Platform · Exposure

Attack paths from what attackers can actually see

An exposed service is a finding. The path it opens through a company's weak controls is a risk. Testify shows the second, and says exactly how much of it was seen.

Testify builds attack paths from each portfolio company's observed external exposure through its open control gaps to Impact or Exfiltration, and prices the blast radius on the firm's own loss model. Only the entry can be observed; every link after it is inferred and labeled that way, with entry and chain confidence shown separately. Findings come from attack-surface connectors and are stored in a self-hosted OpenCTI; the findings and all analysis stay inside the firm's deployment, and only the connector lookups go out.

From exposure to path

Attack-surface connectors (Shodan, GreyNoise, Have I Been Pwned and crt.sh) report what is reachable from the internet. Testify turns those findings into the technique an attacker would use: an exposed admin panel or database becomes T1190 (Exploit Public-Facing Application), a remote-access port becomes T1133 (External Remote Services), and leaked credentials become T1078 (Valid Accounts). Threat-intelligence tags such as GreyNoise activity raise confidence in an entry; they never create one. Connector lookups send only a company's attested domains or IPs to those services, and only with that company's consent; findings, correlation and all AI stay inside your deployment.

Through the company's own gaps

Open control gaps in the company's live control state are mapped from MITRE ATT&CK techniques to CIS Controls. A path runs from an entry tactic to a terminal tactic (Impact or Exfiltration) through the gaps that leave each step unmitigated. Named paths such as “Credential Compromise → Ransomware” carry a standard remediation.

Observed or inferred, on every link

  • Only the entry can be observed. Every later step is inferred: reachable if attempted, not seen happening.
  • Entry confidence and chain confidence are shown separately and never rounded into one number.
  • Detection, response and recoverability appear as coverage lanes naming the specific CIS safeguards on the path.
  • Blast radius is a Low / Likely / High range from the firm's loss model; a maturity-based estimate is labeled as an estimate.

What we monitor, and with whose consent

Each portfolio company keeps its own attested domain footprint. External monitoring runs only with that company's recorded consent, every connector run leaves a per-company receipt, and a company that has never been scanned is shown as never scanned, not as clean. The footprint explains the dollar figure; it never moves it.

Ask in plain language

The local assistant can draw a company's path and summarize which portfolio companies have a way in, answering from the evidence already in the register. No API calls, no third-party model.

Frequently asked questions

How does Testify find attack paths for a portfolio company?

It starts from observed internet-facing exposure reported by attack-surface connectors, maps that exposure to an entry technique, then follows the company's open control gaps (mapped from MITRE ATT&CK to CIS Controls) to Impact or Exfiltration. The blast radius is priced on the firm's own loss model.

Are Testify's attack paths observed or inferred?

Both, and each is labeled. The entry is observed from real external findings; every step after it is inferred from open control gaps. Testify shows entry confidence and chain confidence separately and never presents an inferred step as observed.

Does Testify scan portfolio companies without permission?

No. External monitoring runs only against domains a company has attested and only with that company's recorded consent, and every run leaves a receipt.

See it on your portfolio

Testify is accepting early customers. Portfolio Directors and Operating Partners get priority access to a guided walkthrough.