AttackIQ

AttackIQ

Co-managed security testing and validation services

Overview

AttackIQ provides cybersecurity testing services for organizations to validate and improve security controls. It offers three delivery models: a co-managed service for mature security teams, a fully managed breach-and-attack simulation service for SMBs, and an agentless test-as-a-service for on-demand checks. The platform runs simulated real-world attacks, collects results, and guides remediation to help clients invest wisely, detect advanced threats, and demonstrate control effectiveness to leadership, insurers, and regulators. By blending co-managed and fully managed options along with an on-demand agentless option, it differentiates itself from competitors that offer only one mode of testing.

About AttackIQ

Simplify's Rating
Why AttackIQ is rated
B+
Rated B on Competitive Edge
Rated A on Growth Potential
Rated B on Differentiation

Industries

Enterprise Software

Cybersecurity

Company Size

51-200

Company Stage

Series C

Total Funding

$80.9M

Headquarters

Los Altos, California

Founded

2013

Get referred to AttackIQ

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • DISA deployment spans all Military Services, Combatant Commands, and Defense Agencies.
  • AVA and Watchtower target AI-driven cyber operations, expanding wallet share beyond BAS.
  • Acumen Cyber partnered with AttackIQ on May 29, 2026, showing channel momentum.

What critics are saying

  • Wiz Exposure Management and ASM now overlap AttackIQ's validation and prioritization story.
  • G2 lists Cymulate, Picus, SafeBreach, and Pentera as direct alternatives.
  • If DISA standardization stalls, AttackIQ loses its strongest enterprise reference customer.

What makes AttackIQ unique

  • AttackIQ won DISA's August 4, 2026 Department-wide AEV platform mandate.
  • AVA Agentic OS on July 30, 2026 adds autonomous CTEM workflows across teams.
  • MITRE CTID roots and ATT&CK alignment keep AttackIQ credible with defenders.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$80.9M

Below

Industry Average

Funded Over

5 Rounds

Notable Investors:
Series C funding is usually for startups that are doing well and are looking for more money to fuel major growth, such as acquiring other companies, expanding into global markets, or launching new product lines. Investors typically include larger venture capital firms and private equity.
Series C Funding Comparison
Below Average

Industry standards

$50M
$44M
AttackIQ
$50M
Medium
$62M
SeatGeek
$100M
Oura

Benefits

100% remote

Competitive total rewards package

Flexible paid time off (PTO) and sick days

Paid holidays per region

Mental health and wellness days

Company News

Intelligence Community News
Aug 5th, 2026
DISA chooses AttackIQ as DoW's AEV platform.

DISA chooses AttackIQ as DoW's AEV platform. 0 Comments On August 4, AttackIQ, a provider of threat-informed Continuous Threat Exposure Management (CTEM), announced that after a lengthy analysis of alternatives, the Defense Information Systems Agency (DISA) has selected AttackIQ as the enterprise platform for Adversarial Exposure Validation (AEV) across the Department of War (DoW). The deployment establishes a common operational capability that enables all DoW components to continuously validate the effectiveness of its cyber defenses against real-world adversary behavior while providing Department leadership with enterprise-wide visibility into cyber readiness. The deployment will be implemented by DISA and will be supported across the DoDIN, creating the Department's first enterprise-wide capability for continuously measuring defensive effectiveness through evidence-based adversary emulation. Rather than relying solely on vulnerability data or periodic assessments, AttackIQ enables organizations to continuously prove whether security controls, detections, and defensive processes will perform against the adversary techniques most likely to target their mission. As part of the deployment, the Department will also leverage AttackIQ AVA Agentic OS, the industry's first agentic operating system purpose-built for cybersecurity missions, together with Watchtower, AttackIQ's Hyper-Localized AI Cyber Threat Intelligence Analyzer. These AI-powered capabilities support the Department's broader strategy to modernize cyber operations by accelerating the operational use of artificial intelligence to automate cyber analysis, prioritize mission-relevant threats, and continuously optimize defensive operations. Beyond establishing the Department's enterprise platform for Adversarial Exposure Validation, the deployment includes AVA Agentic OS and Watchtower to automate complex cyber missions through teams of specialized AI agents. Together, these capabilities continuously analyze mission-specific threat intelligence, identify the adversary techniques most relevant to each Defense Agency, orchestrate autonomous validation missions, optimize defensive controls, and provide Department leadership with a real-time understanding of the effectiveness and readiness of cyber defensive operations across the global enterprise. "The future of cyber defense is not measured by how many vulnerabilities are discovered - it is measured by how effectively organizations can validate and optimize their ability to defeat real adversaries," said Carl Wright, chief commercial officer of AttackIQ. "By standardizing on AttackIQ as its enterprise Adversarial Exposure Validation platform, the Department of War is establishing a common operational framework for continuously measuring cyber readiness while leveraging AI to automate analysis, prioritize operational risk, and optimize defensive operations at enterprise scale." IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

