Filigran has launched a new attack chaining capability for its OpenAEV platform, designed to help security teams test how multiple weaknesses can be combined to create a viable path through an organisation’s environment.
Released as part of OpenAEV v3, Attack Chaining allows penetration tests and red team exercises to adapt dynamically based on what a simulated attack discovers. Rather than testing individual techniques in isolation or following a fixed sequence, the platform can use findings from one stage, such as credentials, permissions or an open port, to determine what happens next.
The approach is intended to more closely reflect how real attackers operate, where an apparently minor weakness can provide the foothold needed to reach another system and ultimately sensitive data or critical assets.
From individual vulnerabilities to attack paths
Traditional security validation can be effective at establishing whether a particular technique or control works. However, Filigran argues that this can miss the wider risk created when weaknesses are combined.
Its recent State of Threat Management report found that 97% of organisations have difficulty determining whether their exposures are actually exploitable, while 84% said attacks they face often exploit risks that were already known but had not been prioritised. The study, conducted among 550 security decision-makers and practitioners, also found that 88% rely to some extent on manual processes for offensive attack simulation.
Attack Chaining attempts to address that gap by treating the result of each simulated action as an input for the next. A discovered credential, for example, could be tested against another system. If successful, the simulation could continue deeper into the environment. If a security control blocks the attempt, the chain can stop or take another route.
“Security validation has to evolve with the way attackers operate. The goal is no longer just to prove that we can block individual techniques; it is to understand whether those techniques can be combined into a path that leads to a real compromise,” said Julien Richard, co-founder of Filigran. “As adversaries become more adaptive and increasingly use AI to move faster, we need validation that can keep pace.”
AI takes on the red team
The new capability can be operated manually, autonomously through AI agents, or using a combination of the two. In operator-led mode, security teams define the attack logic and control execution themselves. In agent-led mode, a user instead provides an objective and scope in natural language, after which an AI agent can construct and adapt the attack chain according to the findings it encounters.
This could include generating phishing emails and landing pages as part of social engineering exercises.
Filigran said the agent remains subject to predefined scope controls and its decisions are logged, providing security teams with an audit trail of how the simulation reached a particular outcome. The development builds on Filigran’s wider push into agentic security automation. The company launched XTM One in June, introducing AI orchestration across OpenCTI and OpenAEV to automate workflows spanning threat intelligence, attack scenario generation, validation and remediation guidance.
Mapping the route to critical assets
OpenAEV v3 also introduces a live attack path graph that allows teams to watch a simulation progress through their environment. Each hop, branch and finding is displayed as the exercise takes place, allowing defenders to see how far the simulated attacker progressed and which security control eventually stopped it.
Filigran said this could help organisations identify “chokepoints” within attack paths. Instead of treating every vulnerability encountered during an exercise as equally urgent, teams can identify the control or weakness whose remediation would break the wider attack chain.
“A validation outcome is only actionable when security teams can trace the logic that generated it,” said Jean-Philippe Salles, VP of Product Management at Filigran. “With OpenAEV v3, teams can build or generate attack scenarios, watch attack paths unfold, and inspect the logic and evidence behind every step.”
OpenAEV v3 expands AI security testing
Alongside Attack Chaining, OpenAEV v3 includes a redesigned dashboard called the Adversarial Exposure Command Center, bringing security posture, simulation results and detection coverage into a single interface.
The release also adds an Adversarial Exposure Score for tracking validation results across exposure sources, automated reporting and AI red-teaming injectors which allows organisations to run adversarial simulations against LLM-powered agents and chatbots using the same validation engine employed to test traditional controls including EDR, SIEM and email defences.
OpenAEV v3 is available immediately, with Attack Chaining included in the platform’s Enterprise Edition.

