FeatureProvenance Tracking

Evidence Graph

Full provenance tracking and reasoning transparency for every action across the attack lifecycle. Every finding includes a complete chain of evidence — from initial discovery through verification — with replay capability and confidence scoring.

Attack Chain · 7 evidence nodes
Discovery · example.comconfidence 0.94
Portal · admin.example.comconfidence 0.97
XSS · /search?q=verified · replay ready
SSTI · /api/renderconfirmed · RCE chain
Verified Pending Confirmed
100%
Provenance Coverage
99.7%
Verification Accuracy
14+
Evidence Types
<2s
Graph Query Time
Capabilities

Every finding tells a story. Here's the full narrative.

Attack Chain Visualization

Graph

Graph-based visualization of the complete attack path — from initial reconnaissance through exploitation and lateral movement.

Reasoning Transparency

Explainability

Every decision made by the AI is recorded with full reasoning chains, LLM prompts, tool outputs, and intermediate results.

Replay Capability

Validation

Every finding can be replayed on demand — raw requests, responses, timing, and evidence are captured and preserved.

Confidence Scoring

Scoring

Multi-factor confidence scoring based on evidence strength, reproducibility, attack complexity, and environmental factors.

Chain of Custody

Security

Cryptographic chain of custody for every piece of evidence — tamper-proof audit trails suitable for compliance and legal proceedings.

Regression Tracking

Lifecycle

Track finding status across scans — new, fixed, regressed, or unchanged — with visual diff and trend analysis.

Process

How evidence is captured and verified

01

Capture

Every action — scan, request, response, tool output, LLM decision — is captured in real-time with full context, timing, and metadata. Nothing is discarded.

02

Link

Evidence is automatically linked into an attack chain graph. Each node represents a discrete action or finding, with edges representing causality and dependencies.

03

Verify

Each finding is independently replayed and validated. Confidence scores are calculated from evidence strength, reproducibility, and attack complexity.

04

Present

The complete evidence graph is presented with interactive visualization, searchable provenance, and exportable chain-of-custody reports.

Provenance Graph
Recon
3 nodes
Vuln
5 nodes
Exploit
4 nodes
Deep Dive

Every piece of evidence, fully traced

Evidence Capture

Every action in the attack lifecycle is captured with full context and metadata.

HTTP request/response pairs with timing
LLM prompts, outputs, and reasoning chains
Tool execution logs and exit codes
Screenshots and DOM snapshots
Network captures (pcap) for exploitation
Raw output from scanners and fuzzers

Graph Visualization

Interactive graph-based visualization of the complete attack path.

Multi-layered attack chain visualization
Causality edges with dependency tracking
Severity-based node coloring and filtering
Time-series playback of attack progression
Zoom, pan, and drill-down to evidence detail
SARIF and GraphML export formats

Replay Engine

Independently replay every finding to verify and demonstrate exploitability.

One-click finding replay
Raw request/response inspection
Timing and latency analysis
Idempotent replay — safe to run multiple times
Regression detection — track fixed vs. recurring
Export as curl, Python, or Burp Suite

Reasoning Transparency

Full visibility into how the AI reached each decision and finding.

LLM prompt history for every decision
Chain-of-thought reasoning traces
Alternative hypotheses considered and rejected
Tool selection rationale
Confidence factors and scoring breakdown
Audit log for compliance review
Integrations

Visualize evidence where you work

Neo4jElasticsearchGrafanaKibanaSplunkDatadogJiraSlackPagerDutyGitHub IssuesGitLab IssuesSARIFSTIXOpenCVE
Get Started

Full provenance, zero blind spots

See every step of the attack chain with complete evidence, reasoning, and replay capability.