NodeZero is referenced in the provided content as a product used to find and exploit vulnerabilities in production environments across industries, and as having an "Advanced Data Pilfering (ADP)" feature that combines LLMs with offensive security techniques to help defenders understand data at risk. Based on the provided content, it is presented as a security testing or offensive security platform rather than malware. No high-confidence information is provided indicating malicious payload behavior, infection vectors, persistence mechanisms, targeted victims, associated threat actors, or indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
There exist two distinct vulnerabilities which were assigned CVE-2024-23108 and CVE-2024-23109, both with a CVSS3 score of 10.0, which allows remote, unauthenticated command execution as root. This blog will only cover the first, CVE-2024-23108...
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
NodeZero is an automated penetration testing platform that leverages advanced techniques, including LLM-powered data analysis, to discover and validate credentials, perform lateral movement, escalate privileges, and assess the business risk of compromised data. Its Advanced Data Pilfering (ADP) feature uses LLMs to extract credentials from files and Active Directory attributes, and to classify and assess the risk of compromised data, including intellectual property, financial records, and PII.
NodeZero is an automated penetration testing platform developed by Horizon3.ai that identifies and exploits known vulnerabilities (CVEs) in customer environments to demonstrate real-world exploitability. It is used to surface and verify exploitable weaknesses, helping organizations close the gap between vulnerability awareness and remediation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.