Detection & Response
Running attacks is half the value; what your blue team learns is the other half. Kestrel turns each technique into a controlled experiment for your SOC.
Every action is a detection test
Running attacks is only half the value. The other half is what your blue team learns. Kestrel treats each technique as a controlled experiment for your SOC: did the alert fire, did the log land, did anyone respond?
Pairing offensive actions with detection outcomes turns a red-team exercise into a purple-team feedback loop — tuning detections against real behavior instead of guesswork.
- Per-action verdicts. See detected, partially detected, or missed for every single technique you run.
- Detection tuning. Feed results straight back into your SIEM and EDR rules, then re-test to confirm the fix.
- Time-to-detect. Measure how long each action stayed invisible, not just whether it was eventually caught.
A verdict for every technique.
The exact output your detection team works from after an operation.
Offense and defense on one scorecard.
Signal correlation
Line up emulated actions against the alerts and logs your platforms actually produced.
Feedback loop
Close the gap between offense and defense with a shared, evidence-based scorecard.
Measured detection
Track mean time to detect as a metric that improves operation over operation.
Where to go next
Find out what your defenses miss.
Run an operation and get a per-technique detection scorecard — with the gaps and the slow alerts marked.