AttackIQ
Los Altos, USA
Security control validation platform built around MITRE ATT&CK and purple-team testing.
Named among 2026 CTEM and BAS alternatives in independent vendor comparisons
CTEM, attack-surface, pentest-platform, and continuous-exposure startups. Not a services firm with a PDF report.
Catalog last reviewed 2026-08-23. Page copy reviewed 2026-08-10. Next editorial review by 2026-09-10. Alphabetical order, no paid placement. 13 matched live listings.
This shortlist is the live catalog slice for the Offensive and exposure category. Listings appear here only when their primary category matches. Full page-unique intros for remaining categories ship in a later polish pass.
How order works. Matched companies are the full live catalog slice for this primary category, sorted alphabetically by name. This is not a scored quality ranking. When listing fees open, they are intended to affect publish timing or review-queue position only, not alphabetical order or praise on this page (payments are currently closed). Aevral is a disclosed house listing under the same rules (coming soon, no pin). See /transparency.
Category index: /categories/offensive-exposure. Parent hub: /best. Full catalog: /directory.
Los Altos, USA
Security control validation platform built around MITRE ATT&CK and purple-team testing.
Named among 2026 CTEM and BAS alternatives in independent vendor comparisons
Ann Arbor, USA
Internet-wide map of exposed infrastructure used for ASM, threat hunting, and exposure management.
Raised $40M Series D plus $30M debt led by Morgan Stanley Expansion Capital, March 2026
Tel Aviv, Israel
BAS-born exposure validation that now pushes findings into automated control updates.
Shipped Vero AI for agentic cyber defense engineering on the live platform, 2026
Stockholm, Sweden
Hacker-powered surface monitoring for domains, apps, and APIs, now with an MCP server for AI workflows.
Launched a Detectify MCP server for AI security workflows, 2026
Amsterdam, Netherlands
Outside-in autonomous hacker that discovers, exploits, and validates external exposure continuously.
Shipped Sense, Plan, Attack AI agents to operationalize CTEM, November 2025
San Francisco, USA
NodeZero autonomous pentest that exploits live networks the way an attacker would, continuously.
Raised $250M Series E at a $2B-plus valuation, August 2026
Burlington, USA
Automated security validation that actually exploits attack paths inside the customer's network.
Raised $60M Series D led by Evolution Equity Partners, March 2025
San Francisco, USA
Breach-and-attack simulation plus autonomous pentest that scores whether controls actually stop the attack.
Raised $45M Series C to lead adversarial exposure validation, September 2024
Palo Alto, USA
Cyber risk quantification platform that added an agentic CTEM loop on top of CRQ and TPRM.
Raised $70M Series C and launched a fully autonomous CTEM offering, July 2025
Columbia, USA
Internet-scale IPv4/IPv6 discovery that maps what an attacker can actually see of you.
Launched new product capabilities for AI-driven attack-surface change, December 2025
Tel Aviv, Israel
Agentic pentest platform with a human in the loop across web, API, network, and AI surfaces.
Raised $8M (Q2 2025) to scale agentic continuous pentesting
Tel Aviv, Israel
Hybrid attack-path graph that shows how an identity, cloud, or on-prem foothold becomes a breach.
Named a Challenger in the first Gartner Magic Quadrant for Exposure Assessment Platforms, 2025
New York, USA
CTEM that proves which CVEs are exploitable, then mitigates with the controls you already own.
Raised $60M Series C led by Menlo Ventures, December 2025