PLATFORM

A context layer for vulnerability decisions.

AttackPath AI is being designed around a graph of assets, findings, identities, exposure and relationships. The goal is to make risk explainable at the point where analysts decide what to fix first.

Security findingsCVEs, misconfigurations, code findings
→
Context layerassets, identities, trust boundaries
→
Path modelexposure → reachability → target
→
Decisionpriority + evidence + remediation

CORE MODULES

Focused on the correlation problem.

01

Asset graph

Represent internet-facing services, internal services, identities, data stores and trust relationships as connected security context.

Input
Approved asset inventories and metadata
Output
Normalized graph nodes and relationships
02

Finding correlation

Attach security findings to the assets and services they affect, then preserve the source and evidence behind each record.

Input
Structured scanner or assessment exports
Output
Deduplicated, linked findings
03

Attack-path reasoning

Identify plausible sequences between an exposure and a target using reachability, privilege relationships and control assumptions.

Input
Graph relationships + finding context
Output
Explainable paths and breakpoints
04

Priority engine

Rank findings by more than severity: asset criticality, exposure, path position, exploit evidence and remediation leverage.

Input
Context and evidence signals
Output
Analyst-oriented risk queue
05

Remediation planner

Recommend the smallest set of fixes that breaks the highest-value paths, then give analysts a verification step.

Input
Top paths and affected controls
Output
Owner-ready remediation plan
06

Audit trail

Keep a concise record of the evidence and reasoning used to make a priority decision so that analysts can review or challenge it.

Input
Evidence and decision metadata
Output
Traceable assessment record

SCORING MODEL

Severity is a signal, not the answer.

The first product direction uses a transparent, configurable model rather than a single opaque "AI score." A finding can rise in priority when multiple independent signals align: exposed entry point, reachable route, high-value target, excessive privilege, known exploitation, or a control gap that affects several paths.

ExposureIs the entry point externally reachable or otherwise accessible?
ReachabilityCan the finding participate in a plausible chain to a target?
ImpactWhat is the business importance of the reachable asset?
EvidenceWhat source supports exploitability or malicious activity?
LeverageWould one remediation break multiple high-value paths?

DESIGNED BOUNDARIES

What the current product is — and is not.

Designed for

  • Defensive vulnerability prioritization
  • Authorized attack-path analysis
  • Read-only or exported security data
  • Analyst review and human approval
  • Evidence-linked remediation planning

Not designed to be

  • An autonomous exploitation engine
  • A replacement for all vulnerability scanners
  • A guarantee of exploitability or breach likelihood
  • A tool for unauthorized testing
  • A source of fabricated evidence

CURRENT STAGE

Prototype first. Product second.

The next milestones are focused on dependable data models, repeatable scoring and useful exports before adding more integrations.

Discuss the platform