Hollowpath
A unified security assessment environment.
An assessment touches a lot of tools — network scanners, web probes, exploit search, manual verification — and each one produces its own disconnected output. Hollowpath structures what they find into one connected model, so an asset, its services, its findings, and the evidence behind them stay linked instead of scattered across separate tool output.
The core model: everything Hollowpath finds is tied together through this chain.
One continuous assessment, not six disconnected tools
Hollowpath is structured around how an assessment actually moves — each stage builds directly on the context the last one produced.
Discover
Map the attack surface — host and service discovery in lab environments, subdomain and endpoint discovery against external targets.
Investigate
Move through assets, services, and findings in one navigator, with the relationships between them always in view.
Validate
Confirm what you've found before acting on it — verified URLs, enumerated services, confidence-ranked candidates.
Exploit
Act on validated candidates against in-scope lab targets, with explicit, multi-step confirmation before anything runs.
Document
Findings and evidence collected throughout the assessment, exported as structured reports.
What Hollowpath does today
Hollowpath is not trying to out-perform every specialized tool at its own specialty — the value is what happens to their results afterward: connected into one model instead of staying wherever each tool left them.
Investigation Workspace
An asset-centric navigator through services, findings, and evidence, backed by a single relationship index so every view stays consistent.
Findings & Evidence
Manual and automated findings, with raw and parsed evidence, and explicit links between related findings.
Recon & Attack Surface
Host and service discovery for lab targets, and subdomain, endpoint, and technology discovery for external targets.
Enumeration & Verification
Service and content enumeration, and URL verification, each run under explicit operator confirmation.
Exploitation
Confidence-ranked candidates against verified, in-scope lab targets, fired only after explicit, multi-step confirmation.
Scope Enforcement
A centralized, default-deny scope engine that blocks reconnaissance and exploitation against anything not explicitly in scope.
Reporting
Structured Markdown and HTML report generation, built directly from assessment data.
Context that survives the whole assessment
A finding rarely means much by itself — what matters is how it relates to everything else the assessment has already turned up. Everything in Hollowpath is tied together through one chain: an asset exposes a service, a service produces a finding, and a finding is backed by evidence. Selecting an asset narrows everything below it — its services, its findings, their evidence — without losing the rest of the assessment.
Related findings can be explicitly linked by the operator, building a picture of how individual results connect — without ever pretending that similarity is the same thing as correlation.
- Category, not a boolean
- A finding is an observation, a detection, or a confirmed vulnerability — never a flat “vulnerable: true/false.”
- Severity and confidence, kept separate
- How bad something would be, and how sure Hollowpath is that it's real, are tracked as distinct fields — never collapsed into one score.
- Verification is explicit
- Unverified, corroborated, or verified — a finding's verification status only changes when it's actually earned.
From engagement to report
Hollowpath generates structured Markdown and HTML reports directly from assessment data — every finding, its evidence, and its verification status, rendered from the same objects you investigated with.
Review Findings workflow
An analyst can already record what they believe about a finding — confirmed, false positive, needs further review, or accepted risk — independent of how it was originally verified. That review doesn’t reach the generated report yet; connecting the two is what’s left.
The messy part is the point
Real assessments don't move in a straight line — you discover, backtrack, re-validate, and document while still investigating. Hollowpath is built around that reality instead of assuming it away: one engine as the single source of truth, with every interface reading and writing the same state, so context survives the entire assessment instead of living in whichever tool produced it last.
A desktop tool in active development
Hollowpath is being built and used hands-on, one milestone at a time — not yet packaged for distribution.
Foundation
Core engine, domain model, scope enforcement, and the desktop interface.
Investigation
The asset-centric navigator, relationship index, cross-finding linking, and an analyst's own review of individual findings.
What's ahead
Deeper web verification workflows, expanded exploitation awareness, and connecting findings review through to the generated report.
