CART by Tribastion runs safe, authorised, scheduled MITRE ATT&CK emulation against your registered asset estate — continuously, not once a year — and turns every exercise into control-gap findings, resilience scoring, and regulator-ready evidence.
Every technique is checked against a fail-closed safety gate before it ever touches a target: engagement authorisation, explicit scope, blackout windows, and a hard, non-configurable refusal of destructive techniques. Nothing runs by accident.
Refuse by default, never run by accident. The same safety gate checks the run as a whole and every technique×asset pair inside it.
An engagement is drafted, then explicitly authorised by a second person — never the drafter. Scope is an allow/deny rule set with deny always winning.
Engagement status, time window, and blackout windows are checked first. Destructive techniques are refused unconditionally — always, with no override.
Every allowed step runs and every outcome — prevented, detected, succeeded, or refused — is recorded. A refusal is a logged outcome, never a silent skip.
A resilience score is computed from real outcomes. A "succeeded" step raises a deduplicated finding with an SLA clock, not a lost alert.
Every module below is a real, working part of the console — the same cron that runs your campaigns on schedule also keeps compliance posture and reports current.
Your registered estate — the only things a campaign is ever allowed to target.
Scope, blackout windows, and four-eyes authorisation before anything can run.
Technique sets against real assets, on a cadence, or triggered on demand.
Deduplicated control gaps with severity-driven SLA clocks, not duplicate noise.
The CERT-In 6-hour reporting clock starts the moment an incident is logged, and can't be edited afterward.
RBI & NCIIPC control posture, computed automatically from real run evidence.
Sealed with a SHA-256 hash at generation time — tamper-evident at rest.
Caldera, Metasploit & Nessus with encrypted credentials, plus Slack and webhook channels that push live alerts.
A per-tenant permission matrix — every role, every action, fully editable.
A hash-chained, append-only trail — tampering is detectable, not just logged.
Scoped X-API-Key credentials for a central governance or monitoring platform.
Organisation-level configuration, editable by an administrator.
Hover or tap a card. Every claim here is a real, working page in the console today — not a roadmap item.
Every campaign completion, high-severity finding and new incident lands in-app immediately — and pushes to Slack or a webhook if you've connected one.
Ctrl+K from anywhere in the console searches assets, engagements, campaigns, findings and incidents at once — filtered to what your role can actually see.
An in-app walkthrough of the full lifecycle plus a live role guide, read straight from the same RBAC catalog that enforces permissions — never out of sync.
17 documented REST endpoints behind scoped X-API-Key credentials — every method, permission and a real curl example, right in the console.
The same guardrails that gate a technique run also gate who can see and do what — enforced at the query level, not just the UI.
No one authorises an engagement or approves a finding they created themselves.
Every query is scoped to your organisation automatically — enforced by the framework, not remembered per query.
A hash-chained log of every consequential action, verifiable end to end.
Integration API keys are encrypted at rest and never returned by any page or API response.
Machine credentials can only narrow what their owning user could already do, never widen it.
Sign in to the demo tenant and open a live campaign, finding, or compliance control yourself.
Sign in to your console