Prove Your Segmentation Actually Stops Attackers

Prancer starts from an authorized compromised position, attempts to cross each network, identity, cloud, ZTNA, SSE, firewall, microsegmentation, or IT/OT boundary, and records whether the protected asset was blocked or reachable.

Test the boundary

Exercise actual enforcement rather than reviewing configuration alone. Capture the control response, identity path, and protected-asset outcome.

Prove the change

Run the same attack before and after a policy change for repeatable before-and-after evidence.