← All help articles

Attack paths & your exposure radius

How individual findings chain together into attack paths, how to read the way-in to business-impact sequence, and why fixing one step breaks the whole chain.

A single security issue on its own is rarely how a business gets breached. Attackers combine several smaller weaknesses into a route: a way in, a way to gain control, and a way to steal data. The attack paths view — your "exposure radius" — shows those routes in plain language, built from the issues actually open in your account right now.

How findings chain into attack paths

We take your open findings and run them through a ruleset that knows the common attacker playbooks. When a set of findings lines up into a recognised route, we present it as one attack path — an ordered chain rather than a list. Each rung of the chain has a plain label:

  • Way in — the weakness an attacker would use to get a foothold.
  • Gains control — the follow-on issue that lets them escalate.
  • Steals data — the step that turns access into a data loss.

The chain always ends with "What it costs you" — the real business impact in everyday terms, so you can see why the combination matters even if each individual finding looked minor.

If your open findings don't line up into any known playbook, the page tells you so — that's a good sign, and it changes as you fix or introduce findings.

How to set it up

There's nothing to configure. Attack paths are derived automatically from your open findings, so:

  1. Make sure you've run at least one scan — with no findings there's nothing to chain.
  2. Open Attack paths to see the routes your current issues open up.

How to read your results

  • Paths are listed most urgent first. Each card shows a severity badge and a likelihood meter (likely / could be / harder to exploit), so you know both how bad and how reachable it is.
  • Read a card top to bottom: it starts with the entry point, walks the numbered steps, and ends in the business impact.
  • The most efficient move: fixing any single step breaks the whole chain. Look for a step that appears in several paths and fix that finding first — you'll collapse multiple attack paths at once.
  • As you close findings, paths disappear. The goal is an empty page.