# Attack Path Analysis Figures
Attack Path Analysis Value Proposition
Attack Path Analysis qualifies and explains multi-step risk rather than merely correlating alerts or drawing speculative paths.
Comparison between alert correlation and evidence-qualified attack-path analysis with explicit validation and residual state.
Attack Path Analysis Validation Pipeline
Independent validators challenge evidence, ordering, consequence, and alternative explanations before a path is accepted.
Governed Attack Path Analysis validation pipeline from candidate path through evidence, sequence, consequence, critic, correction, and analyst review.
- 1Candidate pathAssemble a proposed chain from findings, graph relationships, and contextual evidence.
- 2Evidence validatorCheck whether each step has sufficient and correctly scoped support.
- 3Sequence validatorChallenge prerequisites, ordering, and transition feasibility.
- 4Consequence validatorBound the supported outcome and reject exaggerated impact.
- 5Adversarial criticSearch for contradictions, missing alternatives, and unjustified inference.
- 6Correction loopRevise, split, downgrade, or reject the candidate path.
- Grounded core
- Explicit extension
- Rejected path
- Analyst review
Attack Path Analysis Result Contract
The path engine returns clusters, chokepoints, evidence links, residual state, and retest-ready outputs.
Transformation from path evidence through qualified analysis into traceable remediation, retest, and reporting outputs.
Analyst-Reviewed Path
A proposed path becomes publishable only after evidence challenge, correction, and explicit analyst review.
Diagram showing a proposed path, grounded core, explicit inference, rejected alternatives, correction, and human analyst approval.
- Supported entry condition
- Supported transitions
- Bounded impact
- Evidence linked to each step
- 1Challenge evidence sufficiency
- 2Consider alternatives
- 3Correct, split, or downgrade