Domain 2 · Attack-Path and Exposure Intelligence
Attack-Path and Crown-Jewel Intelligence
Reason over sequences from external exposure through identity weakness, privilege expansion and internal reachability to a sensitive asset, rather than over isolated findings.
Decision it answers
What are the plausible routes to our crown jewels, and which minimum set of interventions removes the most risk?
Inputs it needs
- Cloud and network topology
- Identity and access relationships
- Vulnerability and exposure data
- Endpoint inventory
- Crown-jewel and data-classification records
Methods applied
- Attack-path enumeration over the twin graph
- Choke-point and centrality analysis
- Graph-cut optimisation for minimum-cost interventions
- Counterfactual re-computation after each candidate change
Outputs produced
- Ranked material pathways with confidence
- Choke points and shared dependencies
- Intervention set with expected modelled risk reduction
- Recomputed exposure after remediation
Must remain human-owned
Authorization, acceptance of residual risk, containment decisions, disclosure and notification, and any communication to a board or regulator. No analytical capability creates operational authority.
