Attack-Path & Breach Simulation
Chain individual findings into end-to-end attack paths — see how a breach actually unfolds, before it does.
A single medium finding is boring; three chained together are a breach. heimdallX's breach simulation reasons over your findings and surface graph to construct realistic multi-step attack paths — initial access, pivot, escalation, impact — and scores how likely each chain is to succeed. It's the adversary's plan, written out for your defenders.
Chains, not checkboxes
The engine composes findings into ordered exploit chains: an exposed login, a leaked credential, a missing MFA control, a reachable admin panel — the sequence an operator would run. Each step carries its own evidence and confidence.
Likelihood-weighted
Every chain is scored by how achievable each step is, so a low-friction path of 'medium' issues can outrank a single 'critical' that's hard to reach. You fix the chains that actually break, not the scariest-looking single row.
ATT&CK-aligned narrative
Each simulated path maps to MITRE ATT&CK tactics so the story is legible to any SOC — from initial access through impact — and exports cleanly into your reporting.
How it works
Model
Build the exploit graph from findings + surface.
Chain
Compose multi-step paths from access to impact.
Score
Weight each chain by step-wise likelihood.
Explain
Narrate the path, mapped to MITRE ATT&CK.
$ sim breach --target acme-corp.com→ 1. leaked cred (HIBP) → 2. VPN login (no MFA)→ 3. reachable admin panel → 4. data exfilchain likelihood 0.72 · ATT&CK: TA0001→TA0010
Put it to work
Run your first scan in under two minutes. Free, no credit card, real findings.
Launch heimdallX