3 live chains · 1 critical
Scanners list issues. The operator connects them.
A finding on its own is a line in a report. The value is in the join — which weaknesses, taken together, actually walk someone from the open internet to something that matters. Red ranks by what a chain reaches, not by how many issues it found.
1Critical chainto records DB
2Chains in progress
128Candidates explored
1Awaiting your approval
Operator is chaining — step 04 of the critical path
Exploit chain — internet → domain crown jewel
5 findings that are only Medium on their own chain into one Critical path to the customer-records database. No single scanner would have connected them.
01 · Recon
Forgotten asset
CT-log discovery
vpn-old.acme.sa — legacy Citrix, still resolvable
Mapped
02 · Initial access
Session hijack
CVE-2023-4966 · 9.4
Citrix Bleed on the EOL gateway
Validated
03 · Execution
Foothold on CI
CVE-2021-44228 · 10.0
Log4Shell on an internal Jenkins
Validated
04 · Lateral
Reused service token
Credential reuse
CI token also valid in the cloud tenant
Chaining now
05 · Priv-esc
Over-privileged role
IAM misconfiguration
deploy-bot role → data-plane access
Awaiting approval
06 · Objective
Customer records DB
Crown jewel
2.4M records — impact if reached
Not reached
Other chains under construction
01
Awaiting approval
Internet → customer-records database
Dangling DNS→Citrix Bleed 9.4→Log4Shell 10.0→Token reuse→Records DB
02
Chaining
Supplier portal → internal file share
Exposed staging→Weak SSO assertion→Over-broad group→Finance share
03
Chaining
Public chatbot → internal knowledge base
Prompt injection→Unsafe tool-use→Unscoped retrieval→Internal docs
Chain 03 runs entirely through your own AI systems — the surface most tools cannot see at all.