A scenario is a set of findings living on real components. Place findings, pick one to evaluate, and the diagram shows where its trigger can — and can’t — arrive. A finding is internet-reachable if any of three branches fires: a direct network path, a confirmed second-hand trigger, or a chain off another reachable finding sharing its host.
Each component can hold one finding. Click a box to add or select one; the gold-ringed box is the one being evaluated now.
Standing controls on the paths between components. Each one can cut a route the payload would otherwise take.
The chain branch looks at the other active findings sharing the evaluated finding’s host boundary — automatically. This readout is derived, not entered.
Each candidate must be directly reachable on its own before it can serve as an entry point, and its confidence is derived from its facts by a governed, versioned triage rule — not proof of RCE. Full CIA impact alone is possible-only; automatic promotion requires execution evidence, a strict execution CWE, or full impact corroborated by a qualifying conditional CWE. Only a high-confidence candidate auto-promotes, and the downstream CVSS vector never changes. memo: E₀ over ℱ(B(a))
Read-only view. Boxes with a finding show a chip; the gold-ringed box is the one being evaluated. Green edges carry the payload, red marks where it’s cut, and the purple hop is a chained-execution promotion off another finding.
Each bracket is a yes-or-no indicator (1 or 0); the whole thing is an OR — any “1” makes the finding IRV. The downstream CVSS vector never changes; G₀ only records that a co-resident, directly reachable entry point promoted this finding, and only a high-confidence entry point (E₀=high) sets it.