The engine inside Kestryn

Vestryn™

Every host leaves a trace.

The engine beneath the platform.

Vestryn is a clean-room network reconnaissance and detection engine: it finds every host, reads the traces it leaves, and identifies exactly what’s running — ports, services, versions, OS — then hands off clean CPEs for vulnerability matching.

Kestryn

Your networks. Direct, across VPN tunnels, in unprivileged and containerized deployments, and on modern cloud networks.

Structured results. Every host it finds — ports, services, versions, OS family and hostname — machine-readable, with CPE identifiers for CVE matching.

Say it VES-trin.

Latin. A trace, a footprint. The root of investigate.

Every host leaves a trace.

vest
the trace it leaves
ryn
the ending it shares with Kestryn

Three toes converging to a point: a V first, a raptor’s footprint a beat later. Kestryn and Vestryn rhyme by design — the raptor and the tracker.

Vestryn ships inside Kestryn.

Kestryn is the exposure-management platform that doesn’t stop at a list of findings — it finds, explains, prioritizes, and drives the fix, every step grounded in evidence and an auditable trail.

Kestryn hunts. Vestryn tracks. Prospica foresees. AuthX governs.

See the Kestryn platform

Where it runs.

One engine, in every place Kestryn reaches — including the sites that have no route back.

The platform runs it.

A campaign is assigned to run centrally or out at a site, per campaign — the same engine either way, not a lighter edition for the edge.

The central installation runs the engine, deployable wholly on-premise with no external call in any product path.

A collector carries it to a site with no link.

It keeps sweeping on a cached, signed policy and sends findings on when a window opens. It opens nothing inbound — every connection is started from the site.

A site collector runs the engine with no link at all, exposing no inbound service and keeping its previous policy if a new one cannot be verified.

And the agent runs it on the host.

So what a machine is can be read where it sits, rather than only inferred from across the network. It holds no shared secret — the host makes its own key and never sends the private half.

The agent runs the same engine on the host itself, holding no shared secret and shipping with its ingestion off by default.

One engine, not three builds of it. The same binary runs in all three places, so a host identified at a disconnected site and a host identified from the console are identified the same way — and a finding does not change because of where it was found.

Read what’s really there.

What Vestryn reports for a host it finds — and what it declines to report.

$ vestryn --detect -p 22,80,443 10.0.4.12 | jq -c 'select(.type=="service") | {port,state,service,product,version}'
{"port":80,"state":"open","service":"http","product":"","version":""}
{"port":443,"state":"open","service":"ssl/http","product":"nginx","version":"1.24.0"}
{"port":22,"state":"filtered","service":"","product":"","version":""}

Three ports observed. One fully identified. Port 443 gave up a product and a version. Port 80 gave up only its service — the product and version fields are left empty rather than guessed. Port 22 answered nothing, and is reported filtered rather than assumed closed.

Field by field, that record reads:

Live host
Reachable.
Hostname
When one is found.
Ports
Open, closed or filtered — each state as observed.
Service
What is listening.
Product
Identified.
Version
Reported — the observed evidence supports it.
Service
What is listening.
Product
Identified.
Version
Withheld. The observed evidence does not support a version, so none is reported.
OS family
Reported.
CPE identifier
Issued for the first service. None for the second.

reported from observed evidencewithheld — nothing assumed

When a scan cannot run as asked, Vestryn says so. It never narrows the scan and reports it as complete.

Built from the inside out.

In-house
Written by the vendor that ships it. No third-party scanner inside the product.
Clean-room
Built from public standards.
License-clean
Permissively licensed. Carries no copyleft. Yours to ship inside a commercial product.
One binary
Single and embeddable. Releases are signed.
Refuses to guess
A version is reported only when the observed evidence supports it.
Fails loud
Rather than quietly narrowing a scan into one that only looks complete.

Nothing you can’t ship.