Autonomous adversary emulation · embedded & OT

Find the exploit before you ship it.

Mavka is an autonomous red team for embedded and industrial devices. It attacks your firmware, CAN bus, and protocols like a real adversary — on a faithful twin of the device, with authorization, without touching a live line.

In development · design-partner slots open for embedded & automotive teams.

mavka run — bms-firmware v2.4.1
$ mavka run --target bms-firmware.elf --twin stm32h563 booting firmware on register-accurate twin … ok adversary engaged … fuzzing CAN + Modbus
CRITICAL MAVKA-0007  reproduced ✓ Stack overflow in CAN frame handler → code execution
inject   CAN id 0x18FF50E5, 64B payload overflow can_rx_buf[] +72B @ 0x2000_41a8 overwrite return addr → 0x0800_9c14 execute  attacker thunk (MPU off)
proof  replay: mavka replay MAVKA-0007 · 1,284 cycles note   real on the faithful peripheral model — not a phantom $
Built to prove testing for EU CRA UNECE R155 / R156 ISO / SAE 21434 IEC 62443
The problem

The world runs on devices nobody can safely attack.

You can't red-team a live PLC, an ECU on the bus, or a pump in the field. Probe production OT and things break. So the systems most worth attacking are the ones least tested. Attackers don't play by that rule.

47%
of organizations report unintended operational disruption during OT security assessments. — SANS
19 hrs
line shutdown at a major automotive plant — caused by a consultant running standard vulnerability scanning.
2027
EU Cyber Resilience Act obligations bite. Every connected-device maker must prove security testing happened.
The approach

We attack a faithful twin, not your silicon.

Mavka runs a deterministic, register-level model of your device: firmware, peripherals, and buses. It turns an autonomous adversary loose inside. Real exploit chains, zero risk to hardware. It runs in CI, so every build gets attacked before it reaches a board.

Everyone else's twin lies about crashes. Ours doesn't.
The weak spot of firmware emulation is the phantom crash: a fault that can't happen on real silicon, produced by a peripheral the emulator gets wrong. Mavka runs a faithful register-level model, so a crash it reports is a crash an attacker can reproduce. Proof, not phantoms.
The method

Emulate. Attack. Prove. Repeat.

A closed loop that runs every time your firmware changes — not once a year when a consultant is free.

01

Emulate

Boot your real firmware image on a faithful, register-accurate twin of the target device.

02

Attack

An autonomous adversary probes firmware, CAN frames, and industrial protocols for a way in.

03

Prove

Each finding is a reproducible exploit chain on the twin — with the trace, not a guess.

04

Repeat

It runs in CI on every build. Regression the day it appears, not the year it's audited.

Why it's open

The autonomous attacker exists — just not for your hardware.

A wave of well-funded companies build autonomous pentesters. Every one targets web apps and IT networks. Nobody credible has taken the autonomous adversary down to the firmware and the bus.

Where they play
Where it stops
IT autonomous pentestHorizon3 · XBOW · RunSybil
Web apps and IT networks. No firmware, no CAN, no industrial protocols — a different skill set entirely.
OT defense platformsClaroty · Nozomi · Dragos · Armis
Passive by design — asset discovery and monitoring. They watch; they never attack.
Firmware securityONEKEY · NetRise · Finite State
Static analysis and SBOMs. They read the binary; they don't exploit a running one.
Mavka
Autonomous exploitation at the firmware, CAN-bus, and protocol level — on a faithful twin. The layer none of them reach.
Why now

Regulation just turned security testing into a deadline.

Not a nice-to-have chasing a budget. A requirement with a date on it. And the buyers sit in the industrial and automotive core of Europe.

EU CRA
Obligations for connected products land Dec 2027. Vulnerability handling and testing become mandatory, ongoing, and auditable.
UNECE R155
Documented penetration testing and fuzzing already mandatory for every new vehicle sold in the EU and Japan.
IEC 62443
Increasingly written into industrial procurement contracts — buyers now demand proof, not promises.
Early access

Prove it before an adversary does.

Mavka is in early development with design-partner slots for embedded and automotive security teams. If you ship devices under CRA or R155 pressure, let's talk.

or email hello@mavka.id