SecEng Evidence Graph Grounded Attack-Path Chaining
by SecEng › savvy-cli · simstudio · llm-attack-range
Fixture-driven · Support Copilot fixture
10 attack paths 15 validated
Evidence assembled from 3 SecEng tools
Untrusted document → sensitive write, grounded in what SecEng actually observed Each edge below is backed by real evidence records. Grounded steps were observed by a sensor or deterministically derived from configuration; inferred and speculative steps are drawn distinctly and never silently promoted. Analyst validation remains a human step.
Legend Grounded Inferred Speculative trust boundary delegated authorityGrounded attack paths (10) 1 attack path · draft grounded validated https://vendor.example/invoice-4821.html document enters_contextsavvy-cli Retrieved context retrieved context routes_to savvy-cli gpt-support model invokessavvy-cli refund_customer tool can_executellm-attack-range refunds action 1 trust boundary crossing 2 authority stepsmitre_atlas AML.T0049 direct_tested direct_tested direct_tested direct_tested direct_tested replay 003-tool-abuse2 attack path · draft grounded validated https://vendor.example/invoice-4821.html document enters_contextsavvy-cli Retrieved context retrieved context routes_to savvy-cli gpt-support model invokessavvy-cli refund_customer tool authorized_assavvy-cli · simstudio-whitelabel service_account (payments:write) credential 1 trust boundary crossing 2 authority steps3 attack path · draft grounded validated https://vendor.example/invoice-4821.html document enters_contextsavvy-cli Retrieved context retrieved context routes_to savvy-cli gpt-support model invokessavvy-cli refund_customer tool can_sendsimstudio-whitelabel refunds action 1 trust boundary crossing 2 authority steps4 attack path · draft grounded validated https://vendor.example/invoice-4821.html document enters_contextsimstudio-whitelabel Support agent agent can_callsimstudio-whitelabel refund_customer tool can_executellm-attack-range refunds action 1 trust boundary crossing 2 authority stepsmitre_atlas AML.T0049 direct_tested direct_tested direct_tested direct_tested direct_tested replay 003-tool-abuse5 attack path · draft grounded validated https://vendor.example/invoice-4821.html document enters_contextsavvy-cli Retrieved context retrieved context routes_to savvy-cli gpt-support model invokessavvy-cli refund_customer tool can_writesavvy-cli refunds action 1 trust boundary crossing 2 authority steps6 attack path · draft grounded validated https://vendor.example/invoice-4821.html document enters_contextsavvy-cli Retrieved context retrieved context routes_to savvy-cli gpt-support model invokessavvy-cli refund_customer tool can_read savvy-cli customers datastore 1 trust boundary crossing 1 authority step7 attack path · draft grounded validated https://vendor.example/invoice-4821.html document enters_contextsimstudio-whitelabel Support agent agent can_callsimstudio-whitelabel refund_customer tool authorized_assavvy-cli · simstudio-whitelabel service_account (payments:write) credential 1 trust boundary crossing 2 authority steps8 attack path · draft grounded validated https://vendor.example/invoice-4821.html document enters_contextsimstudio-whitelabel Support agent agent can_callsimstudio-whitelabel refund_customer tool can_sendsimstudio-whitelabel refunds action 1 trust boundary crossing 2 authority steps9 attack path · draft grounded validated https://vendor.example/invoice-4821.html document enters_contextsimstudio-whitelabel Support agent agent can_callsimstudio-whitelabel refund_customer tool can_writesavvy-cli refunds action 1 trust boundary crossing 2 authority steps10 attack path · draft grounded validated https://vendor.example/invoice-4821.html document enters_contextsimstudio-whitelabel Support agent agent can_callsimstudio-whitelabel refund_customer tool can_read savvy-cli customers datastore 1 trust boundary crossing 1 authority stepChokepoints — where one control collapses many paths Adding a mandatory approval/control at entity:tool_refund blocks 10 of 10 analyzed paths.
Greedy control cover 1 refund_customer 10/10 paths Evidence provenance — every edge traces here Tool Type Grounding Conf. Claim (subject → object) savvy-cli runtime.rag_chunk_enters_context observed 95% entity:external_invoice —enters_context→ entity:context savvy-cli runtime.context_routes_to_model observed 95% entity:context —routes_to→ entity:model savvy-cli runtime.tool_call observed 96% entity:model —invokes→ entity:tool_refund savvy-cli authority.capability_auth derived 85% entity:tool_refund —authorized_as→ entity:cred_payments savvy-cli authority.capability_write derived 85% entity:tool_refund —can_write→ entity:action_refund_write savvy-cli authority.capability_read derived 85% entity:tool_refund —can_read→ entity:datastore_customers simstudio-whitelabel authority.workflow_input_flow derived 90% entity:external_invoice —enters_context→ entity:agent_support simstudio-whitelabel authority.workflow_can_call derived 90% entity:agent_support —can_call→ entity:tool_refund simstudio-whitelabel authority.tool_credential derived 90% entity:tool_refund —authorized_as→ entity:cred_payments simstudio-whitelabel authority.tool_write derived 90% entity:tool_refund —can_send→ entity:action_refund_write llm-attack-range range.finding.demonstrated observed 95% entity:tool_refund —can_execute→ entity:action_refund_write llm-attack-range range.finding.demonstrated observed 95% entity:tool_refund —can_execute→ entity:action_refund_write
Evidence Pack export — grounded paths → buyer-ready artifact The same grounded paths, bridged into deliverable findings and controls. Machine-validated only — nothing is marked analyst-confirmed until a human signs off.
medium Untrusted https://vendor.example/invoice-4821.html can reach refunds open critical Untrusted https://vendor.example/invoice-4821.html can reach service_account (payments:write) open medium Untrusted https://vendor.example/invoice-4821.html can reach refunds open medium Untrusted https://vendor.example/invoice-4821.html can reach refunds open Synthetic fixture · SecEng Evidence Graph v0.1.0 · deterministic (no LLM in the analysis path)