AI-native · Open source · SSVC-first

Stop doing
security manually.

Configure Horus once. Eight specialized AI agents then discover your attack surface, scan for vulnerabilities, correlate against CISA KEV + EPSS, simulate attacks, debate ambiguous findings, and alert your team every night, without you.

The 8-agent pipeline · runs on your schedule, every night
Recon
nmap nuclei
Analyst
enrich context
Threat Intel
CVE KEV EPSS
Red Team
attack sim
Blue Team
defense
Validation
judge verdict
Risk Mgr
SSVC priority
Reporter
exec summary
Built on the frameworks security teams already trust
MITRE ATT&CK CISA KEV FIRST EPSS SSVC OWASP NVD Nuclei
1,275%
Cyberattacks have increased 1,275% since AI went mainstream.
AI lets attackers generate unlimited phishing variants, credential lures and malware at near-zero cost. Social engineering campaigns that took weeks now run in minutes, targeting your employees, your infrastructure and your supply chain simultaneously. Manual security operations can no longer keep up.
Source: SlashNext State of Phishing 2023 · IBM X-Force Threat Intelligence Index 2024
Findings
Incidents
Posture
1 ACT 2 ATTEND
api.acmecorp.io · 12 findings
sorted by SSVC priority
HTTP/2 Rapid Reset · nginx 1.18.0
CVE-2023-44487⚡ KEVHIGH 7.5:443
SSVC: ACT EPSS 0.94
Remote Code Execution · Apache Log4j 2.14.1
CVE-2021-44228⚡ KEVCRIT 10.0:8080
SSVC: ATTEND EPSS 0.97
Buffer Overflow · OpenSSL 1.0.2 (internal)
CVE-2022-0778CRIT 9.8not exposed · no public exploit
SSVC: TRACK EPSS 0.03
9 more findings · 0 ACT, 0 ATTEND Show all →
338,000+ CVEs indexed and synced daily
SSVC priorities are deterministic, zero LLM tokens
Runs on-prem with your own model or fully cloud
MIT licensed · no vendor lock-in
The problem

Attackers use AI to scale.
Your defenses still rely on humans.

AI-generated phishing, automated credential attacks and AI-assisted malware are outpacing manual security operations. Meanwhile your scanner still outputs 400 "critical" findings a week, and your team still triages them by hand.

Without Horus
Attackers generate AI phishing campaigns in minutes. Your team reviews alerts manually over days
Triaging 400+ "critical" scanner findings every sprint, by hand, while new threats keep arriving
Finding out about KEV entries and active exploits days after they're published
Security coverage depends on who's on-call. Attackers operate 24/7 without shifts
With Horus
Pipeline runs overnight, inbox has 1–3 verified SSVC:Act items
Watchtower alerts the same day a CVE matching your stack enters CISA KEV
SSVC weighs exploitability, exposure and impact. Not just the score
Eight AI agents work every night without anyone needing to show up

How it works

Configure once.
Agents do the rest.

Define your assets, set a schedule, connect your integrations. Horus takes it from there. Every night, every week, indefinitely.

01 / SETUP

Add your infrastructure

Point Horus at domains, CIDR ranges, or individual hosts. Discovery agents map subdomains via CT logs and internal IPs via ping sweep, automatically, on schedule.

02 / PIPELINE

Eight agents run in sequence

Recon → Analyst → Threat Intel → Red/Blue debate → Validation → SSVC Risk Manager → Reporter. Each run produces a prioritized findings list and executive summary.

03 / SIGNAL

Only what matters reaches you

SSVC:Act findings trigger PagerDuty P1. Watchtower KEV matches alert the same day. SSVC:Track findings accumulate silently. You open your inbox to signal, not noise.


Red / Blue Team

AI agents that attack
and defend simultaneously.

Most scanners tell you what is vulnerable. Horus tells you whether an attacker can actually use it, with two adversarial AI agents arguing every ambiguous finding.

Red Team agent attacks

Generates a credible attack narrative per finding: exploit path, threat actor motive, blast radius. Context-aware, not boilerplate CVSS descriptions.

Blue Team agent defends

Argues the defensive side: compensating controls, network segmentation, non-exploitable conditions. Catches false positives before they waste a sprint.

Judge arbitrates, verdict persists

A third LLM call weighs both sides and calibrates a confidence score. The verdict is stored. Future scans inherit it without re-debating.

