The most expensive sentence in corporate cybersecurity may be, “We think it works.” The endpoint software is installed. The SIEM dashboard glows. An annual penetration test produced a thick PDF with alarming reds and reassuring greens. Then a real intruder arrives, and the alert that fired in one console never becomes a useful ticket in another. SCYTHE exists for that awkward seam between purchased protection and demonstrated protection.
The Columbia, Maryland-linked company sells an adversarial exposure validation platform: software that safely performs the behaviors of real attackers inside a customer's IT, cloud, or operational-technology environment. Campaigns can reproduce a named threat actor's tactics, follow a multi-stage path from initial foothold to lateral movement and exfiltration, and map each action to MITRE ATT&CK. The point is not to stage an elaborate hacker pageant. It is to record what the security stack logged, alerted on, blocked, ignored, and handed to a human.
A consulting job refuses to stay a consulting job
SCYTHE's origin is unusually specific. In 2016, Target approached GRIMM, the offensive-security consultancy Bryson Bort had started after leaving government work, with a request for a custom implant to train its defenses. The conventional move was to build the tool, bill the project, and build another bespoke tool for the next client. Bort proposed something more durable: keep the intellectual property and co-develop a platform that could express many kinds of threat behavior. The work continued for two years before SCYTHE was spun out and financed.
That is what the company did, exactly. It took the knowledge locked inside an expert red-team engagement and broke it into reusable communications, capabilities, and tactics. Bort's own description is an “offensive box of Legos.” An operator can assemble the pieces into a campaign without writing an implant from scratch, launch it only within approved boundaries, and repeat the same sequence after defenders change a rule. One clever project became a loop.
“I learned that it's not the idea you start with, but the agility to pivot.”Bryson Bort, founder and CEO
The first thesis still failed a basic market test. SCYTHE was being built as a red-team product, but dedicated red teams were a narrow population with limited software budgets. Bort later put the lesson bluntly: “there is no red team market.” The company did not abandon the offensive craft. It changed who could benefit from the output. Blue teams could tune detections. Purple teams could run the exercise together. CISOs could see coverage and response times. Consultants and managed security providers could package the platform as a service.
A safe punch, then a visible chain of consequences
A SCYTHE campaign starts with a threat worth testing. That might be ransomware behavior, credential dumping, a phishing-led foothold, an industrial adversary, or a chain derived from a fresh intelligence report. The platform can deploy in the cloud, on premises, in hybrid estates, or in air-gapped environments. Operators choose targets and controls, review the steps, and authorize execution. The actions run against the customer's real stack rather than a vendor's lab.
The useful unit is not simply “malware blocked.” SCYTHE follows the entire response chain. Did the EDR notice a PowerShell action? Did that event produce a clean SIEM alert? Did the alert trigger the intended SOC workflow? Was a Jira or ServiceNow issue opened with enough context to act? Did the incident playbook engage before the emulated attacker reached its objective? This is where the company differs from validation confined to one vendor's control plane.
The product supports a campaign library, a visual builder, dashboards, ATT&CK coverage views, validation results, purple-team exercises, and integrations with products including CrowdStrike Falcon, Microsoft Defender, SentinelOne, Cortex XDR, Splunk, Microsoft Sentinel, QRadar, Chronicle, Elastic, Jira, and ServiceNow. SCYTHE 5.1, released in March 2026, added natural-language campaign generation, phishing simulation, SIEM correlation, live monitoring, preparedness scores for ransomware, phishing, and insider threats, and faster loading for large campaigns.
What it costs, and the cost SCYTHE had to eat
SCYTHE does not publish a price list. This is enterprise software sold through demos, scoped deployments, subscriptions, managed validation, exercises, intelligence work, and partners. A buyer's quote will depend on the environment and service level. The company itself has raised approximately $18.25 million across a $3 million initial round in 2018, a $10 million Series A in 2021, and a supplied $5.25 million extension in 2023. Its backers include Gula Tech Adventures, Paladin Capital Group, Energy Impact Partners, Evolution Equity, and experienced security operators.
