NodeZero, from Horizon3.ai, is an autonomous penetration testing platform that safely attacks your live network, cloud, and Active Directory from an assumed-breach position and proves what an attacker could reach. Its tagline is “Security you can prove,” and it runs a Hack, Fix, Verify, Repeat loop.
The platform chains weaknesses the way an intruder would, then hands you proof of exploit rather than a CVSS score. As of July 2026 the homepage counters read 262,224 pentests run in production and 6,436 customers.
That breadth sits entirely on the runtime and infrastructure side. CodeAnt AI is a defensive and offensive security platform that unifies AI code review, SAST, and agentic pen testing, and it is the code-and-app-layer anchor this piece compares against.
TL;DR: NodeZero’s strength is autonomous offense against the live environment. It pentests internal and external networks, cloud, Kubernetes, and Active Directory, drops deception Tripwires, validates your EDR, and ships production-safe exploits for new CVEs within hours.
But, NodeZero has no code security (no SAST, SCA, secrets, or code review), never connects to your repo, and internal tests need a self-hosted host VM that reviewers call a setup chore.
NodeZero Features at a Glance
Here is every core module, what it does, where it runs, and the one limit or plan gate worth knowing first. Each row is drawn from Horizon3.ai’s own product pages and docs, checked July 2026.
Module | What it does | Where it runs | Notable limit or plan gate |
|---|---|---|---|
Internal pentest | Autonomous lateral movement, credential attacks, proof of exploit | Internal network via self-hosted host | Needs NodeZero Host VM or Docker, scheduling needs Core |
External pentest | Attacker’s-eye perimeter test with OSINT asset discovery | SaaS, no host | Asset Groups replaced by Scopes in the 2026.06 rebuild |
Cloud pentest | Privilege escalation and hybrid pivot into AWS and Azure | Cloud accounts | Gray-box, AWS and Azure Entra ID only |
Kubernetes pentest | RBAC misconfig, container escapes, secret exposure | Live clusters via Operators | Managed EKS, GKE, AKS |
AD Password Audit | Cracks weak and breached AD passwords, maps blast radius | Internal via host | Internal test type only |
Rapid Response | Production-safe N-day exploits within hours of disclosure | Internal and external | Pro tier and up |
Tripwires | Honeytoken decoys dropped during pentests | Internal, external, cloud, phishing | Pro tier and up |
Phishing Impact Testing | Tests what a phished credential actually unlocks | Internal via host | Supplements simulated phishing tools |
Endpoint Security Effectiveness | EDR validation via a test remote access tool | Live endpoints | Available at Flex, no EDR vendors named |
Vulnerability Management Hub | Dedups and scores exploitable weaknesses by attack path | Portal | ServiceNow and Jira “coming soon”, 1-Click Verify internal only |
NodeZero Insights | MTTR, trend data, executive reports | Portal | Elite tier only |
MCP Server | Natural-language bridge from your LLM to the NodeZero API | Hosted or self-hosted | Available at Flex |
WebApp Pentest | Runtime OWASP Top 10 and access-control testing | Live app | Early Access waitlist |
Takeaway: every test type and the MCP Server are available even at the entry Flex tier, so Horizon3.ai gates on frequency, detection, and intelligence rather than test volume. Nothing on this list touches source code.
What Features Does NodeZero Actually Include?
NodeZero runs one kind of test across many surfaces. Each test launches a safe, controlled attack and shows you the path an intruder would take. A single portal pulls the findings into deduplicated, impact-scored attack paths with 1-click verification of fixes.
Here is each module the way you meet it after your first pentest, starting with the network tests that anchor the platform.

Internal network pentest
Internal Pentesting is the flagship. NodeZero autonomously discovers and exploits weaknesses inside your network through lateral movement, credential attacks, data mining, security-control bypass, and vulnerability exploitation.
The engine goes far beyond CVEs into misconfigurations and chained weaknesses, then post-exploits with credential dumping and RAT implantation. Every result arrives as proof, so you see the exact path to domain compromise instead of a theoretical score.
External network pentest
External Pentesting shows your organization through an attacker’s eyes with a “Discover, Authorize, Pentest, Repeat” workflow. Passive asset discovery leverages DNS and OSINT to enumerate public-facing systems, and an authorization step controls which of them get tested.
One staleness note from the release notes: the 2026.06 rebuild replaced Asset Groups with reusable Scopes, and the marketing copy still lags that change. Trust the docs over the product page here.
Cloud pentest for AWS and Azure
Cloud Pentesting takes a gray-box approach into AWS and Azure. For AWS, NodeZero enumerates resources to find an opening, then uses privilege escalation and lateral movement. For Azure, it blends native attacks with harvested data to pivot in and out of hybrid environments.
