Fundraising Fox

Scythe

Arlington, US · Founded 2016 · Nevada corporation · 26 employees on LinkedIn · 7 known investors

SCYTHE is a continuous Adversarial Exposure Validation (AEV) platform that emulates real adversary techniques (mapped to MITRE ATT&CK) against an organization's actual IT, cloud, and OT/ICS environments to validate that detection, alerting, and response controls work. It serves enterprise security teams—red, blue, and purple teams—integrating with EDR and SIEM platforms and offering both self-operated and managed engagements.

Also known as SCYTHE

Founders & leadership

Scythe was founded in 2016 by Bryson Bort.

BBBryson Bort
Bryson BortinChief Executive OfficerInvestor at Inner Loop Capital

Investors · 7

Reported raises · per SEC filings

Form D private placements

$18.2M disclosed across 3 rounds · 2018–2023

$5.2MraisedJul 2023 · 3 investors · Other Technology
Rule 506(b)
Officers, directors & promoters on the filing
  • Christopher SteedDirector
  • Ron GulaDirector
  • Tansel IsmailDirector
  • Bryson BortExecutive Officer, Director
  • Dmitri AlperovitchDirector
Offering amount
$6M
Amount sold
$5.2M
Minimum investment
$200K
Proceeds to insiders
$250K
First sale
Jul 2023
Incorporated
Corporation, Nevada
Federal exemptions
06b
Full filing on SEC EDGAR ↗
$10MraisedNov 2021 · 11 investors · Other Technology
Rule 506(b)
Officers, directors & promoters on the filing
  • Dmitri AlperovitchDirector
  • Christopher SteedDirector
  • Ron GulaDirector
  • Bryson BortExecutive Officer, Director
  • Jorge OrchillesExecutive Officer
Offering amount
$10M
Amount sold
$10M
Minimum investment
$20K
Proceeds to insiders
$475K
First sale
Sep 2021
Incorporated
Corporation, Nevada
Federal exemptions
06b
Full filing on SEC EDGAR ↗
$3MraisedSep 2018 · 14 investors · Other Technology
Rule 506(b)
Officers, directors & promoters on the filing
  • Bryson BortExecutive Officer, Director
Offering amount
$3M
Amount sold
$3M
Minimum investment
$25K
Proceeds to insiders
$350K
First sale
Aug 2018
Incorporated
Corporation, Nevada, 2016
Federal exemptions
06b
Full filing on SEC EDGAR ↗

Source: SEC EDGAR Form D. Amounts as filed; amended filings shown once at their latest values.

Company profile

researched Aug 2026

SCYTHE sells an Adversarial Exposure Validation (AEV) platform that continuously emulates real adversary behavior against a customer's production IT, cloud, and OT/ICS environments in order to measure, rather than assume, detection and response coverage. Emulations are mapped to MITRE ATT&CK and are executed as multi-stage, named threat-actor campaigns across the full kill chain, on scheduled cadences or triggered by change events, with a stated production-safe design and either agentless or agent-based deployment.

The platform validates the full response chain rather than only whether a sensor fired: it checks that endpoint detections generate usable SIEM alerts, that correct SOC workflows are triggered, and that expected response actions execute end to end, and it supports regression testing of detection rules after platform changes, parser updates, or the addition of new log sources. A dashboard surfaces a risk score, detection gaps found, ATT&CK coverage percentage, and active campaigns. Named use cases include EDR validation, SIEM detection engineering, OT/ICS security validation, and operationalizing cyber threat intelligence so that reported adversary TTPs are tested against live controls instead of filed as reports. The company also publishes a free self-service AEV readiness assessment scoring programs across cadence, emulation depth, response validation, CTI operationalization, and metrics.

Business model

SCYTHE licenses its validation platform to enterprises under what it describes as transparent, all-inclusive pricing: four tiers, the full feature set at every tier, no per-seat charges, no agent limits, and no overage fees, with price scoped to the size of the customer's environment rather than user or agent counts [0].

Traction

The site cites customer-reported outcomes including a 60%+ reduction in detection MTTR, a 4x increase in continuously executed detection tests, 25-60% improvement in ATT&CK detection coverage, more than 80% of routine validation automated, sub-48-hour average re-test cycles, and 30-50% fewer false negatives. A testimonial from John Strand of Black Hills Information Security states that SCYTHE cut the firm's MITRE ATT&CK testing from days to moments [0].

Full profile — market position, technology, go-to-market

Market position

SCYTHE positions AEV as a successor category to penetration testing (point-in-time, scoped, no detection or response validation) and to breach and attack simulation (more frequent but signature/IOC-based, atomic tests, agent-dependent, with limited OT/ICS support), differentiating on continuous scheduling, behavioral emulation, response validation, and OT/ICS coverage [0].

