Proprietary assessment engine

Autonomous Active Directory assessments.

PrismVector is an early access prototype for authorized, autonomous Active Directory penetration testing. Early access includes assisted deployment, custom service level agreements, and a non-committal contract.

Early access only
Attack graph traversal Nodes representing hosts and identities connected by edges, with a highlighted path from an initial foothold through service accounts and certificate services to domain privilege. Foothold SMB relay Service account ADCS template Domain privilege Attack graph ยท relationships, not isolated findings
45+

Techniques in the current engineering corpus.

Corpus
250+

Finding definitions with evidence, attack context, and remediation guidance.

Findings
4 modes

Operator controlled execution methods, from non-intrusive to full exploit.

Execution

PrismVector is not publicly available and is not offered as a replacement for human penetration testers.

Current validation scope

Windows and Active Directory exposure.

Identity and directory

LDAP, users, groups, trusts, privileged ACLs, delegation, gMSA and LAPS access, password policy, stale objects, and directory relationships.

Kerberos and delegation

Kerberoasting and AS-REP exposure, constrained and unconstrained delegation, service relationships, and privilege paths.

Certificate services

Certificate service configurations, vulnerable templates, enrollment relationships, and attack path implications.

Windows and enterprise services

SMB, shares, sessions, domain controllers, MSSQL, SCCM, and related access relationships.

Credential and privilege exposure

Authorized validation of weak or exposed credentials, credential reuse, replication rights, and privilege conditions within the approved execution mode.

Retesting and change analysis

Run history, run comparison, drift, incremental workflows, resume behavior, remediation retesting, and risk trend outputs.

Controlled workflow

Eight steps, in order, every run.

The operator and customer define the objective, scope, authorization, and execution limits before PrismVector evaluates paths or performs approved actions.

Define scope

Networks, hosts, domains, exclusions, engagement objectives, and approved testing windows, so activity stays inside the authorization.

Discover infrastructure

Reachable systems and the services that matter: domain controllers, SMB, LDAP, Kerberos, WinRM, MSSQL, and certificate services.

Enumerate relationships

Users, groups, ACLs, delegation, trusts, certificate template exposure, credential artifacts, and weak configurations.

Build attack graph

Discovered facts organized to show how access to one account, host, or permission leads to another, and where privilege accumulates.

Identify paths

Realistic routes toward local administrator access, sensitive systems, Domain Admin, or customer defined crown jewels, ranked by confidence.

Validate exposures

Where permitted, controlled and reversible validation of whether a path is genuinely exploitable, with an audit trail of what was attempted and why.

Capture evidence

Each result tied to affected systems, evidence, attack context, and remediation guidance that explains what breaks the path.

Deliver and retest

Executive and technical readout, then a remediation retest that compares the environment against the prior run.

Outputs

Evidence designed for technical and business review.

Reproducible evidence and comparison, rather than a single unstructured list of tool output.

Business and reporting

  • Executive narrative
  • Technical narrative
  • Prioritized findings
  • Attack path summary
  • Remediation status
  • Risk trends

Technical evidence

  • Encrypted world snapshots
  • Hash chained events
  • Timelines and attack graphs
  • MITRE ATT&CK oriented mapping
  • Run history, comparison, and drift
  • Incremental, resume, and retest workflows

Customer controlled deployment

The engineering prototype is designed for self hosted operation with local evidence. Restricted or air gapped operating models can be evaluated subject to pilot design, environment validation, licensing, update, backup, recovery, and support procedures.

Written authorization and operator controls

PrismVector is used only against systems the customer owns or is expressly authorized to assess. Every evaluation defines scope, rules of engagement, operator roles, execution mode, stop procedure, notification path, evidence handling, and customer approval.

Paid design partner or assisted pilot stage

Early access.

A design partner evaluation includes installation assistance, a controlled baseline run, agreed validation objectives, operator support, a remediation retest, and an executive and technical readout.

Included

  • Defined pilot environment
  • Installation support
  • Written authorization and rules of engagement
  • Controlled run plan
  • Evidence review
  • Defect and feedback process
  • Remediation retest
  • Closing readout

Excluded unless separately approved

  • Production use
  • Unattended operation
  • Enterprise scale assurance
  • Customer wide rollout
  • Unsupported integrations
  • Broad MSP licensing
  • White label delivery

Prepare. Anticipate. Protect.

Evaluate PrismVector in a controlled Active Directory environment.

Praeven reviews the environment, authorization model, technical objectives, operational constraints, and design partner expectations before proposing an evaluation.