SCENARIO LIBRARY · OBJECTIVE PACKS

Curated validation scenarios mapped to real security outcomes

Every scenario carries its own contract: the telemetry it needs, the safety metadata that bounds it, and the evidence it is required to produce.

SAFETY-METADATA REQUIREDEVIDENCE CONTRACTS
1,000+
Governed scenarios
and growing
9
Objective packs
exposure → AI
6
Validation modes
exposure, control, detection, runtime, path, pentest
PRODUCT · SCENARIO EXPLORER

Filter 1,000+ scenarios in seconds.

By objective, asset, technology, validation method, safety level, telemetry, control, framework, or business outcome.

app.hayrok.io / scenario-library
LIVE
HAYROK
Overview
Scenarios 1,000+
Objective packs 9
Runs
Policy
Scenario library
1,000+ governed scenarios across 9 objective packs
ransomware
Kubernetes Identity Cloud WAF API Detection
RANSOMWARE HIGH
Initial access via macro-enabled document
EDRSIEMEmail
22 artifacts RUN →
RANSOMWARE HIGH
Segmentation validation · finance → backup
FirewallCloud
14 artifacts RUN →
RANSOMWARE MED
Backup protection & immutability probe
BackupIAM
9 artifacts RUN →
IDENTITY CRIT
Service-account privilege escalation
IAMCloudSIEM
31 artifacts RUN →
API HIGH
BOLA · access to another tenant record
API GWWAF
12 artifacts RUN →
DETECTION MED
Living-off-the-land binary invocation
EDRSIEM
18 artifacts RUN →
SCENARIO ANATOMY

Every scenario carries its own contract.

Target assets. Telemetry. Safety. Evidence. Success criteria. Nothing runs without them.

Objective packs
Group scenarios around a desired outcome — ransomware readiness, identity, API, cloud, detection, K8s, supply chain, AI.
Scenario groups
Organized by asset, attack objective, technology, control, business service, telemetry, and validation method.
Safety metadata
Execution classification, approved environments, expected impact, tool restrictions, blast radius, cleanup.
Telemetry requirements
SIEM, EDR, WAF, cloud audit, identity events, API logs, K8s audit, runtime metrics.
Validation modes
Exposure, control, detection, runtime presence, reachability, attack path simulation, autonomous pentest.
Evidence contracts
Required artifacts, expected control and detection behavior, success criteria, revalidation evidence.
IN PRACTICE

Real scenarios teams validate today.

Concrete outcomes — not abstractions. Every scenario ships with telemetry, safety, and evidence contracts.

AI SECURITY
Prompt-injection through indirect content
Validate whether an LLM assistant can be steered by untrusted content in a retrieved document. Confirm safety controls.
LLMGuardrails
Outcome Blocked
KUBERNETES
Pod escape to node · RBAC + admission
Test whether a compromised container can escape to the node, bypass admission policy, and reach the API server.
K8sRBAC
Outcome Contained
SUPPLY CHAIN
Malicious dependency in build pipeline
Introduce a governed benign payload in a build to validate SCA gate, signing, and rollback controls.
CI/CDSCA
Outcome Detected
"
The library replaced our internal spreadsheet of red team ideas. Every scenario is scoped, safe, and evidence-backed by default.
MD
Marc Delacroix
Head of Offensive Security · Fortune 500 · Insurance
BY THE NUMBERS

Enterprise-grade scenario coverage

The Hayrok Scenario Library ships hundreds of curated scenarios with preconditions, safety classes, evidence contracts, and success criteria — validated by the Hayrok research team.

SCENARIOS SHIPPED
340+
curated · versioned · safety-classed
CATEGORIES COVERED
9
API · Identity · Cloud · K8s · Ransomware …
NEW SCENARIOS / QUARTER
40+
from research team + customer requests
CUSTOM SCENARIOS AUTHORED
120+
co-authored with customers
PROGRAM LEADERS ON THE SCENARIO LIBRARY

Program leaders on the Scenario Library

"Every scenario ships with the safety class, evidence contract, and success criteria we would have written ourselves. It replaced months of internal red-team engineering."
LZ
Lian Zhao
Head of Offensive Security · Atlas.FI Retail
"Production-safe classification and step-up approval on destructive scenarios is the level of scenario governance we could not build in-house."
HB
Håkon Berg
VP Threat & Vulnerability · Nexpro
"The Hayrok research team co-authors scenarios with us — we shipped a bespoke insider-threat validation in ten days that we would have never scoped alone."
AR
Aisha Rahim
CISO · Atlas.FI
ENTERPRISE-READY BY DEFAULT

Scenario coverage across the industries Hayrok serves — from PCI-critical payments to OT-adjacent manufacturing.

Visit the Security & Trust Center
COMPLIANCE
Audit-ready programs
SOC 2 · ISO 27001 · GDPR · CCPA · HIPAA-friendly · PCI-DSS-aligned
IDENTITY
Enterprise SSO & SCIM
OIDC · SAML · SCIM · IdP federation · MFA policy
DEPLOYMENT
Regional data residency
US · EU · UK · Private Runner in customer VPC · CMK options
SECURITY
Encryption everywhere
TLS 1.3 · AES-256 at rest · Managed secrets · CMK options
ENTERPRISE ROLLOUT

Priority scenarios selected in week one; safety-class review by GRC in week two.

A dedicated Enterprise Deployment team runs a repeatable playbook — security review, tenant setup, integrations, scoped pilot, and executive readout.

WEEK 1
Coverage review
Identify priority scenarios per objective in scope.
WEEK 2
Safety-class alignment
GRC signs off on scenario safety classifications.
WEEK 3
Scenario pilot
Selected scenarios executed in scoped pilot.
WEEK 4
Custom authoring
Co-authoring session with Hayrok research team for bespoke scenarios.
ENTERPRISE FAQ

Questions we hear from Fortune 500 buyers

Can we co-author scenarios with the Hayrok research team?+
Yes. Enterprise plans include a co-authoring engagement — from threat model to safety class to production rollout.
How frequently is the library updated?+
New scenarios ship on a monthly cadence, with rapid-response scenarios released within days of critical industry events.
Can scenarios be scoped to a single tenant?+
Yes. Scenarios can be enabled, restricted, or hidden per tenant, environment, and role.
What documentation accompanies each scenario?+
Every scenario ships with preconditions, methods, safety class, telemetry requirements, evidence contract, and success criteria.

Validate outcomes, not tickets.

Explore the scenario library preview and see how governed scenarios map to your security objectives.