Skip to content

UPDATED 07:00 EDT / SEPTEMBER 01 2026

SECURITY

Filigran adds attack chaining to OpenAEV for automated penetration testing

French cybersecurity company Filigran SAS today launched Attack Chaining, a capability in its OpenAEV exposure validation product that links individual attack simulations into a single running path. It ships with OpenAEV v3, out today.

Real intrusions rarely stop at one technique. Reconnaissance finds a target, a credential dump hands over a password and that password opens the next machine, with every step depending on whatever the last one turned up. Single-technique tests and prewritten scenarios catch specific weaknesses well enough. Neither adjusts to what an attacker finds partway through.

Each action feeds the next one. OpenAEV logs what an action turns up as a structured record, whether that is a password, an open port or a set of permissions, and the engine reads it at runtime to work out the next move. A working credential pushes the run deeper into the network. The runs branch where more than one route forward exists, and any control that blocks a step ends the chain there. Teams can assemble that logic themselves out of techniques, payloads or custom actions, then set conditions on each hop.

The run appears on an interactive graph while it happens, tracking pivots and branches from the first action through to the objective. Drilling into a finding shows why an action fired. Filigran said the graph is meant to expose chokepoints, the single step whose removal collapses an entire path, so a team can fix one control instead of triaging the whole chain.

Two modes sit on the same engine. An operator can build the logic and step through execution manually. In agent-led mode the objective and scope are set in plain language, and an artificial intelligence agent builds and adapts the chain itself, generating phishing emails and landing pages for social engineering steps.

“Security validation has to evolve with the way attackers operate,” said co-founder Julien Richard. “The goal is no longer just to prove that we can block individual techniques; it is to understand whether those techniques can be combined into a path that leads to a real compromise.”

Jean-Philippe Salles, vice president of product management at the company, said a validation outcome is “only actionable when security teams can trace the logic that generated it.”

Filigran’s “State of Threat Management” survey of 550 security decision-makers and practitioners found 88% relying on manual processes for offensive attack simulation. The company said 97% also have difficulty working out whether their exposures can be exploited at all.

Four other additions come with v3. A redesigned home dashboard called the Adversarial Exposure Command Center pulls posture, simulation results and detection coverage into a single view. An Adversarial Exposure Score aggregates validation results across exposure sources.

New red-teaming injectors run adversary simulations against chatbots and agents built on large language models, using the same engine that validates endpoint and email defenses. Reporting is now one click to a PDF.

OpenAEV v3 is available to all users today. Attack Chaining is limited to the Enterprise Edition.

Founded in 2022, Filigran has raised more than $100 million in funding, including rounds of $35 million in October 2024 and $58 million in October 2025. Investors in the company include Eurazeo SE, Insight Partners LP, Accel Partners LP and Deutsche Telekom AG.

Image: Filigran

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network

Are you an AWS customer?  Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/

 

About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Send us a news tip

Send us a News Tip

  • This field is for validation purposes and should be left unchanged.
  • Max. file size: 244 MB.

Sign in

SIGN IN

Bio

Ethics statement

Extract the signal from the noise

Get SiliconANGLE updates and analysis.

Contact us

Partner with us

Contact us

Guest inquiry