Solutions / Operators

One attack graph.
The whole team.

Five operators in one domain usually means five copies of the graph. The path someone found at 2am stays on their laptop until standup, and the readout gets rebuilt from memory. Neuron gives the team one graph per engagement and keeps the record as the work happens.

01 / The work

Kickoff to readout,
on one record.

An internal operation from start to finish, using features that ship in Neuron today.

Step by step
  1. Kickoff

    Scope it as a red team

    Create the engagement from the Red Team / Adversary Simulation template. Findings are rated by severity only by default and carry attack phase, detection status, objective achieved and target system, with Attack Narrative and Detection Guidance sections ready to fill.

  2. Plan

    Pick an emulation plan

    Attach an adversary emulation playbook such as APT29 or FIN6 from the starter library, or import your own. A separate Infrastructure playbook keeps the build-out checklist apart from the methodology.

  3. Day 2

    Foothold

    Move tooling through the shell you already have. Echo Up turns a file into a paste-ready Base64 command for Bash, CMD or PowerShell, so there is no staging server and no new outbound connection to explain. Log what you did as events on the host, with your name and the time attached.

  4. Day 3

    Collect

    Import SharpHound and AzureHound output into the engagement's own directory dataset. Hybrid AD and Entra ID data merges into one graph, and Tier Zero rules from the SpecterOps TierZeroTable mark what matters.

  5. Day 4

    Credentials

    Paste secretsdump, NTDS, shadow, Kerberoast or AS-REP output and Neuron detects the format. Each credential is linked to the host, port or person it came from.

  6. Week 2

    Path to Tier Zero

    Run every saved query against the dataset in one pass, then ask for the shortest paths to Domain Admins. Each path is rated by its weakest edge. Select the route you used and generate the finding from it, graph image included.

  7. Readout

    Hand the blue team the gaps

    Every finding records whether the activity went undetected, was detected without an alert, raised an alert, was blocked or was partly detected. The detection gaps are written down before the readout starts, and the report goes through the same review and approval as any other engagement.

Timings and names are examples.

02 / In depth

The parts that matter
to operators.

Edge provenance

Paths you can defend in the readout.

Every edge in the graph records where it came from. Collected edges come straight from SharpHound or AzureHound. Computed edges, such as DCSync, are derived from rights that were collected. Assumed edges cover defaults, like Domain Admins being local admin everywhere. Inferred edges come from GPO settings.

A path is rated Verified, High, Medium or Low by its weakest edge. Use Verified Only when you need to prove exploitability, and All Edges when you are scoping exposure.

An attack path with edge provenance A user is a member of a helpdesk group. A GPO setting suggests the group is local admin on a workstation, where a backup service account has a session, and that account can DCSync the domain. Two edges are collected, DCSync is computed and the admin right is inferred, so the whole path is rated Low. MemberOf collected Verified AdminTo inferred Low HasSession collected Verified DCSync computed High User J.SMITH@CORP.LOCAL Group HELPDESK@CORP.LOCAL Computer WS-0142.CORP.LOCAL User SVC_BACKUP@CORP.LOCAL Domain / Tier Zero CORP.LOCAL
Path confidence: Low A path is rated by its weakest edge. The admin right here was inferred from a GPO LocalAdmins setting, so Verified Only leaves this path out until someone proves it on the host.
Directory

One dataset per engagement.

Each engagement keeps its own directory dataset, so there is no shared graph database to clear between clients, and last month's domain is exactly where you left it.

  • A raw Cypher editor, saved queries, and the SpecterOps query library, which you import yourself and can refresh from upstream
  • Run All Queries against a dataset, with reviewed and to-do status, result counts, and pause and resume
  • K shortest paths (Yen's algorithm) for the alternatives when the first route is burned
  • Hierarchical, horizontal, snake and force layouts, and graph views shared by URL
  • Entra ID coverage up to the tenant root, including Application Administrator credential abuse paths
Findings

Written for both teams.

The Red Team template maps to MITRE ATT&CK and captures what defenders need from each technique: the attack phase, whether it was detected, and the objective it achieved, from initial access to domain compromise.

Assumed Breach, Social Engineering and Physical Security templates sit beside it, each with its own fields and finding ID prefix.

Prioritization

Tier Zero first.

Scan issues are ranked by how close the affected asset sits to Tier Zero in the graph, with badges for Tier Zero, domain controllers, admin tiers and attack-path distance. Every ranking explains itself.

Methodology

Emulation plans, not memory.

Starter playbooks include adversary emulation plans for FIN6, APT29, OilRig, Sandworm and Wizard Spider, alongside PTES and NIST SP 800-115. Coverage comes from the state of each step, and a step marked not applicable needs a reason.

Import your own plans as JSON or YAML.

03 / Recommended setup

What to deploy.
And where.

Setup
Deployment
On-premises or fully air-gapped. Offline Mode blocks outbound connections and flags the integrations that still need the network, such as SMTP and SSO. See how we handle data.
Modules
Neuron Core and Directory. Add Neuron AI for first drafts of findings and briefs on your own GPU or CPU. The Delivery Portal is optional.
Assessment templates
Red Team / Adversary Simulation, Assumed Breach, Social Engineering, Physical Security, Active Directory, and Identity & Access Management.
Imports
SharpHound and AzureHound, as JSON or ZIP, plus Nmap, Nessus and the other scanners listed on the platform page.
Server
Up to ten users: 2 vCPU, 8 GB of RAM and 50 GB of disk. Linux (Ubuntu 22.04 or later recommended), x64 or arm64, with PostgreSQL 14 or later.
04 / Boundaries

What Neuron
is not.

Out of scope

Not a C2

Neuron does not run implants or manage C2 channels. Keep your framework. Neuron is where the operation is recorded.

Not an infrastructure tracker

Redirectors, domains and servers are not tracked as records of their own. Infrastructure playbooks cover the build-out checklist.

Not a collector

Collection stays with SharpHound and AzureHound. Neuron imports the output, analyses it and ties it to the report.

05 / Questions

Asked by
red teams.

FAQ
Does Neuron replace BloodHound?

For analysis inside an engagement, it can. Neuron imports SharpHound and AzureHound collections into a BloodHound-compatible graph with its own Cypher engine. Collection still happens with SharpHound and AzureHound, and you import the SpecterOps query library, edge documentation and TierZeroTable from their public repositories.

Can several operators work the same graph?

Yes. The dataset belongs to the engagement, so everyone assigned to it works from the same graph, saved queries and results, and any graph view can be shared by URL.

Does it cover Entra ID?

Yes. AzureHound data imports on its own or merged with on-premises AD into a hybrid dataset, with Tier Zero coverage up to the tenant root.

Can we run it on an isolated range?

Yes. Neuron installs from transferred, signed packages and activates without contacting us. Offline Mode blocks outbound connections. The only file that ever leaves the server is a hardware fingerprint for licensing, with no customer data in it, and you carry it out yourself.

Does any engagement data reach PenTest.WS?

No. Neuron runs on infrastructure you control, and we never receive your findings, evidence or credentials.

Do we have to use the AI?

No. Neuron AI is a separate, optional module. When you use it, the models run on your hardware and no prompt is sent to a third-party provider.

Can we use our own report template?

Yes. Reports render from your Word template, and the same engagement data exports to PDF, Excel and Markdown.

Brief us on your next operation.

We will walk your operators through Neuron on a directory dataset, from import to readout, on a deployment like yours.