PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

ATT-02

From Isolated Finding to Defensible Path

A defensible attack path connects observed steps, evidence, and consequences rather than merely grouping nearby findings.

comparison

BEFOREIsolated findingSingle findingLimited system contextUnqualified consequenceAFTERDefensible pathObserved or reproduced entrySupported transition orderEvidence linked to each stepBounded consequenceExplicit validation stateQUALIFIED INTOWHAT THE COMPARISON DOES NOT CLAIMNot every finding becomes a pathA path diagram is not proof of exploitation

About this figure

This comparison distinguishes between an isolated finding and a defensible attack path. A single finding may indicate risk, but by itself it does not establish how an adversary could move through a system or what outcome would follow. A defensible path requires observed or reproduced entry, a supported transition order, evidence tied to each step, and a bounded consequence with explicit validation state. The comparison also clarifies its limits: not every finding should be promoted into a path, and a path diagram is not proof of exploitation.

Embed in a route

<FigureFromSource sourcePath="content/publications/figures/platform/attack.dsl.md" figureId="ATT-02" />

Citation

From Isolated Finding to Defensible Path (ATT-02). AI Security LLC Figure Library. https://aisecurity.llc/publication-dsl/figures/ATT-02