There was another cost, less glamorous and more instructive. SCYTHE needed to serve cloud customers and legacy on-premises installations. Separate build paths, full Windows instances, and manual upgrades pushed ordinary support problems into engineering. A published delivery case study estimated that 2.5 hours per customer, four upgrades a year, could consume as much as 350 hours annually for only a small collection of customers.
The team adopted a containerized, common delivery model with Replicated and moved from quarterly or semiannual releases to every two weeks. That change matters beyond DevOps trivia. A threat-emulation product with stale content is a weather service reporting last season's storms. Faster delivery lets new behaviors, fixes, and detections reach restricted environments while they still matter. It also kept a small company's engineers from becoming an artisanal upgrade concierge.
Who needs a rehearsal, and who merely wants a prop
The natural customers are enterprises with costly security stacks and meaningful consequences if those stacks fail: financial services, energy, manufacturing, health care, insurance, defense contractors, and other critical infrastructure. Red teams use SCYTHE to create and repeat realistic campaigns. Detection engineers use it to test rules. Blue teams use the resulting telemetry to tune alerts. SOC and incident-response leaders use it to see whether a technical signal survives the trip into an operational response.
SCYTHE sits between classic breach-and-attack simulation, manual penetration testing, automated penetration testing, and continuous threat-exposure management. Competitors and substitutes include AttackIQ, Picus, Cymulate, SafeBreach, Pentera, Mandiant Security Validation, Horizon3.ai, and internal stacks built from Atomic Red Team or CALDERA. SCYTHE's chosen distinction is fidelity and editability: named adversaries, multi-stage chains, operator-controlled building blocks, and testing across tools rather than inside one.
That distinction should not be treated as magic. The company's performance figures are customer-reported, and realism is contextual. A perfect campaign for a bank may be nonsense in a hospital or factory. Safe execution in operational technology demands knowledge of the process, strict boundaries, and people empowered to stop the test. The platform can automate evidence; it cannot make an organization care about the evidence.
The piece worth stealing
For founders, the copyable idea is not “add cyber AI.” It is the conversion of bespoke expertise into a repeatable instrument. SCYTHE kept the client's problem, retained the intellectual property, modularized the expert's choices, and made improvement measurable. Then it widened the user from the original specialist to everyone who needed the result. That is a solid route from consultancy to software.
The SCYTHE move, in five parts
- Find the expensive expert task clients keep requesting.
- Negotiate to preserve the reusable intellectual property.
- Turn expert choices into modular components, not a rigid template.
- Build a loop that proves improvement after the fix.
- Give adjacent teams a shared output they can act on.
Security teams can copy the operating method without buying the platform. Pick one threat relevant to the business. Map a short behavior chain. Define the expected telemetry and handoffs before the exercise. Run only within approved boundaries. Fix the first broken link. Replay the identical test. Keep the result as a regression check after tooling, staff, or configuration changes. SCYTHE's open Purple Team Exercise Framework offers a starting structure for that work.
When would it not work? When the organization has no trustworthy inventory, no log coverage, no testing authority, no recovery plan, or no owner for the findings. It can also be excessive for a small business that needs basic patching, multifactor authentication, backups, and managed monitoring before it needs adversary emulation. Mature testing amplifies a functioning security program. It does not substitute for one.
The newest chapter expands the tested surface to AI. A 2026 partnership with Starseer proposes Shadow AI Readiness Assessments for unauthorized or tampered models and agentic attack paths. That idea may prove timely, or it may arrive before many buyers have their ordinary endpoints under control. Bort's own recent advice is the sensible brake: strengthen existing operations first, because automation attached to weak process can create work faster than it removes it.
SCYTHE's best contribution is therefore not a scary demo. It is a managerial habit: replace the comforting noun “coverage” with observable verbs. Logged. Alerted. Blocked. Assigned. Contained. Re-tested. In a market stuffed with protective products, the company has made a business from asking them to show their work.