Enterprise · Attestable pentest

Puppet Master

Autonomous attack emulation that proves — with auditable evidence — exactly how an attacker would breach your cloud. Puppet Master takes the attack paths Ghost Mode finds and actually executes them: chaining credentials from step to step, capturing provider request/response evidence, and stopping at a certified human sign-off. A real pentest, on demand.

puppet-master · run #A7F3 live

01 RoE scope confirmed · aws:prod · us-east-1

02 PLAN ingested 16 attack paths from Ghost Mode

03 EXEC igw → ec2 role → sts:AssumeRole → s3:GetObject

04 proof captured · req-id 8f21c… · 3 hops

05 GATE awaiting certified reviewer sign-off

— report sealed on approval · chain-of-custody intact

How it works

Autonomous engine, human attestation

PCI-DSS and SOC 2 don't accept a fully autonomous attestation. Puppet Master runs the hard part automatically, then hands off to a certified reviewer — so the report holds up in audit.

01 · RoE

Rules of Engagement

Scope every account, region and technique up front. Nothing runs without an explicit, signed RoE — and offensive engines stay off unless you opt in.

02 · Emulate

Multi-step kill chains

The engine executes the attack paths Ghost Mode found — propagating credentials and tokens from one step to the next, exactly as a real adversary would.

03 · Prove

Auditable evidence

Every action persists the raw provider request/response, request-id, timestamp and proof of access — a reproducible chain of custody, not free-text notes.

04 · Attest

Certified sign-off

A qualified reviewer validates and signs the report before it's issued — the human gate PCI-DSS 11.4 and SOC 2 require, on top of an autonomous engine.

Why Puppet Master

A pentest that survives an audit

Semantic integrity

Puppet Master never claims exploitation without proof. Each finding states exactly what happened — configuration observed, permission confirmed, or effective access proven — so nothing in the report is an overstatement.

Real kill chains

Credentials obtained in one step feed the next. It proves "key in A → access to B → data in C" end to end — the essence of a pentest — instead of a pile of disconnected findings.

Audit-grade evidence

Reproducible request/response evidence with provider request-ids and full chain of custody — the standard PCI-DSS 11.4 and SOC 2 CC7 demand, and the reason the report is defensible.

Controlled by design

Explicit scope by account and region, safe by default, and offensive engines (Arsenal, C2) gated behind opt-in consent — you decide whether and how they ever fire.

FAQ

Answers for security and compliance teams

Clear answers about how Arkhein secures your multi-cloud — from onboarding to business move forward.

Arkhein connects your AWS, OCI, GCP, Azure and Huawei Cloud accounts and builds a living graph of every resource, identity and relationship. It runs continuous CSPM scans, finds cross-cloud attack paths with Ghost Mode, maps compliance, and can ship fixes as Terraform pull requests.

Scanners hand you thousands of isolated findings. Arkhein connects them on a graph, so you see the real path an attacker would take to your crown jewels — and fix the choke point instead of the checklist. It is also available self-hosted, which SaaS-only vendors don't offer.

AWS, OCI, GCP, Azure and Huawei Cloud today. Compliance is mapped to CIS, NIST 800-53, ISO 27001, PCI-DSS, SOC 2, LGPD and BACEN, with exportable evidence for auditors.

Connecting an account takes minutes with scoped, read-only roles — no agents. Your first attack-path analysis is ready within the first scan, and guided onboarding is included.

Yes. Credentials are encrypted, access is scoped and read-only, and every action is audited. For regulated or data-sovereign environments, Arkhein can run fully self-hosted in your own infrastructure.

Arkhein is priced by value and cloud footprint, in four tiers from Starter to Enterprise. There is no self-serve trial — book a demo and our team will size the right plan for your environment.

Ready to see your cloud
as an attacker does? 

Book a demo and our team will walk you through Arkhein on your own cloud.