🎉 VSEC Test v4.0.1 is now live! Release Notes ↗

Attack Paths

An Attack Path represents a plausible route by which an attacker could realize a threat. It is composed of one or more Attack Steps. An attack path has no name and no feasibility fields of its own — its feasibility derives from its steps (see How feasibility works).

List View

Open Risk ManagerLibrariesThreat Library, then select the Attack Paths tab.

The table shows each path’s ID (its auto-generated AP-xxx reference), Description, Attack Steps (reference chips), and an Actions column. Only the ID cell is a link — click it to open the detail page.

  • Create — click New in the toolbar. The New Attack Path dialog has a required Description plus optional Example and Attack Steps (multi-select). The reference is auto-generated — there is no reference input.
  • Delete — click the delete icon in the Actions column; a confirmation dialog appears before permanent removal.

Detail Page

Click a path’s ID in the list to open its detail page. A Return to Attack Paths link navigates back to the list.

Details

FieldDescription
ReferenceAuto-generated identifier (e.g. AP-001)
DescriptionFree-text explanation of how the attack proceeds (required)
ExampleIllustrative example of the path in action

Attack Steps

Tab listing the Attack Steps that make up this path. Click a step’s ID to navigate to the Attack Step detail page.

How Feasibility Works

Attack paths carry no feasibility ratings themselves. The five ISO/SAE 21434 attack-potential factors — Elapsed Time, Specialist Expertise, Knowledge of Item/Component, Window of Opportunity, and Equipment — are entered on the individual Attack Steps. A path’s feasibility derives from its steps: when scoring a risk, the scoring engine sums the attack-potential points of the steps in each linked path and uses the easiest path — the one with the lowest total — to drive the risk’s feasibility.

Editing

Click Edit on the detail page to open the path in a modal form dialog. Click Save Changes to persist or Cancel to discard.

Last updated on