Product1 distinct publisher3 min readPublished
Attack Chaining ships in OpenAEV v3 and reads each action's output at runtime rather than following a script, which changes what a validation report is for and how much of it you should expect to receive.
The Product Desk · Product desk
Compiled by The Product DeskSomething wrong?How this is made
The Monday version of this problem is a spreadsheet. A simulation run finishes, an analyst gets a column of techniques marked not detected, every row is true and not one of them is ranked. What Filigran is selling here is the ranking, and the ranking comes out of the plumbing: OpenAEV writes what each action turned up as a structured record, a working credential or an open port, and the engine reads that record at runtime to decide the next action [2]. A prewritten scenario executes the steps in the order somebody typed them regardless of what step two found. A chain only reaches step three if step two handed it something usable.
The other half of the mechanism is where the honest signal lives. Runs branch when more than one route forward exists, and a control that blocks a step ends the chain at that step [3]. Teams assemble the logic themselves out of techniques, payloads or custom actions, and set conditions on each hop [4]. Output therefore shrinks as the estate gets harder. A well-defended network yields short chains and thin findings; a long branching graph is bad news rendered attractively. Any team that starts reporting findings-per-run to a steering committee will have inverted its own metric by the second quarter.
The demand-side case comes from Filigran's own research. Its State of Threat Management survey sampled 550 security decision-makers and practitioners and found 88% relying on manual processes for offensive attack simulation [10], which works out to 484 people [15], with 97% saying they have difficulty establishing whether their exposures can be exploited at all [11]. That is a vendor describing the market it wants, and it is still a useful description of who is stuck.
Who this is actually for is narrower than that survey implies. It suits a team with enough controls in place that the argument is about which one to change, and enough logging that somebody will ask why a given step fired. Jean-Philippe Salles, the company's vice president of product management, says a validation outcome is "only actionable when security teams can trace the logic that generated it" [9]. Correct, and worth making a vendor demonstrate on a live run rather than assert in a deck.
Two axes sort this category, and they apply to any exposure-validation tool on your shortlist, not just this one. The first is whether the next action depends on the previous action's output at runtime or the sequence is fixed when the scenario is authored. The second is whether an operator can pull up the record that caused a step to fire. Adaptive without traceability produces a finding you cannot defend in a change-control meeting. Traceable without adaptivity produces a tidy report about a path no intruder would have bothered to walk. Filigran is claiming both quadrants, and co-founder Julien Richard frames the goal as understanding whether techniques can be combined into a path that leads to real compromise rather than proving each one can be blocked [8].
The demo to ask for is the run that dies at hop two. Once your controls are doing their job, that is the run you will be looking at most weeks, and a product priced on the assumption of long dramatic chains will feel expensive by spring.
Ranked by verification strength, evidence, and original report placement.
French cybersecurity company Filigran SAS launched Attack Chaining, a capability in its OpenAEV exposure validation product that links individual attack simulations into a single running path, shipping with OpenAEV v3.
OpenAEV logs what an action turns up as a structured record, whether a password, an open port or a set of permissions, and the engine reads it at runtime to work out the next move; a working credential pushes the run deeper into the network.
Runs branch where more than one route forward exists, and any control that blocks a step ends the chain there.
Teams can assemble the chain logic themselves out of techniques, payloads or custom actions, then set conditions on each hop.
The run appears on an interactive graph while it happens, tracking pivots and branches from the first action through to the objective, and drilling into a finding shows why an action fired.
Filigran said the graph is meant to expose chokepoints, the single step whose removal collapses an entire path, so a team can fix one control instead of triaging the whole chain.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Brinqa buys PlexTrac because a ranked exposure list never proved anything got fixed1 distinct publisher
leadership
Lovable's $400M round moves employee-built software onto the audit committee's agenda1 distinct publisher
product
Ox Alpha was GLM-5.3-Flash, and the number that decides displacement is 18 billion1 distinct publisher
invest
Nearly nine tenths of Anthropic spend is not on its best model, weeks before a $2T listing2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One trade report, one company's word
How the engine picks its next hop, what the graph exposes, the 88% — all of it reaches us through SiliconANGLE's account of Filigran's announcement. Nobody outside the company has run the product, no customer is named, and the survey behind the two headline percentages is Filigran's own with sample and wording undisclosed. What keeps this from scoring lower is the reporting's discipline about attribution: you can see whose word each sentence rests on.
Shipped today, used by no one we can name
The entire uptake record is availability: v3 is out to all users, and the feature everyone will ask about sits behind the Enterprise Edition. No deployment, no design partner, no security team describing a run it actually completed. Shipping is not adoption, and a launch-day story cannot tell you which organisations will let an AI agent write phishing pages aimed at their own staff.
Mechanism explained, consequences asserted
The feature description is sober; the scaffolding around it does the selling. Julien Richard's line about combining techniques into a real compromise, arriving beside a vendor survey that finds 88% of practitioners stuck doing this by hand, sets up a problem the Enterprise Edition happens to answer. Nothing here is false. But 'the engine adapts to what it finds' is claimed rather than shown, and 'remove one control and the path collapses' is precisely the promise that needs one customer's before-and-after to mean anything at all.
The survey and the cure share an author
Filigran commissioned the research that establishes the pain, sells the remedy, gates it to its priciest tier, and sits ten months past a $58 million round that expects growth to follow. Read the 88% and the 97% accordingly. The publisher's position is visible on the page too: SiliconANGLE ends the piece soliciting support for theCUBE's network and its AWS Marketplace referral links, which tells you something about the economics of the outlet that carried the launch.
Sure what was announced, unsure what it does
What Filigran said on 1 September, and how the capability is packaged, we can state with little hesitation. Everything past that point — whether runtime branching surfaces paths a prewritten scenario misses, whether the chokepoint view holds up in a network with fifteen years of accumulated mess — rests on one account of one company's claims. Our read stays provisional by choice.