Critical path · awaiting you
One chain reaches your customer-records database. Four hops proven, one waiting on you.
Five findings that are only Medium on their own. The operator connected them, validated every hop with the least-intrusive check available — and stopped before the last one, because confirming it touches your systems.
8Critical
3Proven chains
1,247Assets swept
1Needs you
Live attack paths3 reach a crown jewel · 1 held for you
Reaches
Held
Customer records DB
01 · Initial accessValidated
vpn-old.acme.sa
Citrix Bleed CVE-2023-49669.4
02 · ExecutionValidated
jenkins-ci.acme.sa
Log4Shell CVE-2021-4422810.0
03 · Lateral moveConfirmed
Reused CI token → cloud tenant
Credential reuse · non-destructive
04 · ObjectiveAwaiting you
records-db-01.acme.sa
2.4M customer records · NOT REACHED
Reaches
Priv-esc
Domain Admin
01 · Credential access3 / 47 cracked
dc01.corp.acme.sa
Kerberoast · offline · non-destructive
02 · DiscoveryFlagged
pki-ca01.corp.acme.sa
AD CS · ESC1 template · SAN-specifiable
03 · Privilege escalationIn progress
Enrol cert as alt subject
low-priv user → DA identity
04 · ObjectiveGated
Domain Admin
DA cert request · awaiting approval
Reaches
Chaining
Internal knowledge base
01 · Prompt injectionIngested
copilot.acme.sa
Indirect injection LLM01 via retrieved doc
02 · Info disclosureConfirmed
System prompt + tool schema
Sensitive disclosure LLM06
03 · Excessive agencyTesting 22 / 140
Unsafe tool-use
Agent tool-call abuse LLM08
04 · ObjectiveProbing
Internal knowledge base
Unscoped retrieval · read-only
Sweeping 1,247 assets · 3,204 checks today · nothing intrusive runs without you
AI reasoning core
Reasoning
local model · zero egress · in-Kingdom
2,140Hypotheses evaluated
128Candidate chains
1,247Assets modelled
18.4kTokens / sec
Live reasoning stream
Working hypothesis
Dangling CNAME on promo-bf.acme.sa → subdomain takeover → phishing-trusted origin
conf82%
Exploit chain — internet → domain crown jewel
5 findings that are only Medium on their own chain into one Critical path to the customer-records database. No single scanner would have connected them.
01 · Recon
Forgotten asset
CT-log discovery
vpn-old.acme.sa — legacy Citrix, still resolvable
Mapped
02 · Initial access
Session hijack
CVE-2023-4966 · 9.4
Citrix Bleed on the EOL gateway
Validated
03 · Execution
Foothold on CI
CVE-2021-44228 · 10.0
Log4Shell on an internal Jenkins
Validated
04 · Lateral
Reused service token
Credential reuse
CI token also valid in the cloud tenant
Chaining now
05 · Priv-esc
Over-privileged role
IAM misconfiguration
deploy-bot role → data-plane access
Awaiting approval
06 · Objective
Customer records DB
Crown jewel
2.4M records — impact if reached
Not reached
Attack surface intelligence
1,247DNS records
341Subdomains
58Live services
23EOL / legacy
9Dangling DNS
6Shadow IT
9 subdomain-takeover-prone
23 end-of-life software
11 exposed non-prod
17 expired TLS
3 public storage
vpn-old.acme.safirst seen 2018 · owner unknownCitrix NetScaler · EOL firmwareExploitable CVE
legacy-blog.acme.safirst seen 2014 · marketing (former)WordPress 4.2.1 · 14 plugin CVEsEnd-of-life
promo-bf.acme.saCNAME → deleted S3 bucketDangling CNAMETakeover-prone
jenkins-ci.acme.sainternal-ish · internet-reachableJenkins · Log4j presentRCE · in chain
autodiscover.acme.safirst seen 2013Exchange 2013 · unpatchedProxyShell
staging-payments.acme.sanon-prod · exposedStaging env · debug onInternet-reachable
wiki-2019.acme.safirst seen 2019Confluence · unpatchedOGNL RCE
ftp.acme.safirst seen 2014Plaintext FTPCleartext creds
app-ios-beta.acme.saCNAME → dead Heroku appDangling CNAMETakeover-prone
careers-2019.acme.saorphaned micrositeUnmanaged · no ownerShadow IT
s3-acme-backupspublic ACLObject storage · readablePublic exports
intranet-old.acme.safirst seen 2015Forgotten intranet · expired TLSExpired cert
High & critical CVEs found
| CVSS | CVE | Vulnerability | Asset | Status |
|---|---|---|---|---|
| 10.0 | CVE-2021-44228 | Apache Log4j2 RCE “Log4Shell” KEVIn chain | jenkins-ci.acme.sa | Validated |
| 10.0 | CVE-2017-5638 | Apache Struts2 content-type RCE KEV | apps-legacy.acme.sa | Found |
| 9.8 | CVE-2023-34362 | MOVEit Transfer SQLi → RCE KEV | filetransfer.acme.sa | Awaiting approval |
| 9.8 | CVE-2021-34473 | MS Exchange “ProxyShell” KEV | autodiscover.acme.sa | Found |
| 9.8 | CVE-2019-0708 | RDP “BlueKeep” pre-auth RCE KEV | ts-old.acme.sa | Found |
| 9.8 | CVE-2022-26134 | Atlassian Confluence OGNL RCE KEVIn chain | wiki-2019.acme.sa | In chain |
| 9.4 | CVE-2023-4966 | Citrix NetScaler “Citrix Bleed” KEVWeaponized | vpn-old.acme.sa | Validated |
| 7.5 | CVE-2014-3704 | Drupal “Drupalgeddon” SQLi KEV | news-cms.acme.sa | Found |
Awaiting your approval
Human approval required
Advance chain step 05 — priv-esc
The operator wants to confirm the over-privileged deploy-bot role reaches the records data-plane. It will use the least-intrusive read-only check.
Non-destructive · no data read or exfiltrated
Operator activity
Chaining — testing reused CI token against cloud tenant
Awaiting approval to advance chain step 05Gate
Validated CVE-2021-44228 on jenkins-ci — foothold confirmed10.0
9 dangling DNS records flagged — subdomain-takeover risk
341 subdomains recovered from certificate-transparency logsDone
Retest passed — F-102 remediation verified, finding closed
Findings by severity
Critical8
High9
Medium10
Low7
Coverage by layer
Recon & surface98%
Web & app logic84%
Identity & access72%
Cloud posture68%
AI / LLM systems45%