PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

OP-02

From attack result to qualified path.

A successful attack or trace is not automatically a defensible multi-step path; context, grounding, validation, and review must remain explicit.

governed lifecycle

Path qualification lifecycle
  1. 1
    Attack result
  2. 2
    Evidence normalized
  3. 3
    System context added
  4. 4
    Path constructed
  5. 5
    Path challenged
  6. 6
    Analyst reviewed
  7. 7
    Qualified path
Decision gate
  • Grounded and validated
  • Mixed grounded and inferred
  • Internal hypothesis
  • Rejected path

About this figure

This template describes a governed lifecycle for turning a raw attack result or trace into a qualified path that can support analysis, review, and remediation. The core idea is that a successful exploit observation is only an initial signal, not proof of a reusable or defensible multi-step path. Each step in the lifecycle makes assumptions explicit: evidence is normalized, system context is added, the path is constructed, challenged, and reviewed by an analyst before it is considered qualified. The diagram also distinguishes exception paths, where a segment is unsupported, an inferred extension remains explicit, or more context is required before the path can be trusted. When a qualified path exposes a control or chokepoint, remediation can be applied and the path retested to determine the residual state. The result is a traceable process that preserves uncertainty, prevents overclaiming, and ties findings to validation and response.

Embed in a route

<FigureFromSource sourcePath="content/publications/figures/partners/offensive-platforms.dsl.md" figureId="OP-02" />

Citation

From attack result to qualified path. (OP-02). AI Security LLC Figure Library. https://aisecurity.llc/publication-dsl/figures/OP-02