HollowpathHollowpath
In active development

Hollowpath

A unified security assessment environment.

An assessment touches a lot of tools — network scanners, web probes, exploit search, manual verification — and each one produces its own disconnected output. Hollowpath structures what they find into one connected model, so an asset, its services, its findings, and the evidence behind them stay linked instead of scattered across separate tool output.

The core model: everything Hollowpath finds is tied together through this chain.

The workflow

One continuous assessment, not six disconnected tools

Hollowpath is structured around how an assessment actually moves — each stage builds directly on the context the last one produced.

01

Discover

Map the attack surface — host and service discovery in lab environments, subdomain and endpoint discovery against external targets.

02

Investigate

Move through assets, services, and findings in one navigator, with the relationships between them always in view.

03

Validate

Confirm what you've found before acting on it — verified URLs, enumerated services, confidence-ranked candidates.

04

Exploit

Act on validated candidates against in-scope lab targets, with explicit, multi-step confirmation before anything runs.

05

Document

Findings and evidence collected throughout the assessment, exported as structured reports.

Capabilities

What Hollowpath does today

Hollowpath is not trying to out-perform every specialized tool at its own specialty — the value is what happens to their results afterward: connected into one model instead of staying wherever each tool left them.

In development

Investigation Workspace

An asset-centric navigator through services, findings, and evidence, backed by a single relationship index so every view stays consistent.

In development

Findings & Evidence

Manual and automated findings, with raw and parsed evidence, and explicit links between related findings.

Foundation

Recon & Attack Surface

Host and service discovery for lab targets, and subdomain, endpoint, and technology discovery for external targets.

Foundation

Enumeration & Verification

Service and content enumeration, and URL verification, each run under explicit operator confirmation.

Foundation

Exploitation

Confidence-ranked candidates against verified, in-scope lab targets, fired only after explicit, multi-step confirmation.

Foundation

Scope Enforcement

A centralized, default-deny scope engine that blocks reconnaissance and exploitation against anything not explicitly in scope.

Foundation

Reporting

Structured Markdown and HTML report generation, built directly from assessment data.

The investigation model

Context that survives the whole assessment

A finding rarely means much by itself — what matters is how it relates to everything else the assessment has already turned up. Everything in Hollowpath is tied together through one chain: an asset exposes a service, a service produces a finding, and a finding is backed by evidence. Selecting an asset narrows everything below it — its services, its findings, their evidence — without losing the rest of the assessment.

Related findings can be explicitly linked by the operator, building a picture of how individual results connect — without ever pretending that similarity is the same thing as correlation.

Category, not a boolean
A finding is an observation, a detection, or a confirmed vulnerability — never a flat “vulnerable: true/false.”
Severity and confidence, kept separate
How bad something would be, and how sure Hollowpath is that it's real, are tracked as distinct fields — never collapsed into one score.
Verification is explicit
Unverified, corroborated, or verified — a finding's verification status only changes when it's actually earned.
Reporting

From engagement to report

Hollowpath generates structured Markdown and HTML reports directly from assessment data — every finding, its evidence, and its verification status, rendered from the same objects you investigated with.

In development

Review Findings workflow

An analyst can already record what they believe about a finding — confirmed, false positive, needs further review, or accepted risk — independent of how it was originally verified. That review doesn’t reach the generated report yet; connecting the two is what’s left.

Built for real assessments

The messy part is the point

Real assessments don't move in a straight line — you discover, backtrack, re-validate, and document while still investigating. Hollowpath is built around that reality instead of assuming it away: one engine as the single source of truth, with every interface reading and writing the same state, so context survives the entire assessment instead of living in whichever tool produced it last.

Where Hollowpath is today

A desktop tool in active development

Hollowpath is being built and used hands-on, one milestone at a time — not yet packaged for distribution.

Complete

Foundation

Core engine, domain model, scope enforcement, and the desktop interface.

In progress

Investigation

The asset-centric navigator, relationship index, cross-finding linking, and an analyst's own review of individual findings.

Direction

What's ahead

Deeper web verification workflows, expanded exploitation awareness, and connecting findings review through to the generated report.