ATK New Technology · Hanoi, Vietnam

Three products.
One question.

Does your security actually do what you assume it does? We build the instruments that answer that — with a measured number, not an opinion.

Run Wazuh? Rule Doctor Lite is free: one read-only Python file that lists the custom rules that never fired, and why — including the ones Wazuh drops at load.

Bench run · out-of-the-box build
24/24 replayed 3 detected 21 silent

This is a real measurement, not an illustration. Read the full report — method, every technique, and what the number does not mean.

All research →  —  six measurements, method and limits in the body, raw data published.

3 / 24
Attack techniques an out-of-the-box SIEM caught on our bench. The other twenty-one were silent.
0–8 s
Measured time to alert for the same technique across Wazuh, Splunk and IBM QRadar.
99.2%
Of VRadar's response decisions are deterministic rules. A language model is the exception, not the engine.
702
Automated tests standing behind VPQ Audit Enterprise.
Registered company

ATK New Technology One Member Company Limited, Hanoi · Tax ID 0110935486

Open source you can read

Rule Doctor Lite on GitHub and PyPI, Apache-2.0

Methods published

Every measurement is published with its method and limits; the research reports include the raw data

Plain terms

PayPal or bank transfer, ATK invoice, written refund policy

Available now · for Wazuh 4.x

Rule Doctor finds the Wazuh rules that never fire.

Including the ones Wazuh throws away while loading them — the config check exits 0, the manager starts, and the rule is gone. Lite is free, read-only, one Python file; a written review is USD 49; a fix is USD 490, paid after it works.

pipx install rule-doctor-liteApache-2.0measured on 4.14.7
Why a rule that passes every check never firesvideo · 3 min 24 s · captions
Approach

Most tools report
their configuration.
We report what happened.

Security spending is justified with artefacts that describe intent. A rule exists. A control is enabled. A policy is signed. None of those are evidence that anything fired when it mattered.

A rule that exists

is not a rule that fires. Detection content is written once and then inherited, edited and quietly broken. The only honest way to know is to replay the technique and time the alert.

An asset inventory

is not an inventory of what crossed the wire. Certificates, key exchanges and cipher suites live in traffic and configuration drift, not in a spreadsheet someone maintained last year.

An escalated alert

is not a closed incident. Anything that ends in a queue nobody drains at 3am is a metric about your process, not about your attacker.

Assumed is not measured. Everything we build exists to close that gap for one specific question.


What we build

Three instruments, three questions.


Research

Six measurements, published in full.

Every number we sell on is one we ran ourselves. Method, sample and limits are in the body of each report rather than in a footnote, and the raw output is published rather than available on request — so anyone can recompute a figure, or contradict it.


Why ATK

Six things most of this industry cannot do.

Every line below is a capability we built and can demonstrate today, not a roadmap item. The numbers come from our own bench and telemetry.

01 · Measurement

Three SIEMs, one clock

The same technique, replayed once, timed natively on Wazuh, Splunk and IBM QRadar. Most breach-simulation tools integrate deeply with one platform and estimate the rest — which makes the comparison worthless precisely when a buyer needs it.

We ship an estimating mode as well, for stacks we are not connected to yet. So we measured it against our own lab on 21 September 2026: across 34 techniques, each one actually executed, the estimating mode made exactly one positive claim — and that claim was wrong, while the live SIEM detected 14. Estimated figures are labelled in the product, carry no detection time, and are never called a measurement. We publish that number because a vendor who cannot state the error of its own instrument is not measuring anything.

0–2 s · ~4 s · 4–8 s
02 · Fidelity

The attack actually executes

Brute force, lateral movement, ransomware behaviour and command-and-control run for real against a twin of the stack. Nothing is injected into a log pipeline, so a rule that only matches a hand-written test event is exposed rather than flattered.

84 techniques · 75 scenarios · 84 Sigma rules
03 · Model

The estate is a graph, not a list

Hosts, identities, zones and trust relationships are held in a property graph, so we can rank choke points by blast radius. Remediation follows the paths an attacker can actually walk, not the order a scanner happened to print.

Attack-path ranking on a live twin
04 · Autonomy

Deterministic first, model last

In VRadar, 99.2% of response decisions are taken by rules that produce the same answer every time and cost nothing per decision. A language model handles the 0.8% remainder. Autonomy you cannot reproduce is not autonomy, it is a demo.

99.2% deterministic · $0 per decision
05 · Safety

It fails closed, and we can prove it

226 incidents were closed automatically only after verifying the originating condition was gone — 42 uncertain cases were held for a human instead. Against prompt injection, provenance-bound gating on the actuator took successful hijacks from 3 in 8 to 0 in 8.

226 auto-closed · 42 held · 0/8 hijacked
06 · Cryptography

Read off the wire, not off a spreadsheet

Handshakes parsed from capture, trust hierarchies rebuilt root to leaf, and harvest-now-decrypt-later risk scored as vulnerability × sensitivity × retention × exposure. Ranking migration impact across a PKI tree is the step most of the post-quantum market has skipped.

V × S × R × E · CBOM CycloneDX 1.7

The mark is three strokes, each rising past the last — one for every instrument we build. We publish figures that can be reproduced, state the status of each product plainly, and say what it does not do. A claim that ages badly costs more than the deal it wins.

Where we actually are

VRadar runs in production with paying users. VCyber Twin and VPQ Audit are in pilot, and their pages say so. Every figure on this site comes from our own bench or our own telemetry — we do not borrow a customer's logo we are not allowed to name, and we do not quote an analyst who has never run our software. If something here cannot be reproduced, write to us and it comes down.


Company

Engineering-first,
founder-led.

Legal entity

ATK New Technology One Member Company Limited · Xuân Đỉnh, Hanoi, Vietnam · Tax ID 0110935486

How we work

Asynchronously, by design. Everything we sell can be scoped, evaluated and delivered over email — nothing to sit through first, no procurement theatre. You should be able to judge the work by the artefact rather than by how well someone presents it.

Who we build for

Managed security providers and consultancies who have to prove their service is worth more than the stack it runs on; banks, government and critical infrastructure who have to prove the same thing to a regulator.


Talk to the person who built it.

There is no sales team to route you through. It goes straight to the founder, and the reply comes back with the technical detail already in it — usually within a working day.