Incident path note: exploit-chain candidates deserve fast review, but IR activation should be based on exploitation evidence, containment need, scope uncertainty, or business-impact urgency.
Exploit Chain Watch
Spot dangerous combinations before they become incident paths.
This hub looks for combinations like internet-facing RCE