AttackIQ Flex

Agentless, On-Demand Exposure Validation.

Run production-safe adversary emulations in minutes. No agents, no installs, no commitment.

Finally, Exposure Validation That Works. On Your Terms.

Transform ad hoc testing into continuous validation that uncovers vulnerabilities other tools miss.

Self-contained test packages you can run on any device

Pay-as-you-go pricing with free credits to start

Prebuilt emulations aligned to real-world adversaries

Remediation guidance built in for faster fixes

Simple Exposure Validation—Anytime, Anywhere

Lightweight deployment gets you testing real-world attack scenarios immediately.

Choose Your Tests

Select from full adversary campaigns and security control baselines to validate your defenses.

Run Anywhere, Instantly

No agents. No installs. Execute production-safe tests on any device in your environment—Flex is fully self-contained.

Analyze and Remediate

View detailed results mapped to MITRE ATT&CK. Use built-in detection rules and mitigation guidance to close validated exposure gaps fast.

Adversary-Informed Testing Built for Speed

Validate your defenses against current threat intelligence without delays or lengthy procurement cycles.

Validate Exposure Using Real Attack Paths

Simulate real-world attacks using MITRE ATT&CK® techniques

Test NGFWs, EDRs, and segmentation controls with targeted assessments

Confirm security posture against NIST, DORA, and ISO 27001 standards

Understand Your Risk in Minutes

Visualize exposure across TTPs

Generate actionable reports and executive-ready summaries

Use MITRE ATT&CK-mapped results for unified communication

Fix Validated Exposures

Follow step-by-step remediation guidance for validated gaps

Deploy included Sigma and YARA rules to your SIEM

Prioritize response based on business risk impact

Verify Detection Coverage

Confirm that controls detect attacks even if prevention fails

Use prebuilt rules to close detection gaps

Validate full SIEM pipeline from event capture to analysis

Once you use it, you’ll never want to use anything else again.

Richard Wadsworth, Cybersecurity Professional

Pay-as-You-Test Pricing That Scales With You

Start free, then scale based on actual usage. You maintain full control over testing frequency and scope—no overhead, no surprises.

Free

Best for people getting started with Breach & Attack Simulation.

  • Access to Free Testing Packages
  • Access to Adversary Research
  • Pay-as-you-go

$300

Best for people looking to test on an intermittent basis.

  • 1 Credit
  • 10 Credits
  • 25 Credits
  • 50 Credits
  • 100 Credits

$4,995

Best for people looking to do comprehensive ad-hoc testing.

  • Access to Unlimited Testing (30 Days)
  • Access to Adversary Research
  • 1 Hour of Professional Services

Get in Touch

Best for people looking to do programmatic testing all year.

  • Access to Unlimited Testing
  • Access to Adversary Research
  • 6 Hours of Professional Services

FAQs

What is Flex?
Flex is an agentless breach and attack simulation tool, described as “test as a service.” It utilizes the AttackIQ platform and employs self-contained test packages to automate security testing without the need for any configuration or agents.

How is it different from Ready or Enterprise?
Flex is a lightweight implementation of the AttackIQ breach and attack simulation platform. Where Enterprise allows for more customization, Flex contains fully packaged scenarios. Click, run and done.

Does it use malware?
AttackIQ utilizes live malware samples that are saved and written to the local file system without execution. Using a hash comparison, Flex determines which samples were successfully planted on the endpoint. All staged files are removed at the conclusion of the test to ensure cleanup.

How can I redeem my flex credits?
To redeem credits, sign up for Flex and redeem within the product.

Will new adversary emulations be added?
We are continually adding new tests and providing curated content, including new adversary emulations.

What type of content is available on AttackIQ Flex?
There are two types of packages currently available: Adversary campaign tests and baseline tests.

Is all of the AttackIQ Enterprise content available on AttackIQ Flex?
No. Flex contains a smaller subset of content than the enterprise version.

What reports are available on AttackIQ Flex?
Flex automatically generates a comprehensive report once the testing output is uploaded to the Flex portal. Content varies depending on the report run.

Can I generate custom reports in AttackIQ Flex?
The lightweight implementation of Flex means users can only run available packages in the menu.

How can I upload a Flex test package to a remote endpoint?
Users can download a Flex test package and upload and execute it on any supported OS endpoint.

Can I run AttackIQ Flex on any OS?
Currently, only Windows OS is supported with additional support coming soon.

What are the primary AttackIQ Flex use cases?
There are numerous use cases for Flex, including:

  • Zero trust validation
  • SMB security testing
  • Red team augmentation
  • Purple teaming augmentation
  • Regular self-managed security validation
  • Fully managed security validation program
  • Security posture assessment
  • Managed service provider assessments
  • Network consolidation during M&A activity

Never Settle for Uncertainty

Validate Your Defenses

Take the guesswork out of threat exposure management. Validate your defenses with real-world attack scenarios.