SECURITY RESEARCH

Evidence sources that shape the product.

The product is designed to use public security guidance and authoritative vulnerability information as reference signals, while keeping the reasoning visible to analysts.

2025OWASP

OWASP Top 10:2025

OWASP’s 2025 Top 10 is the current awareness document for web application security. The release includes categories such as Broken Access Control, Security Misconfiguration, Software Supply Chain Failures, Authentication Failures and Security Logging & Alerting Failures.

Read the source ↗
2024NIST

Cybersecurity Framework 2.0

NIST CSF 2.0 provides a common structure for managing cybersecurity risk across organizations of different sizes and maturity levels. AttackPath AI uses it as a reference for describing security outcomes and remediation intent.

Read the source ↗
OngoingCISA

Known Exploited Vulnerabilities

CISA describes its KEV catalog as an authoritative source of vulnerabilities that have been exploited in the wild and recommends using the catalog as an input to vulnerability-management prioritization.

Read the source ↗
2025OWASP GenAI

Agentic application security

OWASP’s GenAI Security Project expanded its guidance to agentic applications in 2025, reflecting risks introduced when AI systems can plan and act across tools and workflows. This is relevant to any future security automation layer.

Read the source ↗

METHODOLOGY NOTE

Use models to structure evidence, not to invent it.

Security analysis can fail when an automated system treats an inferred relationship as a verified one. The product direction therefore separates observed facts, derived relationships and analyst assumptions.

ObservedSource data directly supplied by an approved connector or import.
DerivedA relationship or priority calculated from documented rules.
AssumedA condition requiring analyst confirmation before it is treated as a security conclusion.