Horizon3.ai claims autonomous escalation to Microsoft Entra ID Global Admin without relying on CVEs. The docs expose an AWS Pentest and an Azure Entra ID test as distinct test types rather than one generic cloud button.
Kubernetes pentest
Kubernetes Pentesting runs against live clusters and hunts RBAC misconfigurations, container escapes, and secret exposures. It deploys inside clusters using Kubernetes Operators and infrastructure-as-code, and chains findings with the underlying infrastructure.
Managed platforms are covered, including AWS EKS, Google GKE, and Azure AKS. Testing happens at runtime against the cluster as it actually runs.
Active Directory testing
Active Directory is where NodeZero earns its reputation, on the premise that “attackers don’t hack in, they log in.” AD Password Audit cracks passwords that are exposed to spraying, stuffing, and cracking using public breach data and OSINT tied to your company, then ranks the riskiest accounts and their blast radius.
The identity story has a detection half too. AD Tripwires plant decoy accounts that look exploitable but stay uncrackable, and they fire on credential abuse like Kerberos ticket harvesting and AS-REP roasting.
Rapid response for emerging threats
Rapid Response answers a specific fear. Attackers weaponize exploits in hours, while patch cycles still run weeks. The Horizon3 attack team builds production-safe exploits for fresh CVEs and KEVs, often within hours of disclosure, so you get proof of exploitability rather than a version check.
As Horizon3.ai puts it, “exploitability is confirmed or ruled out with evidence, not vendor advisories or CVSS scores from vulnerability scanners that just check versions.” Recent 2026 coverage spans Esri ArcGIS Server, Adobe ColdFusion, SimpleHelp, and Apache ActiveMQ. Rapid Response starts at the Pro tier.

Tripwires and deception
NodeZero Tripwires turn pentest findings into defense by dropping expert-designed decoys as the engine discovers critical risk. The decoys and monitoring files behave as honeytokens, staying silent until an attacker touches them, then firing an immediate alert.
Placement is automatic on your crown-jewel assets, and one-click activation works inside internal, external, AWS, phishing, insider-threat, or Rapid Response tests. Alerts flow into your SIEM and SOAR through Splunk and Microsoft Sentinel webhooks.
Phishing impact testing
Phishing Impact Testing answers what actually happens after an employee gets phished. Rather than measuring click rates, NodeZero captures the phished credential and then tests what an attacker could do with it through lateral movement, privilege escalation, and data access.
Horizon3.ai frames it as “Beyond Simulation: Proven Impacts,” and positions it to supplement your existing simulated-phishing tool. The output is the reachable blast radius, not a training score.
Endpoint security effectiveness
Endpoint Security Effectiveness validates whether your EDR earns its budget. NodeZero deploys a test remote access tool, simulates attacker behavior in the live environment, and reports whether the EDR blocked, alerted, or missed the activity.
CEO Snehal Antani is blunt about why, noting that “our research shows that credential-based attacks can bypass EDRs in minutes, often undetected.” Every customer gets the feature, including the Flex tier, though Horizon3.ai names no specific EDR vendors.
Vulnerability management hub
The Vulnerability Management Hub centralizes weaknesses found across internal, external, cloud, and identity tests under the line “where exposure meets action.” Findings are deduplicated, scored by likely impact, and tied directly to the attack paths that make them dangerous.
Two caveats sit on the page itself. ServiceNow and Jira integration are marked “coming soon,” and 1-Click Verify is supported for internal environments only, with external support on the roadmap.
NodeZero Insights
NodeZero Insights is the executive layer, giving organization-wide trend data so a leader can prioritize and prove impact. It aggregates mean-time-to-remediation, open weaknesses and attack paths over time, weakness age, and pentest-series trends.
Insights is Elite-tier only, which places board-level reporting at the top of the four-tier ladder. Everything below it can run the tests but cannot roll the results into a strategic report.
The AI architecture and MCP server
NodeZero’s AI rests on graph-based reasoning, deterministic logic, and scoped GenAI across multiple cooperating agents such as the Exploit Suggester, High-Value Targeting, and Advanced Data Pilfering. Horizon3.ai is explicit that “NodeZero doesn’t train foundation models,” and instead builds structured prompts from live data and runs inference against models like Claude, LLaMA, or Mistral.
The NodeZero MCP Server extends that reasoning to your own agents. It acts as a natural-language bridge between your LLM and the NodeZero API, letting you launch pentests and query asset and vulnerability data from an assistant, in either a Horizon3-hosted mode with OAuth 2.1 or a self-hosted single-user mode.
Deployment and the NodeZero host
External and cloud tests run as pure SaaS with nothing to install. Internal, Kubernetes, AD, phishing, and insider-threat tests, though, need a self-hosted NodeZero Host, delivered as a preconfigured VM appliance, an Ubuntu setup script, or a manual install running Docker or Podman.
