Continuous Adversarial Exposure Validation
Always-on broad coverage of your attack surface by Hackian
Description
Continuous Adversarial Exposure Validation (CAEV) is Ethiack's always-on test mode. Rather than targeting a specific set of assets on a fixed schedule, Hackian continuously analyzes your entire attack surface in breadth — running reconnaissance to detect new assets as they appear and testing for common vulnerabilities across everything it knows about your infrastructure.
Because this mode never stops, it ensures that any new exposure introduced by infrastructure changes, new deployments, or newly discovered assets is caught as early as possible.
How it works
Hackian operates across two dimensions simultaneously:
- Reconnaissance — continuously monitors your domains and surface for new assets being created or exposed, keeping your attack surface up to date without manual intervention.
- Vulnerability testing — runs broad checks for common vulnerabilities across all assets in scope, prioritizing coverage over depth.
When a new vulnerability is found, an alert is raised immediately so your team can act before it has time to be exploited.
How to launch a Continuous Test
- Define the scope — select which assets are in scope and which are out of scope. Assets can be marked as a wildcard, which will include everything matching that asset pattern.
- Set member access — choose which members of your organization can access this test. Members not included will not be able to manage the scope or view findings for this test.
- Launch — click Launch Test and Hackian will immediately begin testing the assets in scope, continuously.
Managing scope over time
You can add or remove assets from the test scope at any time. You can also add Grey-box credentials to give Hackian authenticated access to assets — currently supporting username and password login without MFA.
Acting on results
All findings discovered through CAEV appear in the Findings section in real time. Each finding includes full technical detail — description, evidence, impact, and suggested mitigations — so your team has everything needed to assess and remediate it.
Alerts for new vulnerabilities are surfaced directly in the portal and can be configured to notify your team through your preferred channels.