PARTNERS

Embed, resell, or white-label AI security — OEM, scanner, MSSP, consulting, and reseller tracks are open now

PATH-01

Grounded path steps and explicit hypotheses.

Attack Path Analysis separates what the evidence directly supports from what remains an explicit hypothesis requiring validation or analyst review.

grounding boundary

Observed evidence
  1. 1Code and configuration evidence
  2. 2Runtime and trace evidence
  3. 3Identity and permission evidence
  4. 4Scanner and adversarial findings
Grounded path
  • Observed entry condition
  • Supported intermediate action
  • Evidence-supported impact
Explicit inference
  • Plausible next step
  • Assumption requiring challenge
  • Unverified impact extension

Inference never becomes grounded merely because it is plausible; evidence or explicit analyst validation must change its status.

Validation / analyst review
  • Evidence confirms extension
  • Analyst review required
  • Extension rejected

About this figure

This figure presents a grounded core built from observed evidence, code and configuration evidence, runtime and trace evidence, identity and permission evidence, and scanner or adversarial findings, then draws a clear boundary around what those signals can and cannot support. It traces an observed entry condition through a supported intermediate action to an evidence-supported impact, while labeling any broader consequence as an explicit inference rather than a settled fact. The result is a defensible chain of reasoning that distinguishes verified behavior from a plausible next step, an assumption requiring challenge, or an unverified impact extension that still needs validation or analyst review.

Embed in a route

<FigureFromSource sourcePath="content/publications/figures/partners/apc-throughline.dsl.md" figureId="PATH-01" />

Citation

Grounded path steps and explicit hypotheses. (PATH-01). SecEng Figure Library. https://aisecurity.llc/publication-dsl/figures/PATH-01