Skip to content
BreachPathAttack Path LibraryStart

Methodology

How these attack paths are built, what grounds them, and what they are — and are not — designed to do.

Grounded in established methodology

Each path is a chain of stages that reflects how real intrusions tend to progress: from initial access, through identity abuse, discovery and lateral movement, to a business outcome. The techniques at each stage are mapped to MITRE ATT&CK, the community knowledge base of adversary behaviour. MITRE also publishes adversary-emulation plans based on observed attacker activity, and OWASP threat modelling deliberately examines systems from an attacker's perspective. BreachPath turns those relatively specialist methodologies into something a buyer or a board can follow.

What each stage describes

  • The attacker's objective at that step — in plain English.
  • The relevant MITRE ATT&CK techniques, linked to the canonical reference.
  • The controls that should interrupt the chain there.
  • The logs and alerts a defender ought to be able to see.
  • What a penetration test or red-team engagement would do to validate it.
  • The operational impact if that stage succeeds.

Behaviour, not exploitation

These pages describe attacker behaviour and defensive validation. They deliberately do not include exploit code, payloads, or step-by-step intrusion instructions. The goal is to help organisations understand and scope testing — not to provide an operational playbook. See our responsible-use statement.

What this tool is — and is not

BreachPathis a planning and scoping aid. It helps you reason about how weaknesses could be chained, and to articulate what you might want tested. It is not a scanner, not an assessment, and not a guarantee of coverage. The UK's National Cyber Security Centre is clear that penetration testing is not a magic solution and must be commissioned and planned correctly — a poorly scoped test gives false assurance. This tool exists to help you get that scoping right before you commission anything.

A curated library

We deliberately start with a focused set of carefully constructed paths rather than auto-generating hundreds. Every path and every stage is validated against a strict schema at build time, so the content stays structurally complete and internally consistent.

Ready to scope a test? Build your attack path and generate a red-team brief.