Water utilities: Practical cyberattack response guidance for SCADA and PLC environments. Read the Guide →
CrunchAtlas
AtlasCyber Detection, investigation, campaign intelligence, and reporting in one operating platform. ClemAI The built-in cyber professional for investigation, hunting, forensics, attribution, and reporting. PurpleHaze Operator-controlled validation that proves approved attack paths and retests the fix.
Network Detection & Response Turn network activity into investigated cases and evidence. Alert Investigation Move alerts to evidence-backed verdicts without rebuilding the case manually. Threat Hunting Hunt across network evidence for behavior that alerts didn't explain. Host & Network Forensics Reconstruct what happened, what moved, and how far it spread. Campaign Intelligence Connect related cases into one evidence-backed campaign assessment. Incident Reporting Build the decision-ready incident record directly from the investigation. Agentic Penetration Testing Validate approved exposure, document the path, and retest the fix.
Industries
Water & Wastewater Security investigation and evidence workflows built for utility operations. Power & Energy Passive visibility, investigation, and evidence for grid environments. Municipal Government Cyber defense for small public-sector teams supporting essential services. Manufacturing Investigation and validation across connected industrial environments. Education Cybersecurity coverage for distributed education environments and lean teams. MSPs & MSSPs Investigation, reporting, and validation across customer environments.
Resources
What Is OT Security? Operational technology security across industrial systems, networks, access, and response. What Is Network Detection & Response? What NDR sees, how it works, and where network evidence fits into investigation. Water Cyberattack Response Guide Practical response guidance for SCADA and PLC environments. Small Water System Cybersecurity How operators, IT providers, integrators, and vendors divide cybersecurity responsibility. Vulnerability Scan vs OT Assessment Where a scan stops and a broader OT security assessment begins. NERC CIP-015 Plain-English guidance on INSM requirements, evidence, and implementation. Education Infrastructure Resilience Visibility and investigation across distributed university environments. University Third-Party Cyber Risk What to investigate when a connected vendor or service provider is breached. Insights CrunchAtlas research, incident analysis, and operator guidance.
Careers Contact
Request Access
0
Skip to Content
CrunchAtlas
Home
ClemAI
PurpleHaze
AtlasCyber
Agentic Penetration Testing
Alert Investigation
Campaign Intelligence and Attribution
Host Network Forensics
Incident Reporting
Network Detection and Response
Threat Hunting
Industry Library
Manufacturing
Municipal Government
Education
Water and Waste Water
Power and Energy
Resources
CIP-015
Water System Cyberattack Response Guide
Education Resilience
Vulnerability Scan vs OT Security Assessment
Small Water Systems
University Third-Party Cyber Risk
What is Network Detection and Response
What is OT Security?
MSP MSSP
Apply to Join the CrunchAtlas Network
Careers
Apply
CrunchAtlas
Home
ClemAI
PurpleHaze
AtlasCyber
Agentic Penetration Testing
Alert Investigation
Campaign Intelligence and Attribution
Host Network Forensics
Incident Reporting
Network Detection and Response
Threat Hunting
Industry Library
Manufacturing
Municipal Government
Education
Water and Waste Water
Power and Energy
Resources
CIP-015
Water System Cyberattack Response Guide
Education Resilience
Vulnerability Scan vs OT Security Assessment
Small Water Systems
University Third-Party Cyber Risk
What is Network Detection and Response
What is OT Security?
MSP MSSP
Apply to Join the CrunchAtlas Network
Careers
Apply
Home
Folder: Product
Back
ClemAI
PurpleHaze
AtlasCyber
Agentic Penetration Testing
Alert Investigation
Campaign Intelligence and Attribution
Host Network Forensics
Incident Reporting
Network Detection and Response
Threat Hunting
Folder: Industries
Back
Industry Library
Manufacturing
Municipal Government
Education
Water and Waste Water
Power and Energy
Folder: Resources
Back
Resources
CIP-015
Water System Cyberattack Response Guide
Education Resilience
Vulnerability Scan vs OT Security Assessment
Small Water Systems
University Third-Party Cyber Risk
What is Network Detection and Response
What is OT Security?
Folder: Partners
Back
MSP MSSP
Apply to Join the CrunchAtlas Network
Folder: Careers
Back
Careers
Apply
Home / PurpleHaze

PurpleHazeAgentic Validation

Start from a finding, exposure, or fix. Get a direct answer: proven, blocked, or closed.

Request a Demo

Nothing runs without an authorized operator starting it. IT scope only. OT is never a target.

Validation Details

Search validation runs...
Operator initiated
✓ Approved path reached the protected target. PATH PROVEN
Validated
Approved entry Identity control Internal service Protected target Blocked branch
Key: Entry Proven step Target reached Blocked
Path Proof
Operator controlled
Validation result

The approved entry point can reach the protected target.

The approved route was proven. An alternate path was blocked by an existing control.

Primary pathEntry to target
PROVEN
Alternate branchControl enforced
BLOCKED
Operator output

Remediation guidance and the same repeatable path are ready for retesting after the fix.

PurpleHaze proves the approved route and shows what existing controls stopped.

