French cybersecurity company Filigran SAS today launched Attack Chaining, a capability in its OpenAEV exposure validation product that links individual attack simulations into a single running path. It ships with OpenAEV v3, out today.
Real intrusions rarely stop at one technique. Reconnaissance finds a target, a credential dump hands over a password and that password opens the next machine, with every step depending on whatever the last one turned up. Single-technique tests and prewritten scenarios catch specific weaknesses well enough. Neither adjusts to what an attacker finds partway through.
Each action feeds the next one. OpenAEV logs what an action turns up as a structured record, whether that is a password, an open port or a set of permissions, and the engine reads it at runtime to work out the next move. A working credential pushes the run deeper into the network. The runs branch where more than one route forward exists, and any control that blocks a step ends the chain there. Teams can assemble that logic themselves out of techniques, payloads or custom actions, then set conditions on each hop.
The run appears on an interactive graph while it happens, tracking pivots and branches from the first action through to the objective. Drilling into a finding shows why an action fired. Filigran said the graph is meant to expose chokepoints, the single step whose removal collapses an entire path, so a team can fix one control instead of triaging the whole chain.
Two modes sit on the same engine. An operator can build the logic and step through execution manually. In agent-led mode the objective and scope are set in plain language, and an artificial intelligence agent builds and adapts the chain itself, generating phishing emails and landing pages for social engineering steps.
“Security validation has to evolve with the way attackers operate,” said co-founder Julien Richard. “The goal is no longer just to prove that we can block individual techniques; it is to understand whether those techniques can be combined into a path that leads to a real compromise.”
Jean-Philippe Salles, vice president of product management at the company, said a validation outcome is “only actionable when security teams can trace the logic that generated it.”
Filigran’s “State of Threat Management” survey of 550 security decision-makers and practitioners found 88% relying on manual processes for offensive attack simulation. The company said 97% also have difficulty working out whether their exposures can be exploited at all.
Four other additions come with v3. A redesigned home dashboard called the Adversarial Exposure Command Center pulls posture, simulation results and detection coverage into a single view. An Adversarial Exposure Score aggregates validation results across exposure sources.
New red-teaming injectors run adversary simulations against chatbots and agents built on large language models, using the same engine that validates endpoint and email defenses. Reporting is now one click to a PDF.
OpenAEV v3 is available to all users today. Attack Chaining is limited to the Enterprise Edition.
Founded in 2022, Filigran has raised more than $100 million in funding, including rounds of $35 million in October 2024 and $58 million in October 2025. Investors in the company include Eurazeo SE, Insight Partners LP, Accel Partners LP and Deutsche Telekom AG.





