Continuing my decision model journey with Jev. We know that an Nmap scan tells you what ports are open. It does not tell you which of these hosts matter. You may find a vCenter console, a Jenkins server, and the company blog can all look the same from the outside: TCP 443 or 8443, a TLS certificate, a web page. Typical attack path tools need a distinction before they can do Read more about Finding crown jewels in Nmap scans with Jev!
Finding crown jewels in Nmap scans with Jev!
This post details a tool I wrote to use the Jev detection model and create attack paths from nmap scans.







