Skip to main content

Campaign Box Types

Cybrium campaigns ship in five distinct box types. The box type you pick tells the AI planner what it already knows, how aggressive it is allowed to be, and which tactic categories are eligible to be chained into the campaign plan. Picking the right box type is the single most important decision you'll make before launch.

Screenshot: Box type selector with five campaign tiles

Black Box

Zero prior knowledge. The planner starts with nothing but a target (a domain, an IP range, or a cloud tenant ID) and has to build its entire picture from public sources and unauthenticated probes. This is the most realistic simulation of an external attacker and the best choice when you want to measure what a determined stranger could discover and exploit.

White Box

Full visibility. You provide credentials, source code, configuration files, architecture diagrams, and cloud access. The planner skips time-consuming reconnaissance and drives straight at the highest-impact weaknesses. Pick this when you need deep coverage in a short window — compliance audits, pre-release reviews, and assumed-breach exercises.

Grey Box

The middle ground, and the most common choice for ongoing programs. You provide partial information — a list of in-scope assets, a low-privilege user account, an internal network diagram — and the engine fills in the rest. Grey Box gives realistic adversary behavior with the efficiency of a guided test.

Red Box

Offensive with persistence. A superset of Black Box that includes post-exploitation objectives: establishing footholds, harvesting credentials at scale, moving laterally across trust boundaries, and simulating data exfiltration. Red Box requires explicit authorization for persistence techniques and is Plan-gated.

Plan-gated

Red Box campaigns require the Pro or Enterprise plan.

Blue Box

Defensive emulation. Instead of maximizing impact, the engine executes controlled, noisy versions of known tactics so your SOC, SIEM, and EDR can be measured on what they detect and how fast they respond. Every step emits a deterministic signature so you can correlate against alerts after the run.

Choosing

Start with Grey Box for a new program, rotate to Black Box quarterly to re-baseline external exposure, and schedule Blue Box before every detection-engineering sprint.