Exploitability scoring
Machine-learning models (k-nearest neighbours, random forest, gradient boosting) score each host’s exploitability from the scan data, so targets are ranked by likelihood of success rather than by raw severity.
Exploitation Engine
Crimson is our in-house exploitation engine. It turns raw scan data into ranked, intelligence-backed targets and carries validated findings through to controlled exploitation — so effort follows what is genuinely exploitable, not what a scanner rates by severity alone.
What It Is
Crimson is purpose-built tooling we have developed and refined in-house since 2021. It connects three things that usually live in separate places — scan data, live threat intelligence, and exploitation — into a single workflow that a consultant drives during an engagement.
It takes raw Nessus Pro exports and, instead of leaving you to scroll thousands of spreadsheet rows, filters, scores, and ranks hosts by how exploitable they actually are. From there it pulls current exploit intelligence for each candidate and carries validated targets through to controlled exploitation.
A track record, not a trend. Craft Consulting Solutions has applied artificial intelligence, machine learning, and data analytics to penetration testing since 2021 — well before it became an industry talking point. Crimson is where that work lives.
How It Works
Machine-learning models (k-nearest neighbours, random forest, gradient boosting) score each host’s exploitability from the scan data, so targets are ranked by likelihood of success rather than by raw severity.
Before testing a given vulnerability, Crimson pulls that CVE’s current intelligence from our platform — EPSS probability, CISA KEV status, exploit maturity, known exploit modules, and ransomware associations.
Systems are classified by operating system, exposed ports, and network role. High-value targets — domain controllers, servers — are prioritized over low-value ones such as printers and workstations.
Hosts with a Metasploit module, KEV listing, weaponized exploit, or high EPSS score are moved up the queue. Dead-end hosts with no genuinely exploitable path are dropped entirely, so time goes where it matters.
Crimson drives exploitation through a controlled Metasploit workflow, selecting exploits and payloads from an experience database with layered fallback when the exact match is not available.
The intelligence connection runs over the platform’s API when the environment has connectivity, and through an offline exchange when it does not — so isolated networks still benefit from current data.
Control
Automation is only useful if it stays under control. Crimson gates every expensive operation behind an explicit decision — step through one action at a time, abort, or run a defined sequence autonomously. The consultant is in the loop throughout, and exploitation only ever runs against systems that are in scope and authorized.
The point is not to hand testing to a machine. It is to let a senior tester spend their attention on the targets that are genuinely worth it, with the routine triage and correlation already done.
Where Crimson fits. It is not a product we sell or install in your environment. It is the internal engine that makes our penetration testing sharper — the reason our testing follows real exploitability, and the reason a finding comes with a demonstrated path rather than a severity label.
Beyond Exploitation
Users, groups, and domain information pulled from scan output and presented as structured, readable tables.
Ready-to-run attack files generated from the scan data, plus mapping of vulnerabilities to known public exploits across hosts.
Written reports with risk graphs, operating-system breakdowns, and outlier detection — the analysis behind the findings, not just a list of them.
See It In Action
Walk through an illustrative engagement — how Crimson scores, enriches, and validates a raw 480-finding scan down to the six that were genuinely exploitable, and the chained path that reached domain admin.
Crimson runs inside our penetration testing engagements. Tell us what is in scope and what you need demonstrated, and we will size the work and the depth of exploitation that fits.