Sample attack path, visualized.

Every finding placed on the path it enabled, the pivots that connected them, and the crown jewels they reached.

How to read it

Kill-chain timeline: every finding sits in the phase where it fired. Attack graph: edges show what enabled what and what was extracted from what, and clicking a node reveals the request, payload and captured evidence. Intelligence flow: findings in discovery order with crown jewels flagged.

Sample from an authorized test against OWASP Juice Shop, a deliberately insecure demo application used for security training.