Simulations
Run tabletops, drills, and red/purple-team exercises. Red-team engagements go live only after a leader authorises the Rules of Engagement with a step-up sign-off.
The cyber coordination platform that runs your incident response, threat hunting and exposure management on one operator-first platform — methodology built in, every handoff tracked end to end.
Pick a playbook, walk it across your affected assets, promote to a case the moment it earns one.
Founding offer · 33% off · 25 seats
The methodology your team already trusts — built in, not bolted on
You already have alerting, EDR, SIEM and ticketing. What you don’t have is one place where the work is coordinated — where a hunch becomes a hypothesis, a finding becomes an exposure or an incident, and an incident is walked to closure with the evidence, decisions and regulator clocks in one record. Today that lives in people’s heads, spreadsheets and a dozen chat threads. That’s where things get dropped.
Cyber Toolbox is the coordination layer. It sits above your stack and runs the operation — the playbook, the walk, the handoff, the case, the audit trail.
Pick an IR playbook and walk it asset by asset — each step guided, with the runbook, decisions and evidence inline. Promote to a managed case the moment it earns one: severity engine, decision log, dual control, evidence chain-of-custody, regulator clocks.
See how it worksExposure Response · CTEMContinuous Threat Exposure Management as a guided loop: scope, discover, validate exploitability, band the severity (ES1–ES5), and drive remediation to closure against an SLA clock. Every exposure lands in a register with an owner and a deadline.
See how it worksThreat HuntingBuild a testable ABLE hypothesis, tag it to MITRE ATT&CK, and keep facts separate from judgements. The payoff is a peer-reviewed threat summary and a durable Sigma detection — so the same threat cannot walk in unseen twice.
See how it worksThey share one asset register and one playbook engine, with cross-lifecycle lineage: a hunt finding can become an exposure, an exposure can spawn an IR walk, and an IR walk can be promoted to a case and declared an incident — traceable end to end.
Beyond hunt, respond and expose, Cyber Toolbox carries the surrounding work the cyber team actually owns.
Run tabletops, drills, and red/purple-team exercises. Red-team engagements go live only after a leader authorises the Rules of Engagement with a step-up sign-off.
Every action item the cyber team owns — from a case, a hunt, an exposure or an exercise — tracked to closure in one place with an owner and a due date.
The cyber leader’s surface: maturity assessments with trend, capability uplift programmes, team competency coverage against ATT&CK exposure, and high-consequence authorisations.
An intelligence layer on cases — priority intelligence requirements, IOC pivots and finished-intelligence packaging, feeding tippers straight into scoped hunts.
It sits above your EDR and SIEM and runs the operation — the playbook, the walk, the handoff, the case. The handoff is the product.
ABLE hypotheses, facts-vs-judgements, CTEM severity bands, the Pyramid of Pain, MITRE ATT&CK, structured IR phases — the discipline is on rails, not in a PDF nobody opens mid-incident.
Hunt, respond and manage exposure on shared assets and playbooks, with lineage you can trace end to end in a couple of clicks.
Built by responders for responders — keyboard-driven walks, runbooks inline, vendor-neutral, no fluff. Fast where speed matters.
SMBs & solo operators
Cyber Toolbox gives that person the playbook and the record. No big stack required, guided walks, nothing dropped.
Lean in-house teams
Hunt, respond and manage exposure in one place — methodology built in, CTI and detections, and ATT&CK coverage you can see.
Security leaders
Active hunts, exposures by severity band with SLA burn-down, cases by phase with regulator clocks at risk, and team maturity over time — at a glance.
Community is free for a single operator. Pro is one flat price per workspace — not per seat — that bundles the whole platform, in NZD. The first 25 founding workspaces lock Pro at NZ$980/year (33% off) before launch. We’re here to serve the security community, not to meter it.
SMBs, solo operators, anyone trying it
Walk the free playbook library against your own assets. No card — prove the methodology on a real incident before you commit.
33% off · save NZ$490 · 2-year price lock
9 of 25 seats claimed
In-house teams, MSPs & security leaders
Everything Cyber Toolbox does, in one tier — incident response, exposure, hunting, simulations, CTI, the Command Centre and API. One flat price for your whole team.
Larger teams & regulated programmes
Everything in Pro, delivered on a dedicated tenant with stronger security controls, your own region / RPO and the assurance a regulated programme needs.
Every record is scoped to your organisation by construction — your data is yours alone.
Email one-time codes, passkeys and optional 2FA, with step-up auth on high-consequence actions.
Every operator action captured in an append-only log you can hand to a regulator, insurer or board.
“Incidents don’t fail in the playbook. They fail in the handoff.”
— Christopher Lloyd, Founder
Launching 31 July 2026. Lock the founding offer now, or get a heads-up when Community opens.