LIVE • Continuous exercise running — resilience score recomputed every cycle
● Continuous Automated Red Teaming

Prove your controls
actually stop the attack.

CART by Tribastion runs safe, authorised, scheduled MITRE ATT&CK emulation against your registered asset estate — continuously, not once a year — and turns every exercise into control-gap findings, resilience scoring, and regulator-ready evidence.

Every technique is checked against a fail-closed safety gate before it ever touches a target: engagement authorisation, explicit scope, blackout windows, and a hard, non-configurable refusal of destructive techniques. Nothing runs by accident.

17REST API endpoints
⌘Ksearch everything
24/7Slack & webhook alerts
CART — Tribastion Demo Bank · Weekly exercise
CART
Dashboard
Engagements
Campaigns
Findings
Reports
78Resilience score
14Prevented
6Detected
2Succeeded
22Steps run
Run complete
22 techniques executed2 control gaps found
Evidence sealed
Hash-chain verifiedTamper-evident trail intact
● How the engine works

Every technique passes a fail-closed gate before it ever touches a target

Refuse by default, never run by accident. The same safety gate checks the run as a whole and every technique×asset pair inside it.

1

Authorise & scope

An engagement is drafted, then explicitly authorised by a second person — never the drafter. Scope is an allow/deny rule set with deny always winning.

2

Check the gate

Engagement status, time window, and blackout windows are checked first. Destructive techniques are refused unconditionally — always, with no override.

3

Execute & observe

Every allowed step runs and every outcome — prevented, detected, succeeded, or refused — is recorded. A refusal is a logged outcome, never a silent skip.

4

Score & remediate

A resilience score is computed from real outcomes. A "succeeded" step raises a deduplicated finding with an SLA clock, not a lost alert.

● One continuous loop

Not an annual scan — an always-on exercise

Every module below is a real, working part of the console — the same cron that runs your campaigns on schedule also keeps compliance posture and reports current.

Assets

Your registered estate — the only things a campaign is ever allowed to target.

Engagements

Scope, blackout windows, and four-eyes authorisation before anything can run.

Campaigns & runs

Technique sets against real assets, on a cadence, or triggered on demand.

Findings

Deduplicated control gaps with severity-driven SLA clocks, not duplicate noise.

Incidents

The CERT-In 6-hour reporting clock starts the moment an incident is logged, and can't be edited afterward.

Compliance

RBI & NCIIPC control posture, computed automatically from real run evidence.

Reports

Sealed with a SHA-256 hash at generation time — tamper-evident at rest.

Integrations

Caldera, Metasploit & Nessus with encrypted credentials, plus Slack and webhook channels that push live alerts.

Users & roles

A per-tenant permission matrix — every role, every action, fully editable.

Audit log

A hash-chained, append-only trail — tampering is detectable, not just logged.

API access

Scoped X-API-Key credentials for a central governance or monitoring platform.

Settings

Organisation-level configuration, editable by an administrator.

● Built to actually use, not just watch

A console your whole team opens every day

Hover or tap a card. Every claim here is a real, working page in the console today — not a roadmap item.

Instant notifications

hover / tap

Instant notifications

Every campaign completion, high-severity finding and new incident lands in-app immediately — and pushes to Slack or a webhook if you've connected one.

Global search

hover / tap

Global search

Ctrl+K from anywhere in the console searches assets, engagements, campaigns, findings and incidents at once — filtered to what your role can actually see.

Guided training

hover / tap

Guided training

An in-app walkthrough of the full lifecycle plus a live role guide, read straight from the same RBAC catalog that enforces permissions — never out of sync.

Open API

hover / tap

Open API

17 documented REST endpoints behind scoped X-API-Key credentials — every method, permission and a real curl example, right in the console.

● Regulator-ready evidence

Posture your auditor can trust, because it's never hand-typed

  • RBI & NCIIPC control mappingEvery control is scored from the latest real run outcome of the ATT&CK techniques it declares itself exercised by — "met" only when there's live evidence of a prevented technique.
  • CERT-In 6-hour reporting clockComputed once when an incident is logged and never editable afterward — the deadline can't be quietly pushed out.
  • Sealed reportsEvery generated report carries a SHA-256 content hash, checked on every view — tampering after the fact is detectable, not just theoretically possible.
RBI-CSF-2.1 — Network & perimeter controlsMet
RBI-CSF-3.1 — Access control & authenticationPartial
NCIIPC-CSBP-4 — Endpoint detection & responseMet
CERT-In reporting window4h 12m left
● Built for a shared platform

Every tenant's data stays that tenant's data

The same guardrails that gate a technique run also gate who can see and do what — enforced at the query level, not just the UI.

Segregation of duties

No one authorises an engagement or approves a finding they created themselves.

Tenant isolation

Every query is scoped to your organisation automatically — enforced by the framework, not remembered per query.

Tamper-evident audit

A hash-chained log of every consequential action, verifiable end to end.

Encrypted credentials

Integration API keys are encrypted at rest and never returned by any page or API response.

Scoped API access

Machine credentials can only narrow what their owning user could already do, never widen it.

Ready to see it running on real data?

Sign in to the demo tenant and open a live campaign, finding, or compliance control yourself.

Sign in to your console