Urgent.News

What's breaking now, across thousands of outlets.

Tech

Filigran adds attack chaining to OpenAEV for automated penetration testing

French cybersecurity company Filigran SAS today launched Attack Chaining, a capability in its OpenAEV exposure validation product that links individual attack simulations into a single running path. It ships with OpenAEV v3, out today. Real intrusions rarely stop at one technique. Reconnaissance finds a target, a credential dump hands over a password and that password […] The post Filigran adds…

Filigran adds attack chaining to OpenAEV for automated penetration testing

Filigran SAS, a French cybersecurity firm, has introduced Attack Chaining, a new feature in its OpenAEV product, within version 3. This feature enables the linking of individual attack simulations into one continuous path. Real-world cyber intrusions seldom cease at a single technique; reconnaissance uncovers a target, credential dumping reveals passwords, and these passwords subsequently unlock other machines.

Each stage hinges on the results of the previous one, and standalone tests or prewritten scenarios can only address isolated vulnerabilities. They fail to adapt to new discoveries during an attack. OpenAEV meticulously records each action’s outcome as a structured data point, such as a password, open port, or permissions set, using this information to determine the subsequent move during runtime.

The software can branch out when multiple paths are available, and any control blocking a step halts the chain at that point. Users can custom-build this logic or select from techniques, payloads, or custom actions, setting conditions for each transition. The ongoing process is displayed on an interactive graph, highlighting pivots and branch points from the initial action to the ultimate objective.

Filigran claims the visualization aims to highlight chokepoints—the single step whose removal would disrupt an entire path, allowing organizations to address just one control rather than the entire sequence. The company offers two operating modes. In manual mode, operators construct the logic and oversee the execution step-by-step.

In contrast, agent-led mode allows security teams to define objectives and scope in plain language. An AI agent then creates and adjusts the chain autonomously, generating phishing emails and landing pages for social engineering components. Julien Richard, co-founder of Filigran, emphasized that "security validation must evolve with the way attackers operate."

"The goal is no longer just to prove we can block individual techniques; it is to understand whether those techniques can be combined into a path leading to a real compromise." Jean-Philippe Salles, Filigran’s vice president of product management, stated, "A validation outcome becomes actionable only when security teams can trace the logic that generated it."

A survey of 550 security decision-makers and practitioners by Filigran revealed that 88% still rely on manual processes for offensive attack simulation, while 97% struggle to determine whether their exposures can be exploited at all. Four additional enhancements accompany OpenAEV v3. A redesigned home dashboard dubbed the Adversarial Exposure Command Center consolidates posture, simulation results, and detection coverage into a single interface.

An Adversarial Exposure Score aggregates validation outcomes across various exposure sources. New red-teaming injectors enable adversary simulations against chatbots and agents constructed using large language models, employing the same engine that validates endpoint and email defenses. Finally, reporting has been streamlined to a single click for PDF generation.

OpenAEV v3 is now available to all users, with Attack Chaining exclusively available to Enterprise Edition subscribers. Founded in 2022, Filigran has secured over $100 million in funding, including October 2024's $35 million and October 2025's $58 million rounds. Notable investors include Eurazeo SE, Insight Partners LP, Accel Partners LP, and Deutsche Telekom AG.

Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at siliconangle.com →

More in Tech

More from Tuesday 1 September →