logo
Horizon3.ai's NodeZero® Becomes First AI to Fully Solve Game of Active Directory (GOAD)

Horizon3.ai's NodeZero® Becomes First AI to Fully Solve Game of Active Directory (GOAD)

Business Wirea day ago
SAN FRANCISCO--(BUSINESS WIRE)--Horizon3.ai today announced that NodeZero®, its autonomous penetration testing platform, is the first AI to fully solve the Game of Active Directory (GOAD) — a respected benchmark for Active Directory exploitation — completing the challenge in just 14 minutes.
GOAD, developed by Orange Cyberdefense, simulates a realistic multi-domain enterprise network with the same trust abuses, misconfigurations, and security controls attackers exploit in the wild. Solving it requires chaining reconnaissance, credential abuse, privilege escalation, lateral movement, and persistence across multiple hosts and domains.
Recent Carnegie Mellon University research underscores how difficult this is: state-of-the-art LLMs like GPT-4o, Gemini 2.5 Pro, and Sonnet 3.7, even with advanced prompting frameworks, failed to reliably execute multi-host intrusions, capturing less than 30% of attack graph states in labs capped at 50 hosts.
Why GOAD is Hard
For both humans and algorithms, GOAD is a stress test of scale, reasoning, and persistence. Attack paths are not linear and require maintaining multi-hop memory across dozens of steps, adapting execution priorities based on partial successes, and exploiting inter-domain trust boundaries under realistic constraints.
For expert human pentesters: Completing GOAD typically takes 12–16 hours of sustained effort, deep AD exploitation expertise, and careful sequencing of tools and tactics.
Completing GOAD typically takes 12–16 hours of sustained effort, deep AD exploitation expertise, and careful sequencing of tools and tactics. For algorithms and LLMs: The complexity forces reasoning systems to juggle conditional execution, state tracking, and dynamic reprioritization — capabilities where current AI models fail.
NodeZero's solve time of 14 minutes is 50 times faster than an expert human, with perfect execution of the full attack chain from initial foothold to complete domain compromise.
NodeZero operates in a different league — applying the same architecture that solved GOAD in minutes to production-scale networks across industries. Its campaigns directly map to the breach patterns documented in the 2025 Verizon DBIR, IBM X-Force, and Mandiant M-Trends reports:
Initial access via public-facing vulnerabilities and valid accounts: Verizon: ~20% of breaches start with exploited vulnerabilities, 22% with stolen credentials; IBM: 40% involve public-facing apps, 27% valid cloud accounts. NodeZero safely exploits these same weaknesses in live environments.
Verizon: ~20% of breaches start with exploited vulnerabilities, 22% with stolen credentials; IBM: 40% involve public-facing apps, 27% valid cloud accounts. NodeZero safely exploits these same weaknesses in live environments. Identity and directory abuse : Mandiant: Account Manipulation (T1098) in 19.9% of cases, External Remote Services (T1133) in 22.4%. GOAD's domain trusts, Kerberoasting, and SSO abuse chains mirror these tactics, and NodeZero executes them autonomously.
: Mandiant: Account Manipulation (T1098) in 19.9% of cases, External Remote Services (T1133) in 22.4%. GOAD's domain trusts, Kerberoasting, and SSO abuse chains mirror these tactics, and NodeZero executes them autonomously. Lateral movement and privilege escalation: IBM and Mandiant highlight the use of living-off-the-land techniques post-access; NodeZero's graph-driven orchestration prioritizes these pivots to reach high-value targets.
IBM and Mandiant highlight the use of living-off-the-land techniques post-access; NodeZero's graph-driven orchestration prioritizes these pivots to reach high-value targets. Persistence and re-entry: Mandiant: backdoors in 35% of intrusions, often outpacing ransomware loaders. NodeZero validates whether these footholds can be established and detected.
In the NSA's Continuous Autonomous Penetration Testing (CAPT) program, NodeZero has already shown this capability at national scale:
Expanded coverage from 200 to 1,000 defense contractors.
Discovered 50,000+ vulnerabilities, with 70% remediated — many within days.
Achieved domain compromise in as little as 77 seconds and uncovered catastrophic exposures in under five minutes.
Gained access to sensitive CAD drawings of Aircraft Carriers and Nuclear Submarines in less than five minutes
'GOAD is an excellent benchmark, but its real value is how closely it reflects what's happening in the wild,' said Snehal Antani, CEO and Co-Founder of Horizon3.ai. 'When you can solve GOAD in minutes, and then turn that same capability loose in production networks — aligned to the exact tactics in the DBIR, IBM, and Mandiant reports — you're not just testing security, you're closing the gap between how attackers operate and how defenders respond.'
While competitors make bold marketing claims about being 'No. 1,' NodeZero delivers proof — both in the lab and in live, complex environments — at a scale no other platform has matched.
Learn More About NodeZero vs. GOAD.
About Horizon3.ai
Horizon3.ai empowers organizations to continuously verify their security posture with NodeZero®, the industry's leading autonomous pentesting platform. Built to think and act like an attacker — but operate safely in production — NodeZero identifies exploitable weaknesses, prioritizes fixes based on real-world impact, and verifies remediation at scale. Customers across manufacturing, healthcare, finance, and national security rely on NodeZero to reduce risk and accelerate security outcomes.
Follow Horizon3.ai on LinkedIn and X.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

