Crimson7
Crimson7 BV is a Belgium-based offensive security firm that combines a threat research lab with two platforms — HackerFlow (BAS) and 7Hunter (threat hunting) — and professional services (red/purple teaming, detection engineering, managed Purple Rain) for enterprise security operations teams across regulated industries.
- Company typePrivate
- Founded2024
- HeadquartersZaventem, Belgium
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Crimson7 does
Crimson7 BV is a Belgium-headquartered (Zaventem/Brussels) private offensive security firm that operates a threat research lab and sells a platform-plus-services portfolio targeting enterprise security operations teams. The company positions itself within the C-AEV-R (Continuous Adversarial Exposure Validation and Remediation) category, combining continuous threat-led validation with Detection- and Response-as-Code (DRaC) delivery. Its core technical assets are two integrated platforms: HackerFlow, a hybrid Breach and Attack Simulation (BAS) platform featuring 1,000+ pre-built attack scenarios and 250+ advanced TTPs that generates deployable detection rules from each run, and 7Hunter, a threat hunting query management platform with 4,000+ pre-built KQL queries, 80+ investigation runbooks, full MITRE ATT&CK coverage, and real-time AI-assisted investigations. Both platforms are built on KQL, Sigma, and ARM template detection rules, with one-click export to Microsoft Sentinel and integrations across Splunk, Elastic, QRadar, and CrowdStrike.
The company monetizes through a hybrid revenue model: annual platform subscriptions for HackerFlow and 7Hunter (sized to organization and feature requirements), managed-service subscriptions (Purple Rain, a 12-month continuous purple teaming program), and project-based professional services spanning red team, purple team, detection engineering, threat hunting, and specialty assessments for hardware, firmware/IoT, ICS/OT, and physical security. Pricing includes a freemium 30-day Proof of Value program that lowers adoption friction. Go-to-market is dual-motion: enterprise field sales for high-value engagements targeting SOC leads, CISOs, and managed security buyers (with emphasis on European and regulated industries under TIBER-EU, DORA, and NIS2 frameworks), and a product-led growth motion for the platform POV. The company has no disclosed external funding and appears to operate a bootstrapped model led by co-Managing Directors Nick Maeckelberghe and Damian Myles, with named department heads across managed services, offensive security, research, and hardware/embedded systems practices.
The company serves 50+ enterprise customers across 12+ industries (financial services, retail, aerospace, healthcare, technology, critical infrastructure), reports 80+ years of combined team expertise, and has delivered 500+ validated detection rules as code. Its marketing is anchored on original threat intelligence research (APT38, MuddyWater, Icarus, supply chain analyses, PhaaS platform analysis), open-source tooling (sigma2kql), and a conference circuit presence (Cybersec Europe Brussels 2026, teissAmsterdam 2026), with a strategic partnership announced with Tidal Cyber in February 2026 to map Crimson7's threat hunts into Tidal Cyber's threat-led defense platform.
Crimson7 firmographics
Firmographics- Name
- Crimson7
- Legal name
- Crimson7 BV
- Website
- https://www.crimson7.io
- Company type
- Private
- Founded year
- 2024
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Crimson7 BV is a Belgium-based offensive security firm that combines a threat research lab with two platforms — HackerFlow (BAS) and 7Hunter (threat hunting) — and professional services (red/purple teaming, detection engineering, managed Purple Rain) for enterprise security operations teams across regulated industries.
- Ownership category
- akta.pro rank
Crimson7 industry classification
Industry- Product category
- Offensive Security Software & Services
- NAICS
- Testing Laboratories and Services (541380), Investigation and Security Services (5616), Scientific Research and Development Services (5417)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKAHAF)
- akta.pro secondary industries
- Penetration Testing & Red Teaming (BPAKADAE), Security Operations (SOC), Incident Response & Threat Hunting (EDAOAIAI)
Keywords
Where Crimson7 is headquartered
LocationHeadquarters
- HQ city
- Zaventem
- HQ country
- Belgium
- HQ region
- Europe
Offices2 records
Markets served
Crimson7 business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Platform Licensing (HackerFlow, 7Hunter): Annual subscription licensing for the HackerFlow and 7Hunter platforms. Licensed based on organization size and feature requirements. Includes platform access, updates, support, and a library of pre-built workflows/queries.
- Professional Services (Offensive Engineering, Defensive Engineering): Project-based and managed service engagements covering red team, purple team, detection engineering, and threat hunting. Services include full-scope assessments (4-8 weeks) and assume-breach assessments (2-4 weeks). Purple team component can be combined with any offensive engagement.
- Managed Security (Purple Rain): 12-month managed purple team program (Purple Rain) with annual subscription. Includes weekly simulation cycles, continuous detection rule delivery, monthly threat reports, quarterly optimization reviews, and 24/7 monitoring dashboard access. Designed for organizations with dedicated security operations.
