What's New · August 2026
SCYTHE 5.3
5.2 made the test instant. 5.3 makes the verdict defensible.
Validation never broke in the middle. It broke at the seams: export the timestamps, walk them to the SIEM, eyeball the correlation, write the finding somewhere else. SCYTHE 5.3 pulls detections from your stack, correlates them to the step that actually ran, and scores the response. One platform, one evidence base, one record of what has been validated.
Logged
Telemetry Captured
Proof the data source works
Alerted
Someone Was Told
Coverage that still needs a human
Blocked
Behavior Stopped
The only verdict that prevents impact
Every test in 5.3 ends in one of these three, traced to a specific step on a specific host.
★ Flagship Feature
Run the Whole Loop
From the Client You Already Use.
The SCYTHE MCP server publishes the platform as tools to your AI assistant. Five systems, one conversation.
Continuous validation is the practice most SOCs believe in and almost none actually run. Not because the steps are hard, but because the handoffs between them cost a person, a context switch, and a day. Pick a threat, emulate it on a real host, pull what the SIEM and EDR saw, decide whether the control logged, alerted, or blocked, turn the gap into work someone owns. SCYTHE 5.3 removes the seams: threat intelligence, the threat library, test creation and execution, agent inventory, SIEM and EDR correlation, detection coverage, exposure tracking, exercise management, and reporting are all callable in natural language from a client you already have open.
Identity
It Runs As You.
Access is per-user. Every tool call inherits your SCYTHE identity, workspace, and role permissions, so the assistant cannot see or do anything your account cannot. Connecting a client creates no privilege your role did not already carry.
Blast Radius
Every Tool Declares Itself.
Read-only tools are marked observe. Tools that change platform objects are marked mutate. Tools that execute adversary behavior on a live host are marked destructive and require a real agent on a named target. You know which side of the line a request falls on before it runs.
The Full Loop
One Thread, End to End.
Ask what is trending, run the matching threat against a lab host, pull the correlated detections, record the verdict, open the exposure, file the ticket, post to the channel, and generate the write-up. Your SIEM, tracker, and chat platform join the same thread through their own MCP servers.
Settings → MCP Server
Copy your server URL, expand Connect a client, and pick Claude Desktop, Cursor, or Microsoft 365 Copilot. Each one hands you a copy-and-paste prompt that configures the assistant for you, with manual steps if you would rather do it yourself. Before you point an assistant at your instance, use the explorer on the same page: pick any tool, read the question it answers, its blast radius, and its inputs, then run it live and see the raw response.
"Five systems. One conversation. Minutes, not a sprint."
SCYTHE MCP Server
What's New in 5.3
The Loop Closes.
Inside the Platform.
Detections come back from your stack natively. Verdicts attach to the step that actually ran. Gaps become owned work that agrees with itself. And the evidence reaches every role that needs it, in the view or the client they already work in.
Connect
First-Party SIEM and EDR Connectors
SCYTHE Connect pulls detections from your stack, correlates them to the activity SCYTHE emulated, and scores the response as Logged, Alerted, or Blocked. Splunk, SentinelOne, CrowdStrike Falcon, Microsoft Sentinel, Microsoft Defender, Elastic Security, and more, with no third-party integration platform in between.
Accuracy
Detections Attributed Honestly
A detection is now attributed to the step that actually ran and could plausibly have caused it. Matches that line up on timing alone are labelled Research required instead of silently scoring a step in your favor.
Purple
Purple Team and Tabletop Exercises
A new module for planning, running, and closing out PTE and TTX engagements, including a presenter view for the room, incident response plan coverage, and after-action reporting. Build it, run it, and publish the AAR before people leave the call.
Roles
A Dashboard Per Job
Separate Management, Red, Operator, Defender, and MITRE Coverage views, each built around what that role actually needs to see rather than one dashboard compromising for everyone.
AI
Bring Your Own AI
Choose OpenAI, Anthropic, Google Gemini, or any OpenAI-compatible endpoint including self-hosted models, or use the SCYTHE-managed key with nothing to configure. One shared credential or separate ones for the AI Assistant and the Threat Creation engine.
Help
Comprehensive Help System
A rewritten help center and a page-aware AI Advisor that answers in the context of where you are, tuned to the persona and experience level you set in your AI preferences.
Also in This Release
Numbers That Agree, and Proof You Can Send Upward
RiskOps now agrees between Gaps and Exposures and links straight to the tests behind a number. The ATT&CK Matrix adds ICS alongside Enterprise, plus your own custom tests. MITRE ATT&CK v19 content throughout. Report buttons on every major page with branded PDF, Word, and Markdown output. And a configurable session timeout.
Spotlight Capability
You Ran the Attack.
Now Prove What Your Stack Did.
SCYTHE Connect brings the detections back natively. No middleware, no exported timestamp ranges, no eyeballing.
Most stacks carry a long tail of techniques where the control alerts and nothing blocks, and that distinction only shows up when you execute the behavior and read what the SIEM and EDR actually did. SCYTHE Connect executes, correlates, and scores in one pass, so alert-only coverage stops being mistaken for protection and becomes a ranked, evidenced list with owners against it.
Native Connectors
First-party connectors to the tools you already run, wired directly into the platform. Check connector health, sync on demand, and see exactly which ingest runs succeeded. No third-party integration platform sitting in the middle of your evidence.
Correlated to What Ran
Detections are matched to the step that actually executed and could have caused them, not to whatever happened to land in the same minute. Anything that only lines up on timing is surfaced as Research required for a human to adjudicate.
Scored, Not Dumped
The output is a verdict with the reasoning behind it, not a raw event feed: Logged, Alerted, or Blocked, per technique, per host. Gaps roll into RiskOps as tracked exposures with severity, an owner, and a retest.
Supported at Launch
Splunk · SentinelOne · CrowdStrike Falcon · Microsoft Sentinel · Microsoft Defender · Elastic Security · and more
Still True from 5.2
Intel still goes in and executable tests still come out, with the 100x compression on test design that 5.2 introduced. In 5.3, the result comes back scored. Read the 5.2 release ›
Role-Based Dashboard
Five Views.
One Evidence Base.
Adversarial exposure validation produces the evidence five different functions need to do their jobs. In 5.3 each of them gets a view built for the question they are actually asking, drawn from the same execution data, the same permission model, and the same record of what has been validated.
Management
Program health, remediation backlog, and Threat Preparedness Scores for ransomware, phishing, and insider threat, updated continuously as emulations run. When the board asks whether the stack works, the answer is a coverage record from execution data, not a maturity score.
Red
Campaign activity, threat coverage, and what the library has yet to prove. Hand the rehearsed set to automation so coverage breadth stops competing with engagement depth, then contribute new tradecraft back as a threat anyone can rerun.
Operator
Running tests, agent inventory, per-step outcomes, and connector health in one place. The console stays the workbench, with everything needed to launch, watch, and troubleshoot a run without leaving the view.
Defender
Detection outcomes, unresolved events waiting on adjudication, and open exposures by owner. Write the logic, fire the technique, read what the SIEM and EDR did, and catch a silent rule failure in hours instead of finding it during an incident.
MITRE Coverage
Enterprise and ICS matrices plus your own custom tests, on ATT&CK v19 content, showing what has been tested, what came back covered, and what has not been touched in 90 days. Coverage stops being a spreadsheet someone maintains by hand.
Every number on the dashboard links back to the tests behind it.
A specific test, a specific host, and the SIEM's own account of what it saw.