Methodology
How these attack paths are built, what grounds them, and what they are — and are not — designed to do.
Grounded in established methodology
Each path is a chain of stages that reflects how real intrusions tend to progress: from initial access, through identity abuse, discovery and lateral movement, to a business outcome. The techniques at each stage are mapped to MITRE ATT&CK, the community knowledge base of adversary behaviour. MITRE also publishes adversary-emulation plans based on observed attacker activity, and OWASP threat modelling deliberately examines systems from an attacker's perspective. BreachPath turns those relatively specialist methodologies into something a buyer or a board can follow.
What each stage describes
- The attacker's objective at that step — in plain English.
- The relevant MITRE ATT&CK techniques, linked to the canonical reference.
- The controls that should interrupt the chain there.
- The logs and alerts a defender ought to be able to see.
- What a penetration test or red-team engagement would do to validate it.
- The operational impact if that stage succeeds.
Behaviour, not exploitation
These pages describe attacker behaviour and defensive validation. They deliberately do not include exploit code, payloads, or step-by-step intrusion instructions. The goal is to help organisations understand and scope testing — not to provide an operational playbook. See our responsible-use statement.
What this tool is — and is not
BreachPathis a planning and scoping aid. It helps you reason about how weaknesses could be chained, and to articulate what you might want tested. It is not a scanner, not an assessment, and not a guarantee of coverage. The UK's National Cyber Security Centre is clear that penetration testing is not a magic solution and must be commissioned and planned correctly — a poorly scoped test gives false assurance. This tool exists to help you get that scoping right before you commission anything.
A curated library
We deliberately start with a focused set of carefully constructed paths rather than auto-generating hundreds. Every path and every stage is validated against a strict schema at build time, so the content stays structurally complete and internally consistent.
Ready to scope a test? Build your attack path and generate a red-team brief.