SER-004 — Attack Paths
**Attack paths as decision support**—how organizations interpret structural reachability models to prioritize action, scope investigation, and communicate impact. **Not** graph algorithms, path calculation mechanics, or product feature tours.
SER-004 — Attack Paths
Series: SER-004
Version: 1.0
Fundamental question: How should organizations use attack paths to make better security decisions?
Pillar: PIL-ATTACK-PATH
Season: SEA-002
Status: ✅ Complete — FROZEN (D1 drafts)
Review: Every 6 months (next: 2027-01-03)
Expansion: SER-004 v2.0 only — no new articles in v1.0
Learning path: LP-004
Prerequisite: SER-001 + SER-002 + SER-003 (minimum: KID-CON-0030, KID-GLS-0011)
Purpose
Attack paths as decision support—how organizations interpret structural reachability models to prioritize action, scope investigation, and communicate impact. Not graph algorithms, path calculation mechanics, or product feature tours.
Educational flow: Evidence → Investigation → Risk context → Attack path decisions
Authority anchors: KID-GLS-0011, KID-AGR-0001
Foundation for: SER-005 Threat Intelligence · SER-006 Operational Intelligence
Reading order
| Order | KID | Article | Difficulty | Time |
|---|---|---|---|---|
| — | — | Prerequisite: SER-001 + SER-002 + SER-003 | — | — |
| 1 | KID-GLS-0011 | Attack Path (term) | — | 3 min |
| 2 | KID-CON-0040 | Understanding Attack Paths | Introductory | 9 min |
| 3 | KID-CON-0041 | Attack Paths vs Individual Vulnerabilities | Introductory | 8 min |
| 4 | KID-CON-0044 | Common Misconceptions About Attack Paths | Introductory | 10 min |
| 5 | KID-CON-0042 | Why Attack Paths Change Priorities | Intermediate | 8 min |
| 6 | KID-CON-0043 | Context Matters in Attack Path Analysis | Intermediate | 8 min |
| 7 | KID-CON-0045 | Using Attack Paths for Security Decisions | Intermediate | 9 min |
| 8 | KID-CON-0046 | Attack Paths and Business Impact | Intermediate | 8 min |
| 9 | KID-GLS-0022 | Blast Radius (term) | — | 3 min |
| 10 | KID-CON-0048 | Attack Paths in Investigation | Intermediate | 9 min |
| 11 | KID-CON-0047 | When Attack Paths Are Not Enough | Intermediate | 8 min |
| 12 | KID-GLS-0023 | Decision Support (term) | — | 3 min |
| 13 | KID-CON-0049 | Attack Paths as Decision Support | Intermediate | 10 min |
Practitioner questions answered
| Question | Primary KID |
|---|---|
| What is an attack path? | KID-CON-0040, KID-GLS-0011 |
| Are paths the same as CVEs? | KID-CON-0041 |
| Why did priority change? | KID-CON-0042 |
| How much should I trust the graph? | KID-CON-0043 |
| What mistakes do teams make? | KID-CON-0044 |
| What decisions should paths drive? | KID-CON-0045 |
| How explain paths to executives? | KID-CON-0046 |
| When are paths insufficient? | KID-CON-0047 |
| How use paths in investigation? | KID-CON-0048 |
| What is the core thesis? | KID-CON-0049 |
Glossary (series terms)
| KID | Term | Status |
|---|---|---|
| KID-GLS-0011 | Attack Path | ✅ shared |
| KID-GLS-0022 | Blast Radius | ✅ |
| KID-GLS-0023 | Decision Support | ✅ |
FAQs (attached)
| KID | Question | Primary parent |
|---|---|---|
| KID-FAQ-0002 | What is an attack path? | KID-CON-0040 |
| KID-FAQ-0021 | Are attack paths the same as vulnerabilities? | KID-CON-0041 |
| KID-FAQ-0022 | Do attack paths prove an active attack? | KID-CON-0040 |
| KID-FAQ-0023 | How do attack paths help prioritization? | KID-CON-0042 |
| KID-FAQ-0024 | When should I ignore attack paths? | KID-CON-0047 |
| KID-FAQ-0025 | Do attack paths replace risk analysis? | KID-CON-0049 |
Not in scope (v1.0)
- Graph algorithms and path traversal mechanics
- Attack simulation / BAS product comparisons
- Standalone network topology documentation
- Red-team tooling tutorials
Milestone — Volume 1
Knowledge Architecture Coherence Assessment (2026-07-03): PASS WITH OBSERVATIONS.
See KNOWLEDGE_ARCHITECTURE_COHERENCE_ASSESSMENT_VOLUME1.md.
Volume 1 — Analytical Foundations: Evidence · Investigation · Risk Intelligence · Attack Paths.