- Specialty Security Services: Specialized assessments covering hardware security, firmware/IoT, industrial control systems (ICS/OT), and physical security for high-assurance and targeted environments.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free 30-day Proof of Value — HackerFlow or 7Hunter |
| Subscription | Annual | HackerFlow Annual Platform License |
| Subscription | Annual | Purple Rain Managed Purple Team (annual subscription) |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels6 records
Crimson7 product offering
Product offeringCore offering
Crimson7 operates a threat research lab that delivers offensive security software (HackerFlow hybrid BAS platform and 7Hunter threat hunting platform) and professional/managed services — red and purple team assessments, detection engineering, continuous purple teaming, and specialty hardware/ICS testing. Detection rules are delivered as KQL, Sigma, and ARM templates validated against real attack execution.
Product overview
Crimson7 is an offensive security research lab and services company offering a platform-plus-services model. The core product portfolio consists of two integrated platforms: HackerFlow, a hybrid BAS platform for continuous defense validation that generates Detection- and Response-as-Code (DRaC) with 1,000+ attack scenarios and 250+ TTPs; and 7Hunter, a threat hunting query management platform with 4,280+ pre-built KQL queries, 80+ runbooks, and AI-powered investigation capabilities. These platforms are complemented by professional services including Offensive Engineering (red/purple team exercises), Defensive Engineering (detection rule development), Managed Security services (Purple Rain continuous purple teaming), and Specialty Services (hardware, ICS/OT, physical security). The portfolio is unified under the CAEVR methodology: Continuous Adversarial Exposure Validation and Remediation, closing the loop between validation and deployment-ready detection code.
Differentiator
Problem solved
Functional benefit
Brands
- HackerFlow: A hybrid BAS (Breach and Attack Simulation) platform built for operators. Continuously validates defenses against real-world attack techniques, and generates Detection- & Response-as-Code from every run. Features 1,000+ pre-built attack scenarios, 250+ advanced TTPs, and continuous threat-led validation.
- 7Hunter
- Purple Rain
Products and services
- HackerFlow A hybrid Breach Attack Simulation (BAS) platform for security operators that continuously validates defenses against real-world attack techniques and generates Detection- and Response-as-Code (DRaC) from every run. Includes 1,000+ pre-built attack scenarios and 250+ advanced TTPs with MITRE ATT&CK mapping. Designed for enterprise SOC teams and offensive security operators.
- 7Hunter A threat hunting query management platform that centralizes hunting queries, investigation runbooks, and MITRE ATT&CK coverage mapping. Provides 4,280+ pre-built KQL queries, 80+ investigation runbooks, full ATT&CK coverage, real-time AI-powered investigations, and one-click export to Microsoft Sentinel. Targets SOC analysts and threat hunters.
- Purple Rain (Managed Purple Team) A continuous purple teaming delivered as an always-on 12-month managed program. Includes weekly simulation and validation cycles, continuous detection rule delivery, monthly executive reporting, quarterly optimization reviews, and 24/7 monitoring dashboard access. Combines human intelligence with validated automation for organizations with dedicated security operations.
- Offensive Engineering Services Red team, purple team, and adversary simulation services that put defenses under real, research-led pressure. Includes assume-breach assessments (2-4 weeks), full-scope assessments (4-8 weeks), TIBER/DORA regulatory exercises, and identity platform assessments for Active Directory, Microsoft Entra ID, and Okta. Sold as professional services to enterprise security teams.
- Defensive Engineering Services Detection engineering, validation, and threat hunting services that turn coverage gaps into measurable detections. Detection rules are delivered as KQL, Sigma, or ARM templates via Git repository with full MITRE ATT&CK mapping, documentation, and false positive guidance. Sold as professional services to enterprise SOC teams.
- Managed Threat Hunting Proactive threat hunting across enterprise environments using hypothesis-driven approaches with curated intelligence. Delivers findings and hunting rules to client teams with detailed hunting reports including threat findings, intelligence insights, and recommended actions. Targets organizations that want continuous hunting coverage without building it in-house.
- Specialty Security Services Specialized assessments covering hardware security, firmware and IoT security analysis, Industrial Control Systems (ICS/OT) testing, and physical security penetration testing. Targets high-assurance and critical infrastructure environments including energy, manufacturing, healthcare, transportation, and financial services sectors.