How To Navigate The New Frontier Of Market Segmentation
How To Navigate The New Frontier Of Market Segmentation

Forbes

time2 hours ago

  • Forbes

How To Navigate The New Frontier Of Market Segmentation

Nancy Clark is President of Verizon Value, redefining the prepaid wireless landscape via customer-centric innovation and digital excellence. In today's competitive market, companies must rethink how they connect with customers. Market segmentation—the practice of dividing a broad market into subgroups based onshared characteristics—has long been a cornerstone of the industry. But as customer preferences evolve, segmentation strategies must go beyond demographics to deliver personalized, meaningful experiences. At my company, we use data-driven insights with a human-centered approach to create solutions that resonate more personally. Here's how you can do the same. Understand customer context. Effective segmentation begins with a deep understanding of customers' unique contexts, moving beyond surface-level factors like basic demographics. For example, with our value brands in the prepaid market, we consider a variety of factors to help shape our offerings. This helps us align not only the products and services we offer but also how and where we distribute them. Consider these factors as you're honing your customer experience strategies: In my industry, prepaid customers' financial realities play a big role in their needs. Our value-conscious customers often prioritize the affordability and predictability of no-contract plans, which allow them to stay within budget without long-term commitments. Meanwhile, others may look for features such as premium data or enhanced add-ons. Designing tailored, cost-effective solutions ensures that customers of all spending levels can find a service or product that fits their budget and lifestyle. Customer needs and preferences can vary greatly by location. In urban areas, customers may seek affordable, high-speed connectivity and seamless 5G coverage in densely populated areas. Rural prepaid customers may focus more on reliable, widespread connectivity and the convenience of accessing products and services in a single trip. By understanding geographic differences, companies can strategically allocate resources to better serve their customers. Customers come from diverse household types. A single professional living in the city might value flexibility, opting for data-heavy plans suited for streaming and social media. A head of household managing a family may prioritize family-friendly plans with shared data, add-a-line options and helpful features like parental controls or device upgrades. Creating solutions that accommodate these varied needs can strengthen your relationships with different customer segments. The rise of the gig economy is reshaping how people work, making flexibility a requirement. We see many of our customers juggling multiple roles and they need wireless plans that can keep up with them. I'm passionate about creating solutions that truly serve these workers, offering flexibility, reliability and the data they need to thrive in the ever-evolving work landscape. Think about how you can better understand this growing demographic's needs and offer solutions. Tailor offerings with customer priorities in mind. Tailoring value propositions to match customer priorities is at the heart of segmentation. Customers today expect solutions tailored to their lifestyles, whether it's affordability, flexibility or premium features. Data plays a critical role in understanding these preferences and companies that leverage customer insights to create targeted, personalized experiences can deliver greater value. For example, before refreshing one of our lead pre-paid brands, we conducted extensive research to identify key customer pain points, such as pricing confusion, data speeds and limited service options. Here are some of the things we learned and the actions we took as a result: Consumers didn't have clarity on the monthly out-of-pocket cost of their plan, so we decided to offer a five-year price guarantee, with taxes and fees included. This provided stability and predictability. Consumers told us they wanted more consistent high-speed data, especially during peak times. So, we offered access to our premium network with priority data, so they could achieve significantly faster speeds than 4G LTE. Consumers reported being offered restricted devices with limited upgrade options. Instead, we offered free 5G phones when customers switched to our 5G plan and gave an anniversary credit toward any new 5G phone after 12 months. Remember that personalization is key to building loyalty. Personalization is a key driver of customer experience and customer loyalty. Digital-first brands need to excel at creating tailored experiences. For example, one of our pre-paid brands thrives in digital channels, offering a fully online experience for customers who value simplicity and autonomy. The all-in-one self-service app lets customers adjust their plans easily to meet current needs. Meeting unique needs in real time helps promote loyalty. Prioritize the customer experience. From product design to communication, every touchpoint must resonate with the target audience. Equally important is creating seamless experiences once customers are onboarded. We've found that features like device financing, timely alerts and flexible options make customers feel valued and understood. Personalization becomes even more powerful when paired with first-contact resolution. By leveraging individualized data and predictive insights, we can deploy smarter tools that address concerns quickly and effectively. Resolving issues on the first try not only minimizes frustration but also builds trust and loyalty. We've seen firsthand how this works: By applying targeted technologies and streamlining processes, we improved our first-contact resolution rate by 13% in just a few months. In the prepaid wireless space, loyalty is earned month by month. Whether it's affordable pricing, flexibility or premium features, tailoring plans to fit a customer's lifestyle increases the chance they'll stick around. Digital tools play a key role here, too. Mobile apps that offer automated troubleshooting, real-time updates and user-friendly interfaces empower customers to manage their accounts on their own terms. Think of segmentation as a strategic imperative. The key is blending data and digital tools with a personal touch. The future of market segmentation is its ability to fuel personalization. By designing products, services and experiences tailored to specific needs, companies can create lasting connections with their customers. We view market segmentation and customer experience as ongoing opportunities to refine how we serve our customers. By keeping their needs at the center of our strategy, we aim to build more authentic connections, deliver better service and create experiences that resonate. Forbes Business Council is the foremost growth and networking organization for business owners and leaders. Do I qualify?