Partners & Programs

Department of War
Danvers Electric
NEUCIC
NVIDIA Inception Program
MissionLink
Carahsoft
Unravl
InventWood

Possible isn't the same as proven.

Scanners show possibility. PurpleHaze tests what's actually reachable.

01

A finding doesn't show the path.

A finding shows exposure, not impact.

A list isn't a path
02

Yesterday's answer doesn't hold.

Every change can open a new path.

Valid on the day it shipped
03

A ticket can hide an open path.

A closed ticket doesn't prove the path is closed.

Closed isn't the same as fixed

How a security question gets a verified answer

One cycle from question to proven result and retest.

01

Initiate

An operator sets the question, systems, window, and limits.

02

Validate

Test the approved path. Separate reachable exposure from controls that hold.

03

Report

Get the result, evidence, and remediation direction.

04

Retest

Retest after the fix: blocked, reduced, or still open.

One validation capability. Four security jobs.

One validation layer across testing, investigations, exposure, and remediation.

Solution

Agentic Penetration Testing

Validate approved IT scope and leave with a retest plan.

Explore the solution
Capability

Attack Path Validation

See whether separate weaknesses form a real attack path.

See path validation
Capability

Investigation Validation

Test whether an AtlasCyber finding is reachable.

See connected findings
Capability

Remediation Verification

Retest the same path after remediation.

See remediation retesting

Prove the result, not just the condition.

Reachable. Blocked. Impact. Fix.

  • Starting condition confirmed.
  • Path to impact tested.
  • Evidence and remediation attached.
Approved SOURCE Reachable CONTROL Protected TARGET
Path proven

The approved route reached material impact.

Get the proven path, evidence, remediation direction, and retest.

Starting condition confirmed
Reachability established
Operational impact proven
Retest path prepared

Every result returns to the operation.

Each validation records the question, scope, result, evidence, response, and retest.

  • Validated impact
  • Evidence attached
  • Remediation and retest
  • Linked AtlasCyber case
CrunchAtlas PurpleHaze validation record

Approved path reached the protected service

Question, scope, result, and next action ready for review.

Validated finding

Proven outcome

Recommended response

Evidence

Supporting proof attached

Review the evidence behind the result.

Response

Next change identified

Remediation direction stays with the record.

Retest ready

Same question preserved

Retest the same path after the change.

A closed ticket isn't a closed path.

Retest after remediation: closed, reduced, or still open.

  • Repeat the approved path
  • Keep the same scope
  • Test reachability again
  • Record the result
Before remediation

Path reached the protected target.

Path and impact proved. Evidence preserved.

PathOpen
ImpactProven
After remediation

The same path could no longer complete.

Retest confirmed the path was closed.

PathClosed
StatusVerified

Nothing runs that you didn't authorize

Scope, timing, and authority are set before every run.

01

You define the boundary

Set targets, timing, and limits first.

02

You start the run

An authorized person starts every run.

03

You approve the consequence

Findings and production actions require review.

A test ages the day it ships.

The environment changes. Retest the fix.

29 min

average eCrime breakout time. Source

63%

of daily security alerts go uninvestigated. Source

90%+

faster detection to action. Based on internal testing.

MITRE ATT&CK mapped NIST CSF aligned IT and OT Operator approval required Cloud · On-prem · Air-gapped
Request a Demo

Validation connected to the wider defense operation.

AtlasCyber finds and investigates. ClemAI does the work. PurpleHaze retests the approved path.

Inputs

Existing security tools
CrunchSense
PCAP / NetFlow / Zeek

AtlasCyber

Agentic Threat Intelligence

Detect
Investigate
Threat hunt
Campaign intelligence
Report and response guidance
ClemAI engine embedded throughout

Operator review

The team controls the action.

Review findings and consequential actions.

PurpleHaze

Validate the exposure.

Prove the path. Fix it. Prove the fix held.

Cloud On-premises Air-gapped
Platform

AtlasCyber · Agentic Threat Intelligence

Turn security data into investigated cases and campaigns.

Explore AtlasCyber
Intelligence engine

ClemAI · The Built-In Cyber Professional

Drives each validation from evidence to report.

Meet ClemAI

Prove what's exposed. Verify what changed.

Turn a security question into a proven answer.

Request a Demo

sales@crunchatlas.com

(603) 858-1197

Security Policy

Privacy Policy

Terms of Service

CrunchAtlas

Advanced detection, investigation, and validation for the most critical environments.

For Operators. By Operators. LinkedIn →

Platform

AtlasCyber ClemAI PurpleHaze

Solutions

Network Detection & Response Alert Investigation Threat Hunting Host & Network Forensics Campaign Intelligence Incident Reporting Agentic Penetration Testing

Industries

Water & Wastewater Power & Energy Municipal Government Manufacturing Education MSPs & MSSPs

Resources

What Is OT Security? What Is NDR? Water Cyberattack Response Small Water Systems OT Security Assessment Guide NERC CIP-015 Education Resilience University Third-Party Cyber Risk Insights

Company

Careers Contact sales@crunchatlas.com (603) 858-1197 707 Milford Road
Merrimack, NH 03054
United States
crunchatlas.com Request Access
© 2026 CrunchAtlas Inc. All rights reserved.
Privacy Policy Terms of Service Security Policy