Attack-Path / Kill-Chain Correlation
Did these findings CHAIN into a real compromise?
Every other AgentSmack surface grades ONE channel in isolation, and the scorecard only rolls those independent signals into a blended number. This is the higher-order correlator: it consumes the same cross-surface findings envelope every scan emits and reconstructs the end-to-end attack path — entry → establish → escalate → act → exfiltrate → evade. It answers the question a CISO actually asks: did an injection enter, poison memory or RAG, drive a privileged tool, and exfiltrate data — a complete kill-chain — or are these five unrelated dings? A complete chain requires distinct lifecycle stages from distinct surfaces (one surface's repeated findings can never fake a chain), and it caps the score to not ready regardless of how few total findings there are. And when a chain IS complete, it runs a deterministic graph minimum cut over the path to answer the CISO follow-up no other surface does — which ONE fix breaks the chain? — surfacing the chokepoints and a fix-this-first remediation order. And it rates the chain's exploitability on a CVSS-like 0-100 scale that honestly modulates on causal confidence (a structurally-complete chain caps BELOW a causally-confirmed one), then emits a deterministic adversary-emulation narrative — a numbered, plain-English walk of exactly how an attacker would step through the path. It adds no new surface and no new scorecard dimension — it's a pure correlation OVER the others. Load a sample to watch the lanes light up with no live infra.
Related read-only meta-lenses over the same findings envelope: Attacker Economics / Adversary ROI · Risk Register · Remediation Plan · Cross-Surface Corroboration · Detectability / Dwell-Time (MTTD) · Containment / Recoverability (MTTR) · Kill-Chain Path Drift (across re-scans) · Whole-Stack CI Governance Gate.