news.mlab.sh
Back to the feed
threat-intel

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

High
Summary

Security teams often validate individual security controls, but fail to test how attackers actually chain these controls together, leading to breaches despite passing individual tests. Attack Chaining, a new approach from OpenAEV, simulates multi-stage attack paths in real-time, mirroring how attackers operate, and adapts based on findings. This allows organizations to identify true exposure gaps and prioritize remediation efforts, rather than relying on outdated, isolated testing. The technology is particularly relevant given the increasing use of AI by attackers.

Security teams frequently validate individual security controls – will an EDR agent catch a specific payload? Will a phishing simulation work? – but this doesn’t address the core problem: attackers don’t test techniques in isolation; they chain them together. A phishing email can lead to a credential harvest, which then allows an attacker to gain a foothold, escalate privileges, move laterally, stage data, and ultimately exfiltrate it. Each individual step might be something a security control could theoretically catch, but a long chain of these steps can slip through the gaps between tools, teams, and alerts.

According to Filigran’s State of Threat Management report, 93% of security leaders reported a business-impacting cyberattack in the past 12 months, despite most having validated their defenses. 88% cited AI accelerating attacker movement, and 84% pointed to siloed tools and disconnected testing as a primary reason for missed exposures. This highlights a significant gap between understanding cyber risk exposure and actually being resilient against it.

Organizations that get breached despite passing individual control tests usually fail a chain test they never ran. Attack Chaining, a new capability from OpenAEV, addresses this by simulating multi-stage attack paths in real-time, mirroring how attackers operate. It dynamically links techniques into a live sequence, with each action’s output (a harvested credential, an open port, a token) feeding directly into the next stage. The logic is built around conditional chaining, allowing teams to create reusable multi-stage attack paths and adapt them as new techniques emerge.

The technology is powered by five key capabilities: Open, conditional chaining logic (allowing teams to build reusable attack paths), live attack path mapping (visualizing the attack path in real-time), transparent, actionable findings (identifying chokepoints and providing structured data), scope and safety controls (limiting the scope and preventing uncontrolled escalation), and social engineering as a first-class stage (incorporating phishing and other social engineering tactics).

OpenAEV supports two modes of operation: operator-led (where a human builds the logic and controls execution) and Autonomous Attack Chaining (where an AI agent plans and executes the attack path based on a defined objective and scope, adapting as it goes). Both modes operate on the same conditional engine and scope controls, delivering the same outcome: a realistic, end-to-end attack simulation that runs in minutes, repeatable as often as your environment changes, and prioritized around relevant threat intelligence.

To learn more about how Attack Chaining gets operationalized, Filigran is hosting a live webinar. You can register for one of the sessions here: [Link to Webinar Registration]

Read the full article at The Hacker News