Digital IT News
Jul 30th, 2026
AttackIQ Launches AVA Agentic OS.

AttackIQ Launches AVA Agentic OS. AttackIQ has introduced AVA Agentic OS, an agentic operating system built to help organizations operationalize Continuous Threat Exposure Management (CTEM) by automating and streamlining exposure assessment and security validation. CTEM has emerged as the strategic framework for managing cyber risk, yet many organizations continue to struggle to operationalize CTEM across fragmented security technologies, disconnected workflows, and manual processes. Security teams have invested heavily in tools that identify risk, but they lack an intelligent operational layer that continuously transforms intelligence into action. AVA Agentic OS fills that gap. With AVA OS, AttackIQ is redefining how organizations operationalize Continuous Threat Exposure Management (CTEM). Rather than automating individual tasks, AVA OS orchestrates teams of specialized AI agents into autonomous cybersecurity missions that continuously discover, validate, and reduce threat debt - helping organizations focus resources on the exposures that matter most. By coordinating cyber threat intelligence, security validation, detection engineering, control optimization, threat debt reduction, and AI security validation into unified operational workflows, AVA OS transforms CTEM from a strategic framework into a continuously executing operational capability. CTEM Runs on AVA OS. "Organizations don't have a CTEM strategy problem - they have a CTEM execution problem," said Carl Wright, Chief Commercial Officer at AttackIQ. "AVA OS is the operational layer that makes Continuous Threat Exposure Management executable. It coordinates specialized AI agents that continuously perform the work required to discover, validate, and reduce threat debt. The next generation of cybersecurity operations will be built on specialized, mission focused agentic systems." Operationalizing CTEM. AVA OS provides the orchestration layer that enables organizations to continuously execute CTEM across the enterprise. AVA OS can be invoked through the AttackIQ Platform, AI developer environments such as ChatGPT, Claude, Cursor, and Microsoft Copilot, or directly from AI-native applications and partner solutions. Regardless of where work begins, AVA coordinates specialized AI agents that execute complete cybersecurity missions from start to finish. Rather than requiring security teams to manually coordinate threat intelligence, validation, detection engineering, control optimization, and remediation across disconnected technologies, AVA orchestrates these activities into autonomous operational missions. Those missions include: * CTI-Driven Validation Transforms cyber threat intelligence into validated defensive readiness by researching adversaries, mapping MITRE ATT&CK(R) techniques, generating attack scenarios, executing validations, measuring defensive effectiveness, and prioritizing Threat Debt reduction. * Detection Coverage Analysis Continuously discovers gaps in detection coverage, identifies blind spots, generates and validates new detections, and measures detection improvements across the enterprise. * Control & Defense Optimization Evaluates security controls against real-world attack techniques, identifies ineffective defenses, prioritizes improvements, validates security controls, and measures defensive effectiveness. * Threat Debt Reduction Exposes true adversary opportunity as attack paths, identifies where existing controls already defeat them, and prioritizes the work that measurably reduces threat debt. * AI Security Validation Enables organizations to confidently deploy AI by continuously discovering unknown AI risks, validating AI guardrails, simulating adversarial attacks, and measuring the security posture of AI applications and autonomous agents. Together, these autonomous missions transform CTEM from a periodic assessment into a continuously executing operational capability that produces measurable reductions in cyber risk. Open by design. AVA OS is built on an open, extensible architecture designed to integrate with the technologies organizations already use. Whether initiated from the AttackIQ Platform, AI developer environments, partner solutions, AI-native applications, or future enterprise AI ecosystems, every mission is orchestrated through the same operational layer. Organizations can embed autonomous CTEM into existing workflows without replacing current security investments, allowing security teams, developers, partners, and enterprise applications to leverage the same orchestration engine regardless of where work begins. From security activities to security outcomes. Today's security leaders are measured by outcomes, not activity. Success is no longer defined by the number of vulnerabilities patched or alerts investigated, but by the ability to continuously demonstrate measurable reductions in threat debt. AVA OS enables organizations to answer the questions that matter most: * Are Digital IT News resilient against today's adversaries? * Where are its detection gaps? * Which security controls are measurably reducing risk? * Which remediation activities will have the greatest impact? * Can Digital IT News confidently deploy AI across the enterprise? By continuously executing operational missions, AVA transforms CTEM from a strategic framework into a continuously operating capability that delivers measurable, evidence-based cyber resilience. "AI-driven attacks are increasing in speed and scale, creating incidents that are harder to predict, faster to unfold and more complex to manage," said Chris Foster, US Cyber Resilience and Defense Lead at Accenture. "To stay ahead, Accenture and AttackIQ are helping clients operationalize CTEM with intelligent orchestration and evidence-based security operations, giving teams a continuous way to reduce exposure and accelerate the shift to autonomous cyber operations." Forward Deployed Engineering. To help organizations move quickly, AttackIQ is also introducing Forward Deployed Engineering. AttackIQ Forward Deployed Engineers embed with customer teams to identify and address mission challenges, rapidly integrating AVA Agentic OS into their security operations and leaving enduring capability the customer's team runs. See AVA Agentic OS in action. AttackIQ will debut AVA Agentic OS at Black Hat USA. Visit AttackIQ Booth #1957 for live demonstrations of autonomous missions and learn how AVA Agentic OS operationalizes Continuous Threat Exposure Management.

