Attack path
A sequence of flaws or conditions that can let an attacker move from a starting point to a relevant asset.
Direct definitions, each with the reason the concept matters when buying a penetration test or reading its report.

A term on its own does not define risk. Use the definitions to interpret the report, then apply the context of your own environment before prioritizing any action.
Written to bring technology, leadership and governance closer together.
A sequence of flaws or conditions that can let an attacker move from a starting point to a relevant asset.
A test type that starts with little or no internal information about the environment.
A scoring model used to communicate the technical characteristics and severity of vulnerabilities.
A public identifier assigned to a known vulnerability in a product or component.
A record demonstrating how an exposure was observed or validated.
A test type where the team receives limited information or credentials to assess internal areas of the flow.
A knowledge base that organizes attacker behavior into tactics and techniques.
An authorized assessment that sets out to identify and validate security risk within a defined scope.
A collaborative exercise between offensive and defensive capabilities.
A new validation run after the team reports that a fix has been applied.
The set of assets, services, applications and interfaces that can be reached or exploited.
A technical or logical weakness that can create impact when exploited in a given context.
The scope assessment connects assets, risks and deliverables to the reality of your company.
Ready to assess your company's risk?