Stated differentiators are continuous and change-triggered validation instead of periodic testing, behavioral rather than signature-based emulation, multi-stage named threat-actor campaigns instead of atomic tests, validation of response and analyst performance (measured via MTTR) alongside tooling, agentless OT/ICS-safe deployment, and closing the loop from cyber threat intelligence to executable emulation [0].

Technology

The product performs behavioral emulation of adversary techniques mapped to MITRE ATT&CK, executed as multi-stage kill-chain campaigns rather than atomic, signature- or IOC-based tests. Deployment can be agentless or agent-based, including agentless options positioned as safe for OT/ICS networks. The platform integrates bidirectionally with widely deployed EDR products including CrowdStrike Falcon, Microsoft Defender, SentinelOne, Cortex XDR and Carbon Black, with API-based support for others, and correlates EDR detections with SIEM alerting and SOC workflows [0].

Go-to-market

The company markets directly through its website with 1:1 deep-dive calls, personalized demos, a five-minute product overview video, live hands-on workshops, published pricing and comparison content, and a free 15-question AEV readiness assessment used as a lead-in [0].

Enterprise security teams responsible for detection and response, including SOC analysts, detection engineers working on SIEM rules, EDR owners, and operators of OT/ICS environments [0].

Compiled by commissioned research from 1 cited public sources — announcements, filings, and press listed under research sources below.

Key figures

latest reported
Average re-test cycle after a gap is identified and fixedJan 2025under 48 hours
Customer-reported reduction in detection mean time to respondJan 202560%+ reduction
Improvement in MITRE ATT&CK detection coverageJan 202525-60% improvement
Increase in continuously executed detection testsJan 20254 x
Pricing tiersJan 20254 tiers
Reduction in false negatives across validated controlsJan 202530-50%
Share of routine validation automatedJan 202580%+

Company-reported or press-reported figures, each dated to when it was claimed — not independently audited.

Competitors · 8

by search overlap
Cymulate41 shared keywordsCymulate provides a cybersecurity platform for security validation and exposure management, helping companies assess and strengthen their security posture. Founded in 2016, it serves over 1,000 customers across 50 countries.
Picus Security39 shared keywordsPicus operates a security validation platform that uses AI agents to combine automated penetration testing, exposure validation, and breach and attack simulation, testing whether real exploit chains would succeed against a customer's EDR, SIEM, firewall, and WAF controls. It serves enterprise security teams and CISOs to prioritize vulnerabilities and produce evidence for leadership and regulators.
Netezza33 shared keywordsIBM is a global technology company whose business spans enterprise software (including Red Hat, HashiCorp, and Confluent), IT infrastructure such as mainframes, servers, and storage, and IT consulting services. The company is also investing heavily in quantum computing and AI-based enterprise offerings, including its Lightwell open-source software security clearinghouse and the Anderon quantum wafer foundry.
Sentinel One30 shared keywordsSentinelOne provides an AI-powered cybersecurity platform for enterprises that integrates endpoint protection, threat detection, and incident response capabilities. The company serves large enterprises, including many Fortune 500 organizations, to protect against cyber threats at scale.
Palo Alto Networks29 shared keywordsPalo Alto Networks provides cybersecurity platforms and services to protect organizations' digital infrastructure across cloud, network, and security operations. The company serves enterprise organizations, governments, financial institutions, utilities, and healthcare providers globally.
Cyble27 shared keywordsCyble provides threat intelligence and security solutions for organizations to protect against cyber threats across their attack surface. The company serves enterprises including Fortune 500 firms and government entities in the cybersecurity industry.
Crowdstrike21 shared keywordsCrowdStrike provides an AI-native cybersecurity platform that unifies endpoint, identity, cloud, SaaS, and AI protection to detect and stop breaches for enterprise organizations. It combines automated response with human-led security operations including managed detection and response, threat hunting, and security services.
AttackIQ19 shared keywordsAttackIQ provides automated red team exercise software that scales security testing across organizations without increasing headcount. The platform enables security teams to automate repetitive penetration testing tasks, verify fixes faster, and focus expert analysts on advanced threat hunting and custom adversary research.

Companies competing with Scythe for the same Google search keywords, organic and paid, via search-intersection analysis.

Legal entities · 1

corporate structure
ScytheNevada

In the news

Research sources · 1

primary sources listed

1 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does Scythe do?
SCYTHE runs continuous adversarial exposure validation to test whether enterprise detection and response controls catch real attacks.
Who founded Scythe?
Scythe was founded by Bryson Bort in 2016.
Who are Scythe's investors?
Scythe's investors include Energy Impact Partners, Gula Tech Adventures, Evolution Equity Partners, Saas Ventures, L.L.C., Inner Loop Capital, StoneMill Ventures, Alumni Ventures.
How much funding has Scythe raised?
Scythe has disclosed $18.2M raised across 3 rounds.
Where is Scythe headquartered?
Scythe is headquartered in Arlington, US.