Asset graph
Represent internet-facing services, internal services, identities, data stores and trust relationships as connected security context.
- Input
- Approved asset inventories and metadata
- Output
- Normalized graph nodes and relationships
PLATFORM
AttackPath AI is being designed around a graph of assets, findings, identities, exposure and relationships. The goal is to make risk explainable at the point where analysts decide what to fix first.
CORE MODULES
Represent internet-facing services, internal services, identities, data stores and trust relationships as connected security context.
Attach security findings to the assets and services they affect, then preserve the source and evidence behind each record.
Identify plausible sequences between an exposure and a target using reachability, privilege relationships and control assumptions.
Rank findings by more than severity: asset criticality, exposure, path position, exploit evidence and remediation leverage.
Recommend the smallest set of fixes that breaks the highest-value paths, then give analysts a verification step.
Keep a concise record of the evidence and reasoning used to make a priority decision so that analysts can review or challenge it.
SCORING MODEL
The first product direction uses a transparent, configurable model rather than a single opaque "AI score." A finding can rise in priority when multiple independent signals align: exposed entry point, reachable route, high-value target, excessive privilege, known exploitation, or a control gap that affects several paths.
DESIGNED BOUNDARIES
CURRENT STAGE
The next milestones are focused on dependable data models, repeatable scoring and useful exports before adding more integrations.