Quantifiable outcome
- 80+ years combined expertise and 50+ enterprises protected across 12+ industries
- +3 more outcomes
Companies that use Crimson7
Customer profileNamed customers1 record
Segments4 records
Ideal customer profiles4 records
Crimson7 technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration11 records
AI capability4 records
Feature4 records
Crimson7 partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Tidal CyberstrategicTidal Cyber, a leader in Threat-Led Defense, announced a strategic partnership with Crimson7. The integration maps Crimson7's threat hunts into the Tidal Cyber platform, enabling organizations to prioritize hunts that close coverage gaps and improve their Threat-Led Defense Confidence Score using MITRE ATT&CK framework alignment. The partnership spans industries including financial services, retail, aerospace, healthcare, technology, and critical infrastructure.
Scale indicators5 records
Recent moves6 records
Expansion highlights6 records
Crimson7 competitors and assessment
Company assessmentDirect peers
- AttackIQ: Direct BAS competitor offering the AttackIQ Platform for continuous security control validation, with adversary emulation scenarios aligned to MITRE ATT&CK. Targets the same enterprise SOC and red team buyers as Crimson7.
- XM Cyber: Continuous exposure validation and attack path management vendor with BAS roots now owned by Schwarz Group. Overlaps Crimson7's validation-plus-remediation approach and the ATT&CK-aligned narrative for SOC and CISO buyers.
- NCC Group: Global cyber resilience and offensive security services provider with extensive European presence; offers red team, TIBER-EU testing, and managed detection services that compete directly with Crimson7's offensive engineering, regulatory, and managed practices.
- Scythe: Adversary emulation platform with purple team focus, offering a threat-driven validation product comparable in spirit to HackerFlow and targeting similar SOC operator personas and budget lines as Crimson7.
- Pentera: Automated Security Validation vendor offering agentless, real-attack validation against enterprise defenses. Competes head-to-head for the same enterprise BAS/validation budget that Crimson7's HackerFlow and Offensive Engineering services target.
- Picus Security: Direct competitor operating in the Breach and Attack Simulation / Continuous Security Validation space. Picus's Security Validation Platform maps closely to HackerFlow's threat-led BAS capabilities and competes for the same enterprise SOC/CISO budget.
- WithSecure (formerly F-Secure): European-headquartered cyber security firm offering offensive security services (red teaming, managed detection) along with a broad product portfolio; competes with Crimson7 in EU regulated verticals (TIBER, DORA, NIS2).
- Bishop Fox: Elite offensive security services firm (red teaming, penetration testing, adversary simulation) similar in positioning to Crimson7's Offensive Engineering and Purple Rain practices. Both compete for high-end enterprise red team engagements.
- SafeBreach: Direct competitor in breach and attack simulation, with comparable scenario-based control validation and ransomware readiness testing. SafeBreach's playbook-based remediation philosophy directly overlaps Crimson7's Detection- and Response-as-Code positioning.
Broad incumbents
- CrowdStrike: Endpoint and SIEM/XDR platform incumbent with growing exposure validation capabilities (Falwind Adversary Emulation, Falcon Surface) that increasingly overlap Crimson7's BAS capabilities as part of a much broader enterprise security portfolio.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Crimson7 social profiles
Digital presenceCrimson7 financial estimates
Financial estimateRevenue estimate
Valuation estimate
Crimson7 leadership team
Management profileNumber of profiles
Profiles6 records
Crimson7 funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Crimson7 M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Crimson7
What does Crimson7 do?
Crimson7 operates a threat research lab that delivers offensive security software (HackerFlow hybrid BAS platform and 7Hunter threat hunting platform) and professional/managed services — red and purple team assessments, detection engineering, continuous purple teaming, and specialty hardware/ICS testing. Detection rules are delivered as KQL, Sigma, and ARM templates validated against real attack execution.
Is Crimson7 a public or private company?
Crimson7 is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Crimson7 founded?
Crimson7 was founded in 2024. It employs 11 to 50 people.
Where is Crimson7 based?
Crimson7 is headquartered in Zaventem, Belgium, in the Europe region.
How does Crimson7 make money?
Four revenue lines are on record. Platform Licensing (HackerFlow, 7Hunter) is the primary driver. The others are professional Services (Offensive Engineering, Defensive Engineering), managed Security (Purple Rain) and specialty Security Services.
Who are Crimson7's main competitors?
Direct peers on record are AttackIQ, XM Cyber, NCC Group, Scythe, Pentera, Picus Security, WithSecure (formerly F-Secure), Bishop Fox and SafeBreach. CrowdStrike is listed as a broad incumbent.
Does Crimson7 have an API?
Yes. 7Hunter provides a public REST API for SOAR integration and programmatic access to the full query library. The API enables organizations to integrate threat hunting queries into automation workflows and security orchestration platforms.
What industry is Crimson7 in?
Crimson7's product category is Offensive Security Software & Services. Its primary akta.pro industry code is BPAKAHAF, Penetration Testing & Red Teaming, with a secondary code of BPAKADAE, Penetration Testing & Red Teaming. Its NAICS code is 541380.