IT Brief Asia - Technology news for CIOs & IT decision-makers
Asia
Filigran adds attack chaining to OpenAEV v3 release

Filigran adds attack chaining to OpenAEV v3 release

Mon, 7th Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Filigran has added Attack Chaining to OpenAEV v3, a feature designed to automate multi-step penetration testing and red teaming.

The update centres on software that links the result of one security test to the next, allowing a discovered credential, open port or permission to become the starting point for a further simulated move inside a network.

The approach reflects how attackers typically operate, moving from one foothold to another rather than relying on a single isolated weakness. The new engine can continue, branch or stop based on what it finds and whether a control blocks the next step.

OpenAEV is Filigran's adversarial exposure validation product. The new release also includes a redesigned user interface, a dashboard called the Adversarial Exposure Command Centre, a scoring system for exposure results, AI red-teaming injectors and automated reporting.

Users can build their own chaining logic from scratch using events and actions from existing threat libraries, including tactics, techniques and procedures, payloads and custom actions. The logic can also be made conditional, allowing a scenario to change direction if a password works, a machine is reachable or a defensive control interrupts progress.

The update also adds an interactive attack path graph that shows each step of a simulation as it unfolds. The graph records structured findings at every stage and allows teams to trace how a path developed, why an action was triggered and where a single blocked step could break the whole route.

The feature is available in different operating modes. Security teams can run it manually, allow AI agents to orchestrate the full process, or combine the two approaches with human oversight.

In manual mode, operators define and control the testing logic directly. In agent-led mode, the user sets an objective and scope in plain language, and the software builds and adapts the chain on its own, including social-engineering steps such as phishing emails and landing pages.

Filigran used the launch to argue that many organisations still struggle to determine which security exposures are genuinely exploitable. Citing its global study of 550 security decision-makers and practitioners, it said 97% have difficulty deciding whether exposures can be used in a real attack, while 88% still rely on manual processes for offensive attack simulation.

The issue is particularly pronounced in Singapore, where only 18% of organisations use automated threat validation, the lowest rate across the eight countries covered by the survey.

Kevin Vanhaelen, Senior Vice President, Asia Pacific & Japan, Filigran, linked the release to growing pressure on security teams to show evidence of resilience.

"Australian security teams are being asked to prove their resilience to boards and regulators alike, but a once-a-year penetration test can't keep pace with how quickly critical infrastructure environments change. Attack Chaining lets teams validate continuously and see exactly how isolated gaps combine into a real breach path, so they can fix the one chokepoint that matters rather than chase every weakness in isolation. That shift from point-in-time assurance to continuous, evidence-based validation is what boards are now asking for," said Kevin Vanhaelen, Senior Vice President, Asia Pacific & Japan, Filigran.

Broader release

Beyond Attack Chaining, OpenAEV v3 adds a central dashboard intended to bring posture information, simulation results and detection coverage into one place. The new Adversarial Exposure Score is designed to combine validation results from different exposure sources into a single measure that can be tracked over time.

The software also introduces what Filigran describes as native AI red-teaming injectors for testing large language model-based agents and chatbots with the same core engine used to assess endpoint detection, security information and event management, and email defences.

Another change is one-click PDF reporting generated from simulation results, aimed at reducing the need for manual report preparation after a testing run.

Damian Skeeles, Senior Manager, Solution Engineering, Filigran, said the product was intended to make test results easier to inspect and act on.

"A validation outcome is only actionable when security teams can trace the logic that generated it. With OpenAEV v3, teams can build or generate attack scenarios, watch attack paths unfold, and inspect the logic and evidence behind every step. That means they can test more often, adapt scenarios to their own environment, and identify the specific control or weakness that needs attention without turning every validation exercise into a custom engagement," said Damian Skeeles, Senior Manager, Solution Engineering, Filigran.

Attack Chaining is available in the OpenAEV Enterprise Edition, while OpenAEV v3 has been released to all users.