Responsible use
This site is built to help organisations defend and test — not to help anyone attack.
What we publish
BreachPath describes how attacks progress at the level of behaviour and objective, the way MITRE ATT&CK and attacker-perspective threat modelling do. Every stage is paired with the controls, telemetry and tests that defend against it. The entire framing is defensive: understand the chain so you can break it.
What we deliberately do not publish
- Exploit code, payloads, or working proof-of-concept for any vulnerability.
- Step-by-step, copy-and-paste instructions for carrying out an intrusion.
- Specific tooling commands or configurations for offensive actions.
- Fabricated breach case studies or firm attribution to named threat actors.
Who this is for
The intended audience is defenders, security buyers, risk owners and management deciding what to test — and the testing providers who help them. If you are on that side, this tool is designed to make your scoping conversations sharper and better informed.
Testing must be authorised
Nothing here authorises testing of any system. Penetration testing and red-team engagements must be commissioned, scoped and authorised in writing by the owner of the systems in scope, with appropriate safety constraints. The brief this site generates is a starting point for that conversation — not permission to act.
Report a concern
If you believe any content here crosses the line from defensive education into operational risk, tell us at hello@breachpath.org and we will review it.