Associated Press
Jul 30th, 2026
AttackIQ launches AVA Agentic OS to automate continuous threat exposure management

AttackIQ, a cybersecurity firm specialising in threat-informed Continuous Threat Exposure Management (CTEM), has launched AVA Agentic OS. The system is designed to help organisations operationalise CTEM by coordinating specialised AI agents to continuously discover, validate, and reduce threat exposure. AVA OS orchestrates AI agents across cyber threat intelligence, security validation, detection engineering, and control optimisation into unified operational workflows. The platform can be accessed through the AttackIQ Platform, AI developer environments like ChatGPT and Claude, or partner solutions. The company is also introducing Forward Deployed Engineering, where AttackIQ engineers embed with customer teams to integrate AVA into their security operations. AttackIQ will demonstrate the system at Black Hat USA.

M&S Channel
May 29th, 2026
Engineering-led security and continuous threat exposure management.

Engineering-led security and continuous threat exposure management. Acumen Cyber and AttackIQ announce a strategic partnership focused on continuous threat exposure management and organisational cyber defence. * Friday, 29th May 2026 Posted 10 hours ago in by Sophie Milburn Acumen Cyber, a cyber security service provider, has announced a strategic partnership with AttackIQ, a provider of adversary-informed Continuous Threat Exposure Management (CTEM). The collaboration aims to improve how organisations identify, validate, and disrupt potential attack paths that adversaries may use across enterprise environments. The increasing use of AI has contributed to faster exploitation of security exposures, with threat actors able to operationalise vulnerabilities more quickly than many organisations can respond. As a result, traditional approaches that rely primarily on vulnerability counts, severity ratings, and periodic assessments are increasingly viewed as insufficient. Current cyber defence practices place greater emphasis on continuously understanding which exposures are most significant, how they could be used to access critical assets, and whether existing security controls are effective against those threats. This partnership combines Acumen Cyber's engineering-led security operations capabilities with AttackIQ's CTEM platform, enabling organisations to carry out continuous validation and threat-informed defence. The approach supports ongoing assessment of defensive controls, identification of significant attack paths, and evaluation of whether exploitable opportunities are being reduced over time. By integrating AttackIQ's CTEM capabilities into its security operations, Acumen Cyber is shifting from periodic exposure assessment to a more continuous, evidence-based model focused on resilience. This includes validating preventive and detective controls against adversary techniques, mapping potential attack paths, and prioritising remediation based on demonstrated impact rather than solely on theoretical risk. Acumen Cyber's approach emphasises regular testing and validation against real-world adversary techniques. Within the partnership, engineers map techniques using frameworks such as MITRE ATT&CK to assess whether security controls can effectively prevent or detect them, and to identify where control gaps could lead to exploitable paths. Through the AttackIQ Threat Debt Index, organisations can use an analytical model to measure accumulated adversary exposure across their environment. The index provides ongoing insight into changes in threat exposure, highlighting where attack paths have been reduced, where new exposures have appeared, and where controls are effectively mitigating risk. Overall, the collaboration reflects a shift toward more continuous, evidence-based cyber defence practices, with a focus on validating security outcomes and reducing exploitable opportunities before they can be used by adversaries.

AttackIQ
Apr 2nd, 2026
Emulating the concealed Sinobi Ransomware.

