Exploitation Engine

Crimson: Exploitation Driven by Live Intelligence

Crimson is our in-house exploitation engine. It turns raw scan data into ranked, intelligence-backed targets and carries validated findings through to controlled exploitation — so effort follows what is genuinely exploitable, not what a scanner rates by severity alone.

What It Is

Not a scanner. Not a wrapper.

Crimson is purpose-built tooling we have developed and refined in-house since 2021. It connects three things that usually live in separate places — scan data, live threat intelligence, and exploitation — into a single workflow that a consultant drives during an engagement.

It takes raw Nessus Pro exports and, instead of leaving you to scroll thousands of spreadsheet rows, filters, scores, and ranks hosts by how exploitable they actually are. From there it pulls current exploit intelligence for each candidate and carries validated targets through to controlled exploitation.

A track record, not a trend. Craft Consulting Solutions has applied artificial intelligence, machine learning, and data analytics to penetration testing since 2021 — well before it became an industry talking point. Crimson is where that work lives.

How It Works

From scan data to ranked, intelligence-backed targets

Exploitability scoring

Machine-learning models (k-nearest neighbours, random forest, gradient boosting) score each host’s exploitability from the scan data, so targets are ranked by likelihood of success rather than by raw severity.

Live exploit intelligence

Before testing a given vulnerability, Crimson pulls that CVE’s current intelligence from our platform — EPSS probability, CISA KEV status, exploit maturity, known exploit modules, and ransomware associations.

Persona-based targeting

Systems are classified by operating system, exposed ports, and network role. High-value targets — domain controllers, servers — are prioritized over low-value ones such as printers and workstations.

Intelligence-boosted ranking

Hosts with a Metasploit module, KEV listing, weaponized exploit, or high EPSS score are moved up the queue. Dead-end hosts with no genuinely exploitable path are dropped entirely, so time goes where it matters.

Controlled exploitation

Crimson drives exploitation through a controlled Metasploit workflow, selecting exploits and payloads from an experience database with layered fallback when the exact match is not available.

Online or air-gapped

The intelligence connection runs over the platform’s API when the environment has connectivity, and through an offline exchange when it does not — so isolated networks still benefit from current data.

Control

Automated where it helps, gated where it matters

Automation is only useful if it stays under control. Crimson gates every expensive operation behind an explicit decision — step through one action at a time, abort, or run a defined sequence autonomously. The consultant is in the loop throughout, and exploitation only ever runs against systems that are in scope and authorized.

The point is not to hand testing to a machine. It is to let a senior tester spend their attention on the targets that are genuinely worth it, with the routine triage and correlation already done.

Where Crimson fits. It is not a product we sell or install in your environment. It is the internal engine that makes our penetration testing sharper — the reason our testing follows real exploitability, and the reason a finding comes with a demonstrated path rather than a severity label.

Beyond Exploitation

What comes out of an engagement

Active Directory extraction

Users, groups, and domain information pulled from scan output and presented as structured, readable tables.

Attack tooling

Ready-to-run attack files generated from the scan data, plus mapping of vulnerabilities to known public exploits across hosts.

Reporting and visuals

Written reports with risk graphs, operating-system breakdowns, and outlier detection — the analysis behind the findings, not just a list of them.

See It In Action

From 480 findings to 6 that matter

Walk through an illustrative engagement — how Crimson scores, enriches, and validates a raw 480-finding scan down to the six that were genuinely exploitable, and the chained path that reached domain admin.

Put Crimson to work on your environment

Crimson runs inside our penetration testing engagements. Tell us what is in scope and what you need demonstrated, and we will size the work and the depth of exploitation that fits.