PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

Deliverablesdeliverable
deliverable

Attack Pillar Figures

Canonical figures for the Attack pillar.

Public sample
Client deliverable
public-sample
System
Attack Pillar Figures
Environment
Production pilot

# Attack Pillar Figures

ATT-01

What Attack Tests

Attack turns mapped exposure into reproducible tests across prompts, retrieval, agents, tools, authority, and workflows.

Three-part figure showing mapped attack hypotheses, the Attack capability, and reproduced evidence-qualified results.

INPUTSBounded attack hypothesesPrompt andinstruction pathsRetrieval andcorpus boundariesAgents, tools, andauthorityApplication andworkflowtransitionsENGINEAttackDesign controlledscenariosExecute boundedtestsReproduceconsequentialbehaviorCapture evidenceand alternativesRESULTSQualified resultsReproducedfailuresCandidate orqualified pathsExplicit claimstateDefend-readyhandoff
ATT-02

From Isolated Finding to Defensible Path

A defensible attack path connects observed steps, evidence, and consequences rather than merely grouping nearby findings.

Comparison between an isolated finding with limited context and a defensible path with evidence, ordered transitions, consequence, and validation state.

BEFOREIsolated findingSingle findingLimited system contextUnqualified consequenceAFTERDefensible pathObserved or reproduced entrySupported transition orderEvidence linked to each stepBounded consequenceExplicit validation stateQUALIFIED INTOWHAT THE COMPARISON DOES NOT CLAIMNot every finding becomes a pathA path diagram is not proof of exploitation
ATT-03

Adversarial Testing Workflow

Attack testing moves from scoped hypotheses through controlled execution and evidence capture to qualified findings.

Six-stage adversarial testing workflow from scope through scenario design, execution, reproduction, evidence review, and handoff.

Scope the targetSTEP 1Select hypothesesSTEP 2Design scenariosSTEP 3Execute safelySTEP 4Reproduce andchallengeSTEP 5Qualify the resultSTEP 6Safety and evidence controlsExplicit authorization • Data and tenant safeguards • Evidenceretained for review
ATT-04

Black-Box to Gray-Box Uplift

System context turns observed behavior into better-qualified risk without replacing the partner or operator attack engine.

Comparison of black-box testing and gray-box testing with architecture, authority, trace, and evidence context added.

BEFOREBlack-box observationObserved system behaviorInput and output evidenceInternal preconditions unresolvedAFTERBetter-qualified resultSupported preconditionsBounded transition sequenceEvidence-linked consequenceStructured return objectQUALIFIED INTOBETTER-QUALIFIED RESULTSupported preconditionsBounded transition sequenceEvidence-linked consequence
ATT-05

Attack-to-Defend Handoff

Qualified paths become prioritized control opportunities, remediation hypotheses, and retest plans.

Transformation figure showing evidence-qualified attack results becoming control opportunities, remediation work, and retest plans.

Reproduced findingsQualified pathsSupportedpreconditionsUncertainty andresidual stateTRANSFORMATIONControl analysisCluster shared weaknessesIdentify chokepointsGenerate control optionsPrioritize by leverage andfeasibilityControl planNamed ownerRetest criteriaExpectedevidence state