subdomains. You see the same target list an attacker would build.
Initial access, tested and validated
Atlas chains and exploits vulnerabilities on public-facing applications the way a skilled attacker would, and only alerts on exposures it has validated. Nova goes deeper on the web apps and APIs you choose, covering the OWASP Top 10 from the outside.
Leaked credentials and hijackable subdomains
Stolen logins and abandoned subdomains give attackers an easy way in. Hadrian monitors the dark web for infostealer data tied to your organization and finds unclaimed or poorly managed subdomains that could be taken over.
More from customers
Damen Shipyards Group
After a forgotten marketing webpage was exploited for SEO poisoning, Damen mapped its full attack surface with Hadrian, including forgotten assets and shadow IT.
Breeze Airways
Breeze gets findings confirmed as exploitable before they reach the team, including in APIs and Content Security Policy configurations.
Hadrian tests from the outside, so it focuses on what an attacker does before and during initial access. That includes reconnaissance such as Active Scanning (T1595) and initial access such as Exploit Public-Facing Application (T1190), External Remote Services (T1133) and Valid Accounts (T1078). The Hadrian MITRE ATT&CK overview shows the full mapping.
Hadrian's agents attempt exploitation in a controlled way to confirm that a finding is exploitable. They only run tests that match the technologies found on an asset, so WordPress tests do not run against SAP systems. Every validated finding comes with step-by-step reproduction details your team can check.
Hadrian shows which external techniques would work against you today. Your SOC can use that to check detections for the same techniques and to prioritize fixes. Findings can go to Jira, ServiceNow, Slack, Microsoft Teams and Datadog, and Hadrian's API connects to other tools.
No. ATT&CK is a knowledge base of real-world adversary behavior maintained by MITRE. There is nothing to certify against. Teams use it to describe threats, plan testing and spot gaps in coverage.
See which attacker techniques would work against you today
Book a demo to watch Hadrian run reconnaissance and validation against your internet-facing assets, and see what your team gets back.