Bayer® Aspirin Introduces Aspirina to the U.S. Pain Market
Bayer® Aspirin Introduces Aspirina to the U.S. Pain Market

Business Wire

time3 hours ago

  • Business Wire

Bayer® Aspirin Introduces Aspirina to the U.S. Pain Market

WHIPPANY, N.J.--(BUSINESS WIRE)--Bayer's Aspirina, the #1 pain relief option in Mexico 1, is now available for purchase in the United States, bringing a well-known brand to the Hispanic community. With a deep commitment to Hispanic consumers, Aspirina is poised to provide an accessible and effective solution for pain relief. Bayer's Aspirina, the #1 pain relief option in Mexico, is now available for purchase in the United States, bringing a well-known brand to the Hispanic community. Share As the Hispanic population in the U.S. continues to grow, currently representing 19 percent of the population and projected to reach 28 percent by 2060, Bayer Aspirin recognizes the importance of connecting with this vibrant community. The Aspirina pain relief option resonates deeply with cultural values and family traditions of those from Mexican and Latin American descent who have been using it as a long-standing pain relief option. 'Many Hispanic communities still face inadequate access to healthcare and consumer goods. As the fastest-growing demographic group in the U.S., the Hispanic population presents a unique opportunity for Bayer. By adding Aspirina to the U.S. portfolio, which has a strong equity in LATAM, we are placing the consumer at the center of our strategy. Data shows that 70 percent of Hispanic consumers feel a strong connection to their country of origin, making it essential for brands to honor and reflect this sentiment,' said Mohamed Atef, Global Brand Lead for Aspirin at Bayer. Many U.S. consumers of Hispanic origin grew up with Bayer's Aspirina— their parents and grandparents relied on it, instilling trust and nostalgia for the brand. Due to those deep connections, Aspirina has a 99 percent awareness rate in Mexico, with 67 percent of consumers using it regularly 2. With this inclusion in the U.S. market, we invite consumers to reconnect with a product that represents reliability, familiarity and their heritage. Bayer invented modern aspirin 125 years ago, and it's the most trusted aspirin brand for pain relief in the U.S. 3 Many pain reliever brands have come and gone over the last century, but Bayer® Aspirin continues to be one of the most trusted pain brands on the market. Aspirina is available at select Walmart and Walgreens, making it easy for families to find the pain relief they know. Join us in celebrating the launch of Aspirina in the U.S. and rediscover a brand that feels like home — a trusted companion in the journey of life. For more information on Aspirina visit About Aspirina For over 125 years, Bayer® Aspirin has been a leading aspirin brand in proven pain relief. Aspirina is a powerful pain reliever and fever reducer that contains 500 mg of the active ingredient aspirin (NSAID*). It provides fast and effective multi-symptom relief of headaches, muscle pain, toothaches, menstrual pain and minor arthritis pain for adults and children over 12, when used as directed. Aspirina is coated to