Local AI
Keep AI-assisted analysis inside your environment with a self-hosted model. Support restricted and offline assessments without sending advisor requests to an external provider.
Autonomous exposure validation
PrismVector validates attack paths and helps prioritize the fixes that interrupt them. Review concrete evidence with optional analysis from Praeven Intelligence, using a local model or your own AI provider.
Illustrative attack path
Establish what an authorized attacker can achieve, with evidence behind each validated path.
A consistent, explainable planning engine operates within your assessment scope and rules of engagement.
Run on-premises and assess offline to keep assessment data and credential evidence in your environment.
Praeven Intelligence
Praeven Intelligence adds optional AI-assisted analysis to PrismVector’s assessment evidence. Interpret attack paths, examine how findings connect, and explore remediation priorities with a local model or your own AI provider.
Keep AI-assisted analysis inside your environment with a self-hosted model. Support restricted and offline assessments without sending advisor requests to an external provider.
Connect your preferred provider through a supported API using your own API key. Advisor requests are sent to the external provider you configure.
Discover and validate attack paths using the deterministic engine alone. An AI model is optional and is not required to execute an assessment.
The deterministic planning engine controls assessment execution. Praeven Intelligence assists with analysis; it cannot override scope or safety policies.
Exposure-driven remediation
Individual weaknesses can combine into access to critical systems. PrismVector connects those findings and highlights shared controls and choke points, helping your team focus on changes that address multiple routes to compromise.
Trace how credentials, permissions, and trust relationships lead toward domain compromise and other critical assets.
Use validated paths and affected assets to decide which controls to strengthen and which exposures to address first.
Use targeted validation to check whether a previously working path is closed, then compare assessments to identify changes in exposure.
Continuous threat exposure management
PrismVector supports continuous threat exposure management (CTEM) for Active Directory environments. Scheduled reassessments, drift analysis, and targeted validation connect discovery to remediation and follow-up.
Identify hosts, identities, credentials, permissions, trust relationships, and misconfigurations within the authorized scope.
Construct an attack graph that connects exposures to potential routes toward critical assets.
Follow authorized attack paths with a deterministic planner that updates its next action based on assessment results.
Identify remediation opportunities using validated access, business impact, and controls shared across paths.
Validate fixes, compare runs, and detect changes that introduce or reopen paths to critical assets.
Assessment controls
Set the assessment scope and rules of engagement before execution. PrismVector records active changes, attempts to restore affected systems, and verifies cleanup so your team can review what happened throughout the run.
Explicit targets, protected account exclusions, lockout-aware credential testing, and approval gates constrain active validation.
Active techniques prioritize reversible changes. Change records, restoration attempts, and cleanup verification make follow-up work visible.
Mission Control shows assessment progress and validated access. Operators can launch, pause, resume, or abort a run and review its evidence and audit trail.
Product view · lab benchmark
A run against Game of Active Directory, the open benchmark forest, reaching Domain Admin in about fifteen minutes with evidence preserved at each step.

Current validation scope
LDAP, users, groups, privileged ACLs, delegation, gMSA and LAPS access, parent-child domains, forest trusts, SID filtering, selective authentication, and cross-domain privilege relationships.
Kerberoasting and AS-REP exposure, constrained and unconstrained delegation, service relationships, and privilege paths.
Certificate service configurations, vulnerable templates, enrollment relationships, and attack path implications.
SMB, shares, sessions, domain controllers, MSSQL, SCCM, and related access relationships.
Weak or exposed credentials, credential reuse, replication rights, and privilege conditions that expand a validated attack path.
Run history, run comparison, drift detection, incremental workflows, resume behavior, and risk trend outputs.
Evidence and reporting
Review the evidence behind validated access and export technical and executive reports. Give security teams the detail to investigate findings and leadership the context to set priorities.
Each validated path can include:
Use reporting to explain the findings and track follow-through:
Assessment data and credential evidence can remain on-premises. Offline operation is supported by the deterministic engine and a local advisor; using an external AI provider sends advisor requests outside your environment.
Early access
A private evaluation covers a defined environment, installation support, a controlled baseline run, evidence review, and an executive and technical readout.
Prepare. Anticipate. Protect.