Plan, target, and operate — on infrastructure you control.
ShadowStrike is sovereign computer network operations for approved government clients. Plan, target, and operate with a governed platform — deploy the software yourself, or engage S32 to run missions on your behalf.
The platform is the product.
ShadowStrike is the suite. ShadowOps is the platform where missions live — a single console to plan, target, task, operate, and report. ShadowDev is the exploit-development IDE that builds the tradecraft Ops runs. ShadowUnlock is the decryption engine, attached wherever decrypt is in scope.
Deploy the software and run missions with your own operators, or engage S32 to run them on your behalf — same console, same audit chain, whether your operators or ours. Managed Operations is simply us running your ShadowOps.
Inside the suite
S32 ShadowOps
The operations and C2 platform
Mission planning, rules of engagement, live session management, tasking, deconfliction, and ATT&CK-native reporting. The console agencies use to run operations end to end.
S32 ShadowDev
The exploit development IDE
AI-native ability authoring, signing, and catalogue. Tradecraft built here is signed and taskable directly from ShadowOps.
S32 ShadowUnlock
The decryption engine
Authorization-gated decrypt workflow and holdings catalogue. Integrates with ShadowOps and ShadowDev, or deploys on its own.
How the suite fits together
ShadowDev
Author and sign abilities
ShadowOps
Plan · target · task · operate · report
Sovereign C2 runtime
Isolated build and callback infrastructure
ShadowUnlock
Authorization-gated decrypt — with Ops/Dev, or standalone
ShadowOps is the hub. ShadowDev feeds it. ShadowUnlock attaches where decrypt is in scope. Execution runs on sovereign, per-country infrastructure.
What runs the mission
The operations console.
ShadowOps is where missions live. Operators work a live mission object graph — targets, sessions, and tasks in one picture — issue tasking with built-in deconfliction, and hold a kill-switch at every level. An AI mission planner proposes courses of action, bounded strictly to your signed ability catalogue, and every operation reports natively against ATT&CK.
In the console
- Mission object graph — targets, sessions, and tasks in one live picture
- Live callbacks and session management across the whole operation
- Task issuance with built-in deconfliction between operators
- Kill-switch at task, session, and mission level
- AI mission planner bounded to your signed ability catalogue
- ATT&CK-native reporting and after-action export
The tradecraft IDE.
ShadowDev is where tradecraft is built. Author and test abilities with AI assistance, sign them cryptographically, and map coverage against ATT&CK. Only signed abilities are taskable — and the signed catalogue flows straight into ShadowOps, ready to run.
From author to operation
Coverage matrix
Products — ShadowOps, ShadowDev, and ShadowUnlock
Suite, one console — from mission planning to the after-action report
Native technique mapping on every operation and report
Of operator actions carry an authorization record and audit trail
Shared black boxes — sovereign, per-country infrastructure you control
Only cryptographically signed abilities are taskable — the AI planner included
Governed by design
Authorization on every action
Every operator action carries an authorization record. The default mode records rather than blocks, so missions are never stalled — governance without friction.
Policy-configurable governance
Tenants set the rules of engagement: require dual control per action class, tighten authorization, or scope what may be tasked. Governance is configuration, not a hard-coded workflow.
Sovereign, per-country runtime
Build and command-and-control run on a sovereign C2 runtime, isolated by jurisdiction — infrastructure you control, never a shared black box.
Kill-switch everywhere
Halt a single task, an operator’s session, or an entire mission instantly, at any level of the operation.
Signed abilities only
Only cryptographically signed abilities from your catalogue can be tasked, and the AI planner is bounded to exactly that catalogue.
One audit chain
Same console, same audit chain — whether your operators or ours run the mission. Every task, callback, and decrypt is recorded in an immutable log.
How you deploy
Platform
Customer-operated
Deploy ShadowOps — plus ShadowDev and ShadowUnlock as needed — on sovereign infrastructure. Your operators plan and run missions end to end.
ShadowStrike Managed Operations
Operated by S32
S32 mission operators run tailored-access operations on your ShadowOps tenant — and you retain audit, policy, and the kill-switch throughout.
End-to-end delivery
Platform + tradecraft + missions
Platform, tradecraft, and operated missions together — for teams that want mission outcomes without standing up a full CNO capability.
Frequently asked
What does ShadowStrike include?
ShadowStrike includes ShadowOps (the operations and C2 platform), ShadowDev (the exploit development IDE), and ShadowUnlock (the decryption engine). S32 also offers managed mission operations for customers who want S32 to run operations on the platform on their behalf.
Who can access ShadowStrike?
ShadowStrike is provisioned exclusively for approved government clients, after vetting and approval.
Can we run it ourselves, or does S32 operate it?
Both. Deploy ShadowOps and run missions with your own operators, engage S32 for managed mission operations on your tenant, or combine the two for end-to-end delivery. It is the same console and the same audit chain either way.
How is ShadowStrike governed?
Governance is policy-configurable. Every operator action carries an authorization record and lands in an immutable audit trail; tenants can require dual control per action class and tighten authorization without stalling missions. A kill-switch is available at task, session, and mission level.
Where does it run?
On a sovereign C2 runtime provisioned per country — build and command-and-control infrastructure you control, isolated by jurisdiction.
Your platform. Your audit chain. Your call.
ShadowStrike is the operations platform for computer network operations — deploy it yourself or have S32 run missions on it, on sovereign infrastructure you control.
Request a briefing