Scythe
Arlington, US · Founded 2016 · Nevada corporation · 26 employees on LinkedIn · 7 known investors
SCYTHE is a continuous Adversarial Exposure Validation (AEV) platform that emulates real adversary techniques (mapped to MITRE ATT&CK) against an organization's actual IT, cloud, and OT/ICS environments to validate that detection, alerting, and response controls work. It serves enterprise security teams—red, blue, and purple teams—integrating with EDR and SIEM platforms and offering both self-operated and managed engagements.
Also known as SCYTHE
Founders & leadership
Scythe was founded in 2016 by Bryson Bort.

Investors · 7
Reported raises · per SEC filings
Form D private placements$18.2M disclosed across 3 rounds · 2018–2023
▶$5.2MraisedJul 2023 · 3 investors · Other TechnologyRule 506(b)
- Christopher SteedDirector
- Ron GulaDirector
- Tansel IsmailDirector
- Bryson BortExecutive Officer, Director
- Dmitri AlperovitchDirector
- Offering amount
- $6M
- Amount sold
- $5.2M
- Minimum investment
- $200K
- Proceeds to insiders
- $250K
- First sale
- Jul 2023
- Incorporated
- Corporation, Nevada
- Federal exemptions
- 06b
▶$10MraisedNov 2021 · 11 investors · Other TechnologyRule 506(b)
- Dmitri AlperovitchDirector
- Christopher SteedDirector
- Ron GulaDirector
- Bryson BortExecutive Officer, Director
- Jorge OrchillesExecutive Officer
- Offering amount
- $10M
- Amount sold
- $10M
- Minimum investment
- $20K
- Proceeds to insiders
- $475K
- First sale
- Sep 2021
- Incorporated
- Corporation, Nevada
- Federal exemptions
- 06b
▶$3MraisedSep 2018 · 14 investors · Other TechnologyRule 506(b)
- Bryson BortExecutive Officer, Director
- Offering amount
- $3M
- Amount sold
- $3M
- Minimum investment
- $25K
- Proceeds to insiders
- $350K
- First sale
- Aug 2018
- Incorporated
- Corporation, Nevada, 2016
- Federal exemptions
- 06b
Source: SEC EDGAR Form D. Amounts as filed; amended filings shown once at their latest values.
Company profile
researched Aug 2026SCYTHE sells an Adversarial Exposure Validation (AEV) platform that continuously emulates real adversary behavior against a customer's production IT, cloud, and OT/ICS environments in order to measure, rather than assume, detection and response coverage. Emulations are mapped to MITRE ATT&CK and are executed as multi-stage, named threat-actor campaigns across the full kill chain, on scheduled cadences or triggered by change events, with a stated production-safe design and either agentless or agent-based deployment.
The platform validates the full response chain rather than only whether a sensor fired: it checks that endpoint detections generate usable SIEM alerts, that correct SOC workflows are triggered, and that expected response actions execute end to end, and it supports regression testing of detection rules after platform changes, parser updates, or the addition of new log sources. A dashboard surfaces a risk score, detection gaps found, ATT&CK coverage percentage, and active campaigns. Named use cases include EDR validation, SIEM detection engineering, OT/ICS security validation, and operationalizing cyber threat intelligence so that reported adversary TTPs are tested against live controls instead of filed as reports. The company also publishes a free self-service AEV readiness assessment scoring programs across cadence, emulation depth, response validation, CTI operationalization, and metrics.
Business model
SCYTHE licenses its validation platform to enterprises under what it describes as transparent, all-inclusive pricing: four tiers, the full feature set at every tier, no per-seat charges, no agent limits, and no overage fees, with price scoped to the size of the customer's environment rather than user or agent counts [0].
Traction
The site cites customer-reported outcomes including a 60%+ reduction in detection MTTR, a 4x increase in continuously executed detection tests, 25-60% improvement in ATT&CK detection coverage, more than 80% of routine validation automated, sub-48-hour average re-test cycles, and 30-50% fewer false negatives. A testimonial from John Strand of Black Hills Information Security states that SCYTHE cut the firm's MITRE ATT&CK testing from days to moments [0].
▸Full profile — market position, technology, go-to-market
Market position
SCYTHE positions AEV as a successor category to penetration testing (point-in-time, scoped, no detection or response validation) and to breach and attack simulation (more frequent but signature/IOC-based, atomic tests, agent-dependent, with limited OT/ICS support), differentiating on continuous scheduling, behavioral emulation, response validation, and OT/ICS coverage [0].
Stated differentiators are continuous and change-triggered validation instead of periodic testing, behavioral rather than signature-based emulation, multi-stage named threat-actor campaigns instead of atomic tests, validation of response and analyst performance (measured via MTTR) alongside tooling, agentless OT/ICS-safe deployment, and closing the loop from cyber threat intelligence to executable emulation [0].
Technology
The product performs behavioral emulation of adversary techniques mapped to MITRE ATT&CK, executed as multi-stage kill-chain campaigns rather than atomic, signature- or IOC-based tests. Deployment can be agentless or agent-based, including agentless options positioned as safe for OT/ICS networks. The platform integrates bidirectionally with widely deployed EDR products including CrowdStrike Falcon, Microsoft Defender, SentinelOne, Cortex XDR and Carbon Black, with API-based support for others, and correlates EDR detections with SIEM alerting and SOC workflows [0].
Go-to-market
The company markets directly through its website with 1:1 deep-dive calls, personalized demos, a five-minute product overview video, live hands-on workshops, published pricing and comparison content, and a free 15-question AEV readiness assessment used as a lead-in [0].
Enterprise security teams responsible for detection and response, including SOC analysts, detection engineers working on SIEM rules, EDR owners, and operators of OT/ICS environments [0].
Compiled by commissioned research from 1 cited public sources — announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed — not independently audited.
Competitors · 8
by search overlapCompanies competing with Scythe for the same Google search keywords, organic and paid, via search-intersection analysis.
Legal entities · 1
corporate structureIn the news
▸Research sources · 1
primary sources listed
- Scythescythe.io · web
1 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does Scythe do?
- SCYTHE runs continuous adversarial exposure validation to test whether enterprise detection and response controls catch real attacks.
- Who founded Scythe?
- Scythe was founded by Bryson Bort in 2016.
- Who are Scythe's investors?
- Scythe's investors include Energy Impact Partners, Gula Tech Adventures, Evolution Equity Partners, Saas Ventures, L.L.C., Inner Loop Capital, StoneMill Ventures, Alumni Ventures.
- How much funding has Scythe raised?
- Scythe has disclosed $18.2M raised across 3 rounds.
- Where is Scythe headquartered?
- Scythe is headquartered in Arlington, US.