Full adversarial simulation cycles

Beyond individual findings: run Red Team cycles simulating DNS spoofing, certificate attacks, exposed paths, credential exposure: all against live infrastructure.

Red Team
Blue Team
CVE-2022-3602 · OpenSSL X.509 Overflow
admin.acmecorp.io · :443 · confidence 0.55
Red Team

Stack-based overflow in X.509 cert parsing. Attacker controls a cert in the TLS chain → code execution plausible. Internet-facing on port 443.

Blue Team

OpenSSL 3.0.7 patches this. Banner shows 3.0.7-1ubuntu1. WAF terminates TLS before OpenSSL processes it. NVD exploitability: none.

Judge verdict · confidence calibrated
Likely false positive · SSVC: TRACK
verdict stored · future scans inherit 4h triage saved

Phishing Simulation

Find out who clicks
before attackers do.

Horus runs AI-personalized phishing campaigns against your own team, using your real asset inventory to craft credible lures: IT impersonation, VPN resets, internal portal alerts.

Context-aware lures

PhishingAgent reads your asset inventory. If you run nginx and Jira, the email is about a Jira security update affecting your nginx version. Not a generic reset link.

Credential + MFA/OTP simulation

Full credential lure with fake MFA prompt. Captures who entered credentials, who just clicked, who reported it as suspicious. Three distinct risk tiers.

Instant awareness landing

Employees who click see an immediate security awareness screen. The teachable moment is in the same session, not in a training email three weeks later.

Repeat offender tracking

Click rate per employee and department over time. See who improved after training and who remains a persistent insider risk.

Q2 Awareness · IT Password Reset Complete
42 targets · sent 2026-06-10
42
Emails sent
34%
Click rate
18%
Credentials entered
JM
James M. · Engineering
Opened → clicked → entered credentials
high risk
SR
Sofia R. · Finance
Opened → clicked → closed page
clicked
KL
Kai L. · Security
Reported suspicious email immediately
reported

Watchtower

Your stack changes once.
Threats change every day.

Watchtower runs nightly after CISA publishes that day's KEV additions. If any entry matches something in your asset inventory, you get alerted. No re-scan needed.

Zero re-scan overhead

Inventory is persisted from past scans. Watchtower re-correlates it, not your network.

EPSS spike detection

When a CVE's exploit probability jumps 20+ points overnight, often before KEV. Watchtower catches it first.

Dark web IOC feeds

ThreatFox and URLhaus feeds checked against your domains daily. Ransomware victim lists cross-referenced against your industry.

watchtower · daily run · 06:30 UTC

cisa_kev sync complete · +4 new entries

epss_daily sync · 338k scores updated


→ cross-referencing 847 inventory entries


⚡ kev match: activemq/5.15.14

  CVE-2023-46604 · EPSS 0.97 · RCE

  asset: 10.0.1.15 (internal broker)


→ epss spike: spring-webmvc/5.3.27

  CVE-2023-20861 · 0.03 → 0.34 (+0.31)


→ SSVC: ACT · activemq finding

→ incident #43 opened · PagerDuty P1


run complete · 2 exposures · 0 false positives


Pricing

No lock-in.

All tiers run the same pipeline. You choose where your data lives.

Open
Free
self-hosted · MIT license
Full feature set. You run it, you own it. Bring your own LLM or use Ollama locally.
  • Unlimited assets & scans
  • Full 8-agent pipeline
  • SSVC + CVE correlation
  • Red/Blue Team + Phishing
  • Watchtower
  • Community support
Deploy on GitHub →
POPULAR
Cloud
$49
per org / month
Managed. We run it, keep it updated, and redact your infrastructure data before any LLM call.
  • Everything in Open
  • Managed infrastructure
  • Data redacted before LLM
  • Automatic updates
  • Email support
  • PagerDuty + OpsGenie
Start free trial →
Sovereign
Custom
on-prem · enterprise
Zero data leaving your perimeter. BYO LLM (Ollama, vLLM), SSO, dedicated SLA.
  • Everything in Cloud
  • On-prem deployment
  • BYO model (Ollama / vLLM)
  • SSO / SAML
  • Dedicated SLA
  • Private Slack channel
Talk to us →

Configure it once.
Your agents start tonight.

The demo is pre-loaded with 30 days of posture history, real CVE findings, Red/Blue debate transcripts, and phishing campaign results.