ATTACKER
SURFACE · FIDDLE · OBSERVE · EXPLOIT
A black-box policy with network tools and no source access.
Offensive security research
Guarding machines against autonomous adversaries.
01 — Mission
Attackers already run on AI, and the models themselves are learning to slip their containment — probing, escalating, reaching into systems nobody authorised them to touch. Either way the adversary is a machine.
Securing cyberspace is a grand challenge because defence has always arrived late: the perimeter gets bypassed, the patch follows the breach. So we build our own attacker and point it at ourselves, alongside the detection and the containment, and let each one raise the standard for the others.
Cyber crime is where that starts, not where it ends. Financial crime is next, and the same loop holds wherever an adversary learns.
02 — The approach
Everything else in the lab exists because the attacker needed it: detection had to become measurable to score it, defence a distinct player to blame it, ranges generated because there were never enough real ones. Each turned out to stand on its own — the detector, the defender and the range generator are independent products, adopted one at a time by teams that never run the loop.
SURFACE · FIDDLE · OBSERVE · EXPLOIT
A black-box policy with network tools and no source access.
APPLICATION AND NETWORK TELEMETRY
Separates someone is attacking this from this is attackable.
CONTAIN · INVESTIGATE · REMEDIATE · REPORT
Acts on the Detector's inference. Never on the Attacker's report.
RANGE PROVIDER
Designs the flaw, and ships the exploit that proves it.
Each run feeds the next. What the Attacker gets past becomes the Detector's signal; what the Detector misses tells the Generator which situation to build; what the Defender patches is what the next Attacker has to beat. The loop runs on many situations at once, and each player gets harder as the others improve.
4 players · one loop
GENERATOR · LEVELS
Four players, one loop. Every pass leaves each of them better equipped than the last — more tools, sharper skills, memory of what already worked.
03 — Founder
NAVIN AGARWAL
FOUNDER
Built SIEM & SOAR and products that help governments defend against threats at national scale, built multiple iterations of Google SecOps and CyberShield.
The advantage isn't just technical ability. It is having built systems and teams from the ground up to unprecedented scale.
04 — The record
As of August 2026, updated in the same commit as the code it describes.
A COUNT WE HAVE NOT PUBLISHED IS MARKED AS SUCH, NOT ROUNDED UP.
05 — Join
A lean team building offence and defence together. If that is the work you want, write to us — a link to something you broke is worth more than a CV.