Plan for meaningful resources, 2 cores and 8 GB RAM at minimum, 4 cores and 16 GB recommended, scaling further past 5,000 assets. A NodeZero Runner on that host then picks up scheduled pentests from the portal automatically.
What’s Good About NodeZero’s Feature Set?
The proof-of-exploit model is the strongest part. NodeZero shows the actual chained path to a domain takeover or data-exposure event, so you triage what an attacker can truly reach instead of a wall of unranked CVEs.
Autonomy and coverage back that up. One platform runs internal, external, cloud, Kubernetes, and Active Directory attacks unlimited times, and the 1-click verify loop confirms a fix worked without booking another engagement.
Reviewers echo the value on live infrastructure. Fabian Brandt, in a 5-star PeerSpot review (July 2026), highlights the proof NodeZero delivers, and one G2 reviewer notes it “shows what’s actually exploitable in my setup” rather than staying theoretical.
Accessibility lands too. Horizon3.ai pitches that NodeZero “gives these small teams the ability to act as a 20-year pentester with just three clicks,” and a G2 reviewer confirms “you don’t need to be a pen tester to run a test.”
Where Are the Limits?
None of this is a knock on the product. Each point below is the documented reality of what NodeZero does not do, and the pattern is that the entire shift-left, code-security half of security sits out of scope.
The structural miss is code. NodeZero has no SAST, no SCA, no secret scanning, and no code review, and it never connects to your repository, which is fine right up until the exploitable bug lives in your own source. Horizon3.ai’s packaging matrix carries zero code-related rows, and GitHub appears only as a destination for remediation tickets.
Its application testing is runtime-only and still early. WebApp Pentest tests the running app for OWASP Top 10 and access-control flaws, reads none of the source behind it, and remains gated behind an Early Access waitlist as of July 2026.
Internal deployment is a genuine friction point. Because internal tests need that self-hosted host, one G2 reviewer wrote that “from a deployment standpoint, NodeZero is a dumpster fire” that “requires a full Linux VM or a dedicated machine with no one-click deploy option.”
Cost and yield draw honest criticism at scale. Karrie Westmoreland, a Sr. Security Engineer, left a 3-star PeerSpot review (July 2026) citing out-of-scope results and a wish for web-app testing, and separately noted a “high cost for low-yield real attacks” that led her not to renew.
Integrations stay thin. The ServiceNow and Jira connectors that would close the loop into your ticketing are marked “coming soon” on the Vulnerability Management Hub, and external 1-Click Verify is still on the roadmap.
How Do NodeZero’s Features Compare to CodeAnt AI?
The two platforms barely overlap. NodeZero owns the network, infrastructure, identity, and threat-detection layer, and CodeAnt AI owns the code and application layer with a free way to begin.
Where NodeZero reads none of your source, CodeAnt AI’s pentest is code-aware and reads it in black, white, and grey box modes to surface authorization and logic flaws a network attack cannot see. CodeAnt also folds in SAST, SCA, secrets, and IaC, plus AI code review and DORA delivery metrics, none of which NodeZero offers.

Here is where each platform’s coverage falls, feature area by feature area.
Capability area | CodeAnt AI | NodeZero |
|---|---|---|
Network, infra, AD, cloud, and K8s pentest | Not offered | Yes, autonomous from an assumed breach |
Code-aware pentest that reads source | Yes, black, white, grey box, free first scan | No, runtime black-box only |
SAST, SCA, secrets, IaC | Yes, one unified report | Not offered |
AI code review | Yes, unlimited PR reviews and custom rules | Not offered |
Engineering and DORA delivery metrics | Yes, dedicated pillar | Not offered |
Threat coverage (Tripwires, Rapid Response, EDR validation) | Not offered | Yes |
Free start | Yes, free black-box scan, pay only on high or critical | No, demo-gated, 30-day trial then read-only |
Takeaway: reach for NodeZero when you need proof of how far an intruder moves across your live network, identity, and cloud. Lead with CodeAnt AI when the code you ship, the app it becomes, and the metrics around it should carry security in the developer workflow. The full head-to-head lives in the CodeAnt AI vs NodeZero breakdown.
Where This Leaves You
NodeZero’s feature set is a deep, autonomous offense engine for everything you run, strongest when you need evidence that your network, Active Directory, and cloud hold up against an actual attacker. The honest caveats are the missing code security, the Early Access web-app test, and the self-hosted host that internal testing demands.
The two tools are complementary, and the practical move is to pick by layer. For pricing detail, read the NodeZero pricing breakdown, and for other options, see the NodeZero alternatives roundup. If the code and app layer is what you need to cover, CodeAnt AI is the one you can evaluate for free today.


