Federal & Mission-Critical Security Validation
Horizon3 pitches continuous NodeZero validation for federal teams, arguing annual pentests miss fast identity attacks.
Horizon3.ai argues federal security programs should replace annual penetration tests with continuous exploitability validation and promotes its NodeZero Federal platform. In an engagement modeled on Iranian tradecraft, NodeZero identified Zerologon (CVE-2020-1472) on a domain controller, and the flaw was patched and re-validated in just over 24 hours. The post says one deployment reduced 18,000 scanner findings to 21 verified exploitable paths, and a GOAD benchmark showed full Active Directory compromise in 14 minutes. NodeZero Federal is described as FedRAMP High authorized, listed on the NSA CSfC Approved Products List, and used as the engine for the NSA Continuous Autonomous Penetration Testing program.