Test your defences
like an attacker.
Delivered as a VM deployed on your LAN — like the HoneyPot. Internal pentesting in continuous active discovery, every weakness verified by the AI. Seven modules: network, host, web, Active Directory, API, IoT/OT, cloud — driven remotely by your SOC.
An annual pentest was enough ten years ago. Today the estate changes daily: a new service, a new VLAN, a new firewall opening, a new CVE. Automated pentesting scans continuously from the inside, checks every finding with the AI (priority, exploitability, MITRE mapping, recommended actions) and reports to the SOC. Not a static checklist — an agent that learns and acts.
From threat to evidence, in real time.
The module captures the signal, SYLink AI correlates it and decides — you keep control.
The technology, in detail.
What the module actually does — functions, not promises.
Network discovery
- nmap top 1000 then full TCP
- 200+ services identified (banner + nuclei)
- Automatic mapping of RFC1918 subnets
- Static routes to scan remote VLANs
- Discovery / audit / full modes
Active Directory
- Kerberoast (service account TGS)
- AS-REP roasting (accounts without pre-auth)
- Controlled password spray (lockout policy respected)
- BloodHound collection (attack paths)
- ADCS misconfig + NTLM relay (SMB → LDAPS)
Web · API · IoT · Cloud
- Web: nuclei (13,000+ templates) + nikto
- API: REST / GraphQL fuzz, auth bypass, IDOR
- IoT/OT: CoAP, MQTT, Modbus, S7, IEC-104, BACnet
- Cloud: S3 misconfig, Azure SAS leak, GCP IAM
- TLS: Heartbleed, DROWN, ROBOT, weak ciphers
Verified by SYLink AI
- A structured JSON verdict for every finding
- is_exploitable + priority_score + confidence
- MITRE techniques (T1190 / T1059 / T1110…)
- Concrete actions (patch / isolate / IDS rule)
- False-positive probability — up to 80% less noise
CVE / KEV / Nuclei sync
- Daily CVE pack (1,500+ with CVSS ≥ 7 over five years)
- CISA KEV pack (1,562 actively exploited vulnerabilities)
- Nuclei pack (13,061 UniSOC-signed templates)
- Wordlists (top 1k/10k/100k plus AD-specific)
- IoC blocklist excluded from the scan
Security & licensing
- QR activation (HMAC-signed token)
- Services enabled per tenant (network / AD / web…)
- One month to three years, plus immediate revocation
- Emergency kill switch on the SOC side
- RFC1918 routes only (no hijacking of the default route)
What is it actually for?
Find a critical CVE within 24 hours
A critical CVE lands on Exchange: automated pentesting pulls the day's pack, finds the affected servers, has the AI check exploitability → a SOC ticket at 95% priority within two hours.
Continuous AD auditing
A quarterly AD audit? Too late. Automated pentesting runs kerberoast, AS-REP and a controlled spray every week and raises an alert the moment a new vulnerable account appears.
Multi-site scope through routing
Three sites linked by VPN: one VM plus two static routes are enough to scan Paris, Lyon and Marseille from a single point.
Validate before the audit
Ahead of the NIS2 audit, the CISO launches a full scan. An executive report with three priority actions — ready for the management committee.
Driven by SYLink AI, hosted 100% in France (HDS v2), with no Cloud Act exposure. Every decision is logged and defensible under NIS2 and DORA.
One building block of the SOC — never on its own.
Each module feeds the others through SYLink AI.
Ready to see what is really
happening on your network?
First trial free, no credit card, no commitment. On your existing infrastructure.
