Rubeus
- Baseline evasion
- 42%
- Model-guided evasion
- 94–100%
Across tested configurations.
TURUL uses data-driven modelling to assess detection boundaries across your tooling. Every build is shaped by those models and verified against live EDR endpoints before delivery.
Pilot access is available only to vetted customers.
New detection models can turn yesterday’s working tool into today’s engineering backlog. TurulGAN automates the transformation and verification cycle, helping teams spend less time rebuilding individual binaries.
Generate statistically diverse binaries from your C# source, reducing reliance on the same binary signatures across engagements.
Test builds against live EDR endpoints inside the pipeline, giving operators evidence of their static evasion posture.
Move from repeated manual re-engineering to an automated build workflow designed to deliver verified variants in minutes.
LLM agents can write payloads, but without measurement they can only guess how static detection will respond. TURUL uses probabilistic modelling to guide the adaptation of known, hardened tools. Before a build is used, TURUL’s surrogate models estimate where the static detection boundary lies, then rebuilds the binary inside the boundary.
That layer is exposed over MCP, so the agents you already operate can query it directly rather than improvise.
TurulGAN learns how static detection models see a binary. Every transformation is guided by machine learning trained on measured build outcomes, so each build is shaped by evidence rather than manual re-engineering.
Transformations target the features static ML classifiers score against, not just signatures, shaping each build to sit where classifiers expect benign software.
A learning agent explores each tool's transformation space, discovering which settings produce clean, verified builds and which do not.
Every build and EDR verification cycle produces labelled data that sharpens the models, so the pipeline's aim improves the more it is used.
Across tested configurations.
Successfully compiled builds.
Indicative only. Outcomes vary by build and detection environment.
Traditional obfuscation and variant generation with high TLSH scores achieved 42% baseline evasion. Model-guided outcomes varied by configuration:
| Configuration | Evasion |
|---|---|
| Manual SCM configuration | 100% |
| Auto-generated, conservative | 95% |
| Auto-generated, aggressive | 94% |
Baseline evasion was 54%. Model-guided configuration achieved 100% evasion among successfully compiled builds.
Percentages are rounded to whole numbers.
Use the operator interface for day-to-day work, or connect TurulGAN to your existing automation. Your team keeps its tools and delivery processes.
A web interface puts the transformation and verification workflow in your operators’ hands.
A REST API with over 35 endpoints, Python and .NET SDKs, and an MCP layer for LLM agents, supports integration with your own tooling.
Bring transformation and EDR verification into CI/CD and repeatable build processes.
TurulGAN can be fully self-hosted on Windows build hosts, keeping your source and build workflow within your own environment.
Discuss deployment requirements, integration, and evaluation against the EDR platforms relevant to your team.
Tell us about your tooling, deployment needs, and EDR environment. We’ll arrange a pilot and discuss the right evaluation for you.
TurulGAN answers static detection today. Our active research programme extends the platform towards the harder problem: how offensive tooling behaves at runtime, and how it keeps pace with detection models that retrain overnight.
Each phase compounds on the last: proven static capability, then behavioural understanding, then runtime adaptation, all under the operator's control.
We are building data-driven models of how behavioural detection engines respond to offensive tooling at runtime. Tooling runs against a live, instrumented EDR/XDR/SIEM lab; every run is measured; the result is a family of models that understand detection risk for a given behaviour before it executes.
Phase 3 closes the loop between the models and the tooling: capability that adapts its own behaviour at runtime, guided by the Phase 2 models, holding its position as detection models update. The level of autonomy stays with the operator.
Whether you represent a corporate, a consultancy, a government or an MSSP, we’d love to hear from you. To discover just how our offensive security contractors could help, get in touch.