Quantum Ventura Request a demo
Authorised penetration testing

CNRT Vanguard

You cannot defend against an attack path nobody has walked. Vanguard walks them, against systems you own and have authorised in writing, and hands back what it found and how it got there.

IsolatedOne machine per campaign
AuthorisedWritten consent before any run
ExpandingAttack coverage grows with the field
CNRT Vanguard · Engagement 214
AUTHORISED
Target3 hostsIn signed scope
Paths found0Not yet run
EnvironmentReadyDisposable machine
Attack path Awaiting run
ReconIdle
Initial accessIdle
EscalationIdle
ReportIdle
Event stream
ScopeEngagement 214 countersignedVERIFIED
EnvDisposable machine provisionedREADY
Authorised, idle
1
vpn-gw.customer.example REACHABLE

Credential reuse from a service account gave a foothold on the gateway. Reproduction steps and evidence captured.

2
app-01.customer.example PARTIAL

Escalation attempted from the foothold. Host policy held, so the path stops here.

Every finding carries the path that produced it, so your team can reproduce it rather than take it on trust.
Authorised byHead of Information Security
Window14 days from countersignature
ReferenceENG-214-A
Systems named in the authorisation
app-01.customer.example IN SCOPE
vpn-gw.customer.example IN SCOPE
everything else OUT OF SCOPE
No signed scope, no campaign. The button on the first tab does not exist without this.
Authorisation

It will not run without your written authorisation

No signed scope, no campaign.

Before a campaign starts, the customer has to supply a signed authorisation naming the systems in scope. No token, no run. That gate exists because testing a system you do not own is not a grey area, and because a security vendor that treats consent as optional is not one you should let near your network.

CNRT Vanguard · Engagement 214
CampaignFindingsScope
SIGNED
Authorised byHead of Information Security
OrganisationCustomer, named on the form
Window14 days from countersignature
ReferenceENG-214-A
Systems named in the authorisation
app-01.customer.exampleIN SCOPE
api-02.customer.exampleIN SCOPE
vpn-gw.customer.exampleIN SCOPE
everything else OUT OF SCOPE
Nothing outside this list is touched. Without a signed engagement there is no campaign to run.
Isolation

Every campaign runs in its own disposable machine

One machine per engagement, destroyed after.

Each engagement spins up a fresh, isolated virtual machine, does its work inside that boundary, and is torn down afterwards. Nothing from one campaign can reach another, and nothing persists between them. Concurrency is capped deliberately rather than stretched, and work beyond the cap queues.

CNRT Vanguard · Environments
CampaignEnvironmentsScope
2 OF 2 IN USE
CAMPAIGN 214 RUNNING
Isolated image · own network · no shared volume
Provisioned 00:04 ago
CAMPAIGN 213 RUNNING
Isolated image · own network · no shared volume
Provisioned 00:31 ago
CAMPAIGN 215 QUEUED
Isolated image · own network · no shared volume
Waiting for capacity
One machine per campaign, destroyed on completion. Capacity is capped on purpose, so work beyond it queues rather than sharing an environment.
Coverage

The attack library tracks the field, not a release cycle

Techniques tracked from a public catalogue.

Vanguard draws its techniques from a public, actively maintained catalogue of adversarial methods rather than a list frozen at ship time, so coverage moves as the field does. Defensive modules are being added alongside the offensive ones so the same engine can report what would have stopped each path.

CNRT Vanguard · Technique library
CampaignLibraryScope
TRACKING
Reconnaissance
IN PLACE
Initial access
IN PLACE
Credential access
IN PLACE
Lateral movement
IN PLACE
Defence evasion
IN PLACE
Defensive checks
BEING ADDED
Techniques come from a public catalogue that is actively maintained, so coverage moves with the field instead of with our release cycle.
Where it came from

Built at Quantum Ventura.

Built at Quantum Ventura and sold on its own. It runs only against targets the customer has authorised in writing, and access is restricted to provisioned accounts.

PositionStandalone product, deliberately separate from the CNRT dashboard
AuthorisationWritten pre-engagement consent required before any campaign
IsolationOne disposable virtual machine per campaign
AccessProvisioned accounts only, no self-service sign-up
InterfaceMultilingual, English and Japanese in place today

Tell us the program
and the problem.

We reply from San Jose, usually within two working days.

Request a Demo