make it easy to swallow and is free of caffeine. *nonsteroidal anti-inflammatory drug About Bayer Bayer is a global enterprise with core competencies in the life science fields of health care and nutrition. In line with its mission, 'Health for all, Hunger for none,' the company's products and services are designed to help people and the planet thrive by supporting efforts to master the major challenges presented by a growing and aging global population. Bayer is committed to driving sustainable development and generating a positive impact with its businesses. At the same time, the Group aims to increase its earning power and create value through innovation and growth. The Bayer brand stands for trust, reliability and quality throughout the world. In fiscal 2023, the Group employed around 100,000 people and had sales of 47.6 billion euros. R&D expenses before special items amounted to 5.8 billion euros. For more information, go to Forward-Looking Statements This release may contain forward-looking statements based on current assumptions and forecasts made by Bayer management. Various known and unknown risks, uncertainties and other factors could lead to material differences between the actual future results, financial situation, development or performance of the company and the estimates given here. These factors include those discussed in Bayer's public reports which are available on the Bayer website at The company assumes no liability whatsoever to update these forward-looking statements or to conform them to future events or developments. 1 Based on volume sales in the last 52 weeks, via source: Grupo Knoblock/CID – Centro Integrador de Datos

Engadget Podcast: How real is Ford's $30,000 EV pickup truck?
Engadget Podcast: How real is Ford's $30,000 EV pickup truck?

Engadget

time3 hours ago

  • Engadget

Engadget Podcast: How real is Ford's $30,000 EV pickup truck?

Ford has big plans for 2027: This week, the American carmaker announced a new "Universal EV Platform" for future electric cars, spearheaded by a $30,000 mid-sized EV pickup. In this episode, we're joined by SAE International Editor Roberto Baldwin to break down all of Ford's claims, as well as where its $5 billion manufacturing investment is going. Can Ford really rebound after slow EV sales and last year's disappointing product delays? Topics Ford has a plan for a 'Universal EV Platform' and a $30,000 mid-size electric pickup, can they pull it off? – 0:49 OpenAI releases GPT-5, the reception so far is mixed – 24:45 NVIDIA and AMD may tithe 15% of their Chinese GPU sales to the U.S. government – 30:18 Goodbye: AOL will phase out dial-up at the end of September – 33:25 AI-powered 'Smarter Siri' likely won't hit iPhones until Spring 2026 – 36:42 Perplexity makes an unsolicited offer to buy Chrome for $34 billion, which is more than the company is worth – 41:03 Listener Mail: Gaming on a MacBook Air – 52:31 Pop culture picks – 59:13 Host: Devindra Hardawar Guest: Roberto Baldwin Producer: Ben Ellman Music: Dale North and Terrence O'Brien If you buy something through a link in this article, we may earn commission.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store