Skip to content

Attack Chains ​

Attack chains are visual flow diagrams that show how individual vulnerabilities combine to achieve broader impact. They connect discrete findings into end-to-end exploitation paths that demonstrate real-world risk.

Attack chain canvas editor

Screenshots use fictional demonstration data.

Why Attack Chains ​

Individual findings often don't convey the full risk picture. A medium-severity information disclosure combined with a low-severity misconfiguration might chain into a critical account takeover. Attack chains make these compound risks visible to stakeholders.

Node Types ​

NodePurpose
VulnerabilityA specific finding from the project's issues list
LabelA descriptive text node for annotations or phase names
BlockA system or component (e.g., "Web Server", "Database")
PersonA user role or identity (e.g., "Regular User", "Admin")
AttackerThe threat actor initiating the chain
PwnedThe compromised end state (e.g., "Full Account Takeover")

Building Chains ​

Use the canvas editor to construct attack chains:

  1. Add nodes: place nodes on the canvas for each step in the attack
  2. Connect edges: draw directional edges between nodes to show the flow
  3. Link vulnerabilities: connect vulnerability nodes to actual findings for traceability
  4. Annotate: use label nodes to describe transitions between steps

You can build multiple chains per project to illustrate different attack scenarios.

Including Chains in Reports ​

Attack chains are embedded in generated PDF reports alongside the findings they reference. The visual diagram is included as a figure, tying individual vulnerabilities into a coherent risk story.

Hashiro. Continuous Threat Exposure Management.