Emulating the concealed Sinobi Ransomware. Ayelen Torello April 2, 2026 Sinobi is a financially motivated ransomware group that emerged in late June 2025, operating a closed, hybrid Ransomware-as-a-Service (RaaS) model in which a core team manages the malware, infrastructure, and payment/negotiation systems while a small number of trusted affiliates carry out intrusions. The name "Sinobi," derived from "shinobi" (Japanese for ninja), reflects the group's focus on stealth and controlled execution. Both technical and infrastructural overlaps strongly suggest that Sinobi is a rebrand or direct successor of the Lynx ransomware group, which itself inherited code from the earlier INC ransomware family. Sinobi conducts system and network discovery to identify local and remote targets prior to encryption, and implements a hybrid cryptographic scheme combining Curve25519 Donna for key protection with AES-128 in CTR mode for fast, scalable file encryption, enabling efficient impact across networked environments while preventing recovery without attacker-controlled private keys. AttackIQ has released a new attack graph that emulates the Tactics, Techniques, and Procedures (TTPs) associated with the deployment of Sinobi ransomware to help customers validate their security controls and their ability to defend against this threat. Validating your security program performance against these behaviors is vital in reducing risk. By using this new emulation in the AttackIQ Adversarial Exposure Validation (AEV) Platform, security teams will be able to: * Evaluate security control performance against baseline behaviors associated with the Sinobi ransomware. * Assess their security posture against an opportunistic adversary, which does not discriminate when it comes to selecting its targets. * Continuously validate detection and prevention pipelines against a playbook similar to those of many of the groups currently focused on ransomware activities. Sinobi Ransomware - 2025-08 - associated Tactics, Techniques and Procedures (TTPs). This emulation replicates the sequence of behaviors associated with the deployment of Sinobi ransomware on a compromised system with the intent of providing customers with the opportunity to detect and/or prevent a compromise in progress. The emulation is based on the behaviors reported by ESentire on August 27, 2025, and internal analysis. Discovery & Privilege escalation - Sinobi Ransomware deployment. This stage begins with the deployment of Sinobi ransomware. It gathers system and environment information using GetSystemInfo and GetEnvironmentStrings, followed by process discovery via CreateToolhelp32Snapshot, Process32FirstW, and Process32NextW. It then establishes elevated access by creating a local account (Assistance), adding it to the Administrators group using net localgroup, and enabling the SeTakeOwnershipPrivilege privilege to facilitate further actions. Download and Save Scenarios (T1105): The Sinobi Ransomware Sample (SHA256: 1b2a1e41a7f65b8d9008aa631f113cef36577e912c13f223ba8834bbefa4bd14) is first downloaded and then saved to disk in two separate scenarios to test network and endpoint controls and their ability to prevent the delivery of known malicious samples. Enable "SeTakeOwnershipPrivilege" Privilege via Native API (T1134): This scenario enables the SeTakeOwnershipPrivilege privilege for the current process using the AdjustTokenPrivilege Windows API. System Information Discovery via "GetSystemInfo" Native API (T1082): This scenario executes the GetSystemInfo Windows native API call to retrieve system information. This can be used to detect sandboxes, create unique identifiers, and adjust execution behaviors. Process Discovery via Native API (T1057): This scenario executes the CreateToolhelp32SnapshotWindows native API call to receive a list of running processes and iterates through each process object with Process32FirstW and Process32NextW. Get System Environment Variables via "GetEnvironmentStrings" Native API (T1082): This scenario executes the GetEnvironmentStrings Windows native API call to discover environmental variables, usually used to fingerprint the system or search for stored passwords and secrets. Create Account (T1136.001): This scenario attempts to create a new user into the system with the net user Windows command. Add Local User to Local 'Administrators' Group (T1098): This scenario adds a local user to the local Administrators group using the net localgroup command. Impact - Sinobi File Encryption. In this stage, Sinobi discovers network resources via WNetOpenEnumW and WNetEnumResourceW, and identifies available printers using EnumPrintersW. It then enumerates volumes with FindFirstVolumeW and FindNextVolumeW, and determines drive types via GetDriveTypeW to prioritize targets. Finally, it traverses the file system using FindFirstFileW and FindNextFileW, and encrypts files using AES-128 in CTR mode, with Curve25519 used for key exchange and protection. Network Resource Discovery via "WNetOpenEnumW" and "WNetEnumResourceW" Native API (T1049): This scenario performs network resource discovery by calling the WNetOpenEnumW and WNetEnumResourceW Windows native API calls to enumerate network resources from the local computer. Enumerate System Printers via "EnumPrintersW" Windows API (T1120): This scenario executes the EnumPrintersW Windows API to enumerate available printers, print servers, domains, or print providers. Volume Discovery via "FindFirstVolumeW" and "FindNextVolumeW" Native API (T1082): This scenario executes the FindFirstVolumeW and FindNextVolumeW Windows API calls to iterate through the available volumes of the system. Drive Type Discovery via "GetDriveTypeW" Native API (T1120): This scenario retrieves information about the system's physical disks using the GetDriveTypeW Windows API call. File and Directory Discovery via "FindFirstFileW" and "FindNextFileW" Native API (T1083): This scenario executes the FindFirstFileW and FindNextFileW Windows native API calls to enumerate the file system. Sinobi File Encryption for Windows (T1486): This scenario performs the file encryption routines used by common ransomware families. Files matching an extension list are identified and encrypted in place using similar encryption algorithms as used by Sinobi ransomware. Wrap-up. In summary, this emulation will evaluate security and incident response processes and support the improvement of your security control posture against the behaviors exhibited by Sinobi ransomware. With data generated from continuous testing and use of this assessment template, you can focus your teams on achieving key security outcomes, adjust your security controls, and work to elevate your total security program effectiveness against a known and dangerous threat. AttackIQ is the industry's leading Continuous Threat Exposure Management (CTEM) platform, enabling organizations to measure true exposure, prioritize risk, and disrupt real-world attack paths. By moving beyond static vulnerability data, AttackIQ operationalizes CTEM by continuously validating exposures against real adversary behavior and defensive controls. The platform connects vulnerabilities, configurations, identities, and detections into adversary-validated attack paths - quantifying the likelihood of attacker movement and impact. This evidence-based approach empowers security leaders to focus on what matters most, optimize defensive investments, and strengthen resilience through threat-informed, AI-driven security operations. The company is committed to supporting its MSSP partners with a Flexible Preactive Partner Program that provides turn-key solutions, empowering them to elevate client security. AttackIQ is passionate about giving back to the cybersecurity community through its free, award-winning AttackIQ Academy and founding research partnership with MITRE Center for Threat-Informed Defense.

Recently Posted Jobs

Sign up to get curated job recommendations

There are no jobs for AttackIQ right now.

Find jobs on Simplify and start your career today

We update AttackIQ's jobs every few hours, so check again soon! Browse all jobs →