PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

Deliverablesdeliverable
deliverable

Attack Path Analysis Figures

Canonical figures for Attack Path Analysis.

Public sample
Client deliverable
public-sample
System
Attack Path Analysis Figures
Environment
Production pilot

# Attack Path Analysis Figures

PATH-04

Attack Path Analysis Value Proposition

Attack Path Analysis qualifies and explains multi-step risk rather than merely correlating alerts or drawing speculative paths.

Comparison between alert correlation and evidence-qualified attack-path analysis with explicit validation and residual state.

Correlation or path sketchAttack Path Analysis qualificationMaturity boundaryNearby or relatedfindingsPossible relationshipsUnbounded impacthypothesisEvidence linked toeach stepSupported transitionorderAlternativeexplanationschallengedBounded consequenceResidual andunresolved stateEvaluation-ready pathanalysisNo automaticenterprise-readinessclaim
Grounded / validated -- evidence-backed and confirmedInferred / under review -- plausible, not yet confirmedResidual -- unresolved after review
PATH-05

Attack Path Analysis Validation Pipeline

Independent validators challenge evidence, ordering, consequence, and alternative explanations before a path is accepted.

Governed Attack Path Analysis validation pipeline from candidate path through evidence, sequence, consequence, critic, correction, and analyst review.

Validation pipeline
  1. 1
    Candidate path
    Assemble a proposed chain from findings, graph relationships, and contextual evidence.
  2. 2
    Evidence validator
    Check whether each step has sufficient and correctly scoped support.
  3. 3
    Sequence validator
    Challenge prerequisites, ordering, and transition feasibility.
  4. 4
    Consequence validator
    Bound the supported outcome and reject exaggerated impact.
  5. 5
    Adversarial critic
    Search for contradictions, missing alternatives, and unjustified inference.
  6. 6
    Correction loop
    Revise, split, downgrade, or reject the candidate path.
Retest loop returns to Evidence validator
What state does the path support?
  • Grounded core
  • Explicit extension
  • Rejected path
  • Analyst review
PATH-06

Attack Path Analysis Result Contract

The path engine returns clusters, chokepoints, evidence links, residual state, and retest-ready outputs.

Transformation from path evidence through qualified analysis into traceable remediation, retest, and reporting outputs.

PROVENANCEPath evidenceFinding referencesEvidence-linked transitionsSource and trace referencesQualification and control analysisQualified pathsPath clustersShared chokepointsRejected and alternative explanationsTraceable result contractControl opportunitiesResidual path stateRetest criteriaPath and evidence JSON
PATH-07

Analyst-Reviewed Path

A proposed path becomes publishable only after evidence challenge, correction, and explicit analyst review.

Diagram showing a proposed path, grounded core, explicit inference, rejected alternatives, correction, and human analyst approval.

Grounded core
  • Supported entry condition
  • Supported transitions
  • Bounded impact
  • Evidence linked to each step
  1. 1
    Challenge evidence sufficiency
  2. 2
    Consider alternatives
  3. 3
    Correct, split, or downgrade
Analyst-reviewed outcome
Analyst-reviewed path