TURUL / Detection modelling
Know the boundary.
Operate inside it.
TURUL uses data-driven modelling to assess detection boundaries across your tooling. Every build is shaped by those models and verified against live EDR endpoints before delivery.
Built for the detection landscape
Keep your tools ready as detection changes.
New detection models can turn yesterday’s working tool into today’s engineering backlog. TurulGAN automates the transformation and verification cycle, helping teams spend less time rebuilding individual binaries.
Distinct builds
Generate statistically diverse binaries from your C# source, reducing reliance on the same binary signatures across engagements.
Verified before delivery
Test builds against live EDR endpoints inside the pipeline, giving operators evidence of their static evasion posture.
On-demand capability
Move from repeated manual re-engineering to an automated build workflow designed to deliver verified variants in minutes.
LLM agents can write payloads. What they cannot do is know where static detection boundaries are: without measurement an agent guesses at the boundary. Probabilistic modelling, and then adaptation on known, good, hardened tools removes the guesswork. The models behind every TURUL build state, before a payload is used, where the boundary sits and the detection risk of the build.
That layer is exposed over MCP, so the agents you already operate can query it directly rather than improvise.
Model-guided transformation
Evasion steered by models, not guesswork.
TurulGAN learns how static detection models see a binary. Every transformation is guided by machine learning trained on measured build outcomes, so each build is shaped by evidence rather than manual re-engineering.
Classifier-aware builds
Transformations target the features static ML classifiers score against, not just signatures, shaping each build to sit where classifiers expect benign software.
Self-optimising search
A learning agent explores each tool's transformation space, discovering which settings produce clean, verified builds and which do not.
Build, verify, learn
Every build and EDR verification cycle produces labelled data that sharpens the models, so the pipeline's aim improves the more it is used.
Your tools. Your workflow.
Add capability without rebuilding your toolchain.
Use the operator interface for day-to-day work, or connect TurulGAN to your existing automation. Your team keeps its tools and delivery processes.
Operator interface
A web interface puts the transformation and verification workflow in your operators’ hands.
API & SDKs
A REST API with over 35 endpoints, Python and .NET SDKs, and an MCP layer for LLM agents, supports integration with your own tooling.
Pipeline integration
Bring transformation and EDR verification into CI/CD and repeatable build processes.
Deployed on your terms
UK-developed.
Under your control.
TurulGAN can be fully self-hosted on Windows build hosts, keeping your source and build workflow within your own environment.
Discuss deployment requirements, integration, and evaluation against the EDR platforms relevant to your team.
Built for specialist teams
- Red teams that need repeatable tooling for realistic adversary simulation.
- Security assurance teams evaluating endpoint detection against diverse builds.
- Defence and sovereign capability teams requiring local deployment and control.
See TurulGAN in action
Evaluate TurulGAN with your team.
Tell us about your tooling, deployment needs, and EDR environment. We’ll arrange a pilot and discuss the right evaluation for you.
Research programme
Phase 1 solved static. We're moving up the stack.
TurulGAN answers static detection today. Our active research programme extends the platform towards the harder problem: how offensive tooling behaves at runtime, and how it keeps pace with detection models that retrain overnight.
A three-phase programme.
Each phase compounds on the last: proven static capability, then behavioural understanding, then runtime adaptation, all under the operator's control.
- Phase 1 · Static: complete
- Phase 2 · Behavioural modelling: in progress
- Phase 3 · Runtime adaptation: roadmap
Phase 2: Behavioural detection modelling
We are building data-driven models of how behavioural detection engines respond to offensive tooling at runtime. Tooling runs against a live, instrumented EDR/XDR/SIEM lab; every run is measured; the result is a family of models that understand detection risk for a given behaviour before it executes.
- Live EDR lab, instrumented end-to-end
- Measured across a broad portfolio of tools and tactics
- Model outputs feed directly into Phase 3
Phase 3: Runtime adaptation
Phase 3 closes the loop between the models and the tooling: capability that adapts its own behaviour at runtime, guided by the Phase 2 models, holding its position as detection models update. The level of autonomy stays with the operator.
- Model-guided behaviour at runtime
- Autonomy level set by the operator, from human-led upwards
- Extends TurulGAN and Turul C2 into one adaptive platform
Contact Us
How can we help?
Whether you represent a corporate, a consultancy, a government or an MSSP, we’d love to hear from you. To discover just how our offensive security contractors could help, get in touch.
