KNULL / INTERACTIVE DEMO
Breach Path.
Explore how an attack path connects. Select its steps and simulate the fix that breaks the chain.
PATH 01
OPEN PATHExposed panel
STEP 01 / 04
Forgotten subdomain
staging.acme.example, no owner.
STEP 02 / 04
Exposed admin panel
reachable without VPN.
STEP 03 / 04
Default credentials
never changed after deploy.
STEP 04 / 04
Customer data access
full export possible.
WHAT TO FIX FIRST
Take staging.acme.example off the internet and rotate the default credentials.
PATH 02
OPEN PATHLeaked token
STEP 01 / 03
Employee public repo
linked from their profile.
STEP 02 / 03
API token in git history
old commit, never rotated.
STEP 03 / 03
Cloud storage access
backup bucket.
WHAT TO FIX FIRST
Revoke the leaked token and purge the secret from the repo history.
PATH 03
OPEN PATHReused credentials
STEP 01 / 03
Credentials in a third-party breach
from an unrelated service.
STEP 02 / 03
Reused on remote access
same password, no second factor.
STEP 03 / 03
Foothold on the internal network
from outside, as an employee.
WHAT TO FIX FIRST
Force a reset on the reused passwords and require a second factor on remote access.
Explore the steps. See where to break the chain.acme.example
YOUR NEXT PENTEST
Request an assessment Know what to fix first.
Manual testing. Reproducible evidence. Prioritised fixes.