Attack Chaining: Continuous, Automated Red Teaming
Turn OpenAEV into a live, agentic multi-stage attack path engine to chain techniques continuously - the way real attackers do.

Automation is no longer optional
Periodic, manual validation simply cannot match the volume, speed, and sophistication of AI-powered adversaries.. Red and Purple Teams need to adapt.
The problem with validation today
Attackers chain techniques fast, while most defenders still test manually with point-in-time processes. And AI is widening that gap.
- Simulations don't act like real attackers. Scripted scenarios never change course based on what they find, so teams test against paths no attacker would take.
- Point-in-time testing goes stale. Environments and attacker techniques change constantly, so pentest results are outdated almost as soon as the report lands.
- Red team capacity doesn't scale. Building chains by hand is slow and needs specialist skills, so only a fraction of attack paths ever get tested.
- AI is shrinking attacker timelines. Adversaries use AI to chain and adapt faster, so defenders have less time to respond.
90% of security professionals still rely on manual processes across every stage of exposure management.

What is Attack Chaining?
Attack Chaining turns OpenAEV into a live, adaptive attack path engine, where the output of one action feeds the input of the next. Each result (a credential, an IP/port, a token, a file, and more) is captured as a structured finding, and the engine evaluates these at runtime to decide what happens next, branching the path based on what's actually discovered rather than following a fixed script.
Three things set it apart:
- Open, conditional logic. Build chains by hand, then update and reuse them as techniques change.
- Live, actionable visibility. Track every action and finding on an interactive graph as it happens.
- Chokepoint identification. See how an attacker would chain your weaknesses together, and the one fix that breaks the whole path.
- Autonomous orchestration. Give an agent an objective and it plans, runs and adapts the chain on its own.
The result is a fast, realistic and cost-effective way to test vulnerabilities at scale.
How does Attack Chaining work?
How does Attack Chaining work?
An Attack Chaining scenario is a set of actions linked by conditions. You pick actions from your threat arsenal (TTPs, payloads, phishing or custom actions) and the conditions decide which one runs next, based on what the previous action found. A single chain can branch several ways, so one scenario covers many possible paths.
Each chain also has a scope that sets which assets and targets are in bounds and how far it can escalate.
During a run, every result is saved as a structured finding, such as a credential, an open port or a clicked phishing link. The engine checks each finding against your conditions and moves the chain forward. You can follow the path live on an interactive graph and click any node to see what the action did, what it returned and why the chain took the next step.
Below is a closer look at each capability, from building the logic to running it safely.
Open, conditional chaining logic
Build your own reusable attack path logic from scratch, drawing on any event or action from your threat arsenal: TTPs, payloads, or custom actions. Define conditions that determine what happens next, so the chain branches automatically based on what each action discovers rather than following one fixed sequence. Update your logic anytime as new actions or techniques emerge.
Red teams can encode their tradecraft once and rerun it on every engagement. Purple teams can run the same path again after a fix to confirm it's actually closed.

Live attack path mapping
Watch your attack chaining simulation unfold in real time on an interactive graph, tracking every action as it executes end to end, from first action to final objective. Each hop and pivot is rendered live as it happens, giving teams a real-time view of the attack path forming instead of a static report after the fact.
Red teams can watch their attack run in real-time, while Blue teams can review the run and compare each step with what the SOC sees, or misses. Purple team exercises become live working sessions, not a debrief a week later.

Transparent, actionable findings to prioritize chokepoints
Every action's result (a credential, an IP/port, a token, a file, and more) is automatically captured as a structured finding. Drill into any node on the map to see exactly why and how an action was performed, what it returned, and how that finding drove the next step, surfacing the chokepoints where a single fix breaks the entire path.
You don't have to hand remediation teams a long list of findings sorted by CVSS. You can show them the one misconfiguration that three attack paths depend on. That makes priorities easier to defend with IT teams and easier to explain to leadership.

Scope and safety controls
Every chained scenario runs inside guardrails you set upfront: which assets, targets, and actions are in bounds, and how far the chain is allowed to escalate before stopping. This ensure you keep every run safe and controlled.
You can test realistic attack paths in production-like environments without risking outages. Your rules of engagement are set and enforced in the platform, not kept in a separate document.

Social engineering and phishing simulation
Real intrusions often start with a phishing email, a harvested credential or a convincing pretext, not a technical exploit.
Attack Chaining lets you add social engineering and phishing actions straight into a chain. A clicked link, a submitted credential or a downloaded attachment becomes a finding like any other and feeds the next stage. You can test the full route from inbox to compromised endpoint to lateral movement in one scenario.
You no longer run phishing campaigns and technical tests as separate exercises with separate reports. You can show how a single click turns into domain access, which makes a much stronger case for awareness training and email security investment.

Autonomous Attack Chaining
Autonomous Attack Chaining runs on the same engine as Attack Chaining, with an agentic layer on top. These aren't separate features. You give an AI agent an objective, and it plans the path, runs it, reads each result and changes course as it goes, the way a real adversary would.
You decide how much control the agent gets: let it run fully on its own, or keep a human in the loop to approve key decisions.
This is ideal for teams that can't put a senior red teamer on every engagement. That includes small teams covering large environments, teams still building offensive skills and teams without the budget for regular pentests. You can run realistic multi-stage attacks whenever you need to, not just once a year.
Automated, agentic logic creation
Describe an objective and a scope in plain language, such as "Get domain admin starting from a phished workstation in the finance OU" or "Reach the customer database without touching production web servers." The agent builds the attack path logic itself and picks and orders actions the way a red teamer would plan a campaign. You can ask it to create a new chain or update an existing one, for example to add a lateral movement stage or test a TTP from a recent threat report.
Nobody has to build complex chains by hand, so junior red teamers can run realistic multi-stage scenarios from their first week. Experienced operators on a deadline can have a working campaign ready in minutes instead of days. Purple teams can turn a detection question into a test plan without writing any logic.

Autonomous execution and adaptation
After you set the objective, the agent runs the simulation on its own. It reacts to each finding by adding steps, reordering them or switching techniques to keep moving toward the goal. If a credential dump is blocked, it looks for another way in, just like a real attacker. It can also generate phishing emails and landing pages, so it can switch between technical and human vectors in the same run.
You see how far an attacker who adapts could really get, not only whether one technique was blocked. Purple teams can see exactly where defenses force the agent onto another path. That shows which controls actually stop attacks and which ones only slow them down.
Guardrails and decision log
Every autonomous chain runs inside guardrails defined upfront (what it's allowed to touch and how far it can escalate) with the boundaries automatically enforced at each step rather than left to the agent's judgment. A live, transparent record of every decision the agent takes, and why, gives operators full visibility into the run, so automated chains can operate unattended in production-like environments with confidence.
You can let chains run unattended without worrying that they'll go off-script. Red teams get a full audit trail for rules-of-engagement reviews. Blue teams can use the decision log to replay the attack against their telemetry and find detection gaps.

Agents at your disposal, or build your own
Start with OpenAEV's built-in agents, connect a pre-built agent from XTM One, or build your own for advanced or specialized operations. During a run, the orchestrator calls on specialist agents for payload creation, code generation, recon and exploitation support. These are pre-filled from your tenant defaults.
Built-in agents are on by default, and you can turn them off or replace them for any run. Each agent's discovery mode sets how much it can create from recon:
- Enrich only: adds detail to entities you already have
- Stay in scope: finds new assets, but only inside the defined perimeter
- Expand perimeter: maps attack surface beyond the starting scope
Teams with in-house tooling or niche needs, such as OT, cloud or industry-specific tradecraft, can plug in their own agents and still use the orchestration. Discovery modes let you set how aggressive recon is for each engagement, from a narrow validation test to a broad attack surface review.

Why OpenAEV Attack Chaining stands out
Attack path management isn't new, but OpenAEV's approach is. Instead of scripting a fixed sequence of steps in advance and treating the graph as a static after-action report, Chaining reacts to real runtime evidence, revealing the attack path as it actually forms.
Configure your own branching logic
Set the conditions that trigger each next step. Start from scratch or from a pre-built scenario, and edit the chain when techniques change.
Real-time, actionable graph
See every pivot and finding as it happens. Click any step to see why it ran, and find the chokepoint that breaks the chain.
Manual or autonomous
Run the chain yourself, or give an agent the objective and scope. Use OpenAEV's agents, connect XTM One or bring your own.
Driven by your threat intel
Attack chaining use ATT&CK-mapped TTPs from OpenCTI that are relevant to your organization. Every result feeds your Adversarial Exposure Score.
What you gain from continuous, red team-level testing
Fix the chokepoint first
Every finding links back to the action that produced it. You can find the one fix that breaks a whole attack path, instead of triaging each weakness on its own.
Lower testing costs
Scenarios run on demand in minutes, not over weeks of manual scripting or scheduled red team engagements. A realistic end-to-end attack costs less time and money to validate.
Test more without scaling your red team
Building multi-stage chains by hand limits how much of your environment gets tested. Automated and agent-run chains remove that limit, so more of your real attack surface gets checked.
Continuous testing to keeps up with changes
A point-in-time assessment is out of date as soon as something changes. Attack Chaining can run continuously, so your results reflect the environment you have today.
FAQ
How are attack chaining scenarios different from normal simulations?
A normal simulation typically runs a fixed set of standalone techniques or atomic tests in isolation. Attack Chaining links techniques together into a connected, multi-step attack path, where each step's outcome influences what happens next based on real runtime evidence — closer to how an actual adversary pivots through an environment than a checklist of isolated tests.
How is this different from other attack path tools?
Most tools schedule a pre-set sequence and present the resulting graph as a static after-action report once the run is done. Attack Chaining is different on two fronts: the logic itself is open and configurable (not a vendor-locked black box), and the graph is live and explorable — you see the path form in real time, not after the fact.
Can I build my own chaining logic, or do I need to use pre-built scenarios?
Both are supported. You can use and customize pre-built scenarios, or build chaining logic from scratch, defining the exact conditions that determine what happens next. This lets you tailor chains to your own environment and update them as new adversary techniques emerge.
Does Attack Chaining require a human operator to run?
No. Chains can be run manually by an operator, or handed entirely to an AI agent that's given only an objective and scope — enabling true autonomous pentesting and red teaming rather than a simulated run. You can use OpenAEV's own agents, connect one from XTM One, or bring your own.
How do I know what to fix after a chain runs?
The graph is fully explorable: drill into any node to see exactly why and how it fired. Attack Chaining also automatically surfaces the chokepoint — the single step that, if broken, collapses the entire attack path — so remediation can focus on the one fix that matters most.
Is Attack Chaining just a standalone red-teaming feature, or does it connect to threat intelligence?
It's threat-intel-native. As part of Filigran's XTM Platform, chains are built and prioritized around threat intelligence and adversary TTPs actually relevant to your organization — not a generic technique library — and every result feeds directly into your Adversarial Exposure Score.
See Attack Chaining in action
Validate the full attack path, not just isolated techniques — with OpenAEV.