Black Hat USA Aug 4-6, Mandalay Bay. Book time with us
Solutions · Pen Testing

Validate findings without re-fighting the investigation.

So what does Soarcery do for pen testing? Feed a finding into the same investigation loop that works every real alert, and get a replayable record of what your response would actually have caught.

The problem

A report proves a path in. It rarely proves what your SOC would have caught.

A pentest confirms an exploit worked. It does not usually show whether your detection and response would have found it, worked it correctly, and stopped it in time, so remediation debates happen without evidence either way.

A path in is not the whole story

The report proves the exploit worked. It says nothing about whether your detection and response would have caught it.

Remediation debates run on opinion

Without a record of what the response would have done, prioritization gets argued from instinct rather than evidence.

Findings age fast

By the time the retest happens, the environment has moved. The finding needed validating the week it landed.

How Soarcery does it

Run the finding through the same loop as a real alert.

1

It investigates the finding like a real alert

Give the Familiar the entity or technique involved and it pulls the same context an analyst would: identity, endpoint, email, and cloud signals.

2

It shows the plan before it acts

The Familiar lays out what it would investigate, correlated against MITRE ATT&CK, so you can compare its plan against what the test actually did.

3

It hands you a receipt, not a guess

The output is a replayable record: what was detected, what was recommended, and exactly where the Seal would have stopped it, evidence attached.

4

The gaps become the fix list

Where the investigation would have missed, or the response would never have reached the Seal, you have a specific evidenced gap to close instead of a general worry.

In the product

Where the response would have stopped, and why.

The Soarcery Seal queue: a containment action the Familiar planned, paused for an explicit human approval before it runsThe Soarcery Seal queue: a containment action the Familiar planned, paused for an explicit human approval before it runs

Actual product. Demo data.

The gate

Every privileged action pauses for a human, marked with its blast radius. Running a finding through the loop shows you exactly which response would have been proposed, and precisely where it would have waited for a person.

The record

The deliverable is a receipt: what was checked, what was decided, who approved it, and when. That is a defensible artifact for the retest conversation, rather than two teams recalling the same week differently.

A Soarcery receipt: an approved response action on the record, with the case it came from and who approved it, demo dataA Soarcery receipt: an approved response action on the record, with the case it came from and who approved it, demo data

Actual product. Demo data.

Where this is different

Validation with a paper trail.

  • The finding runs through the same loop as a real alert, with no special casing.
  • The plan is visible and correlated against MITRE ATT&CK, so you can compare it to what the test actually did.
  • The Seal shows exactly where a consequential response would have stopped for a human.
  • The output is a receipt, not a guess: replayable evidence of what your response would have caught.
Close the loop

Run your last finding through it.

A 30-minute walkthrough. Bring a recent finding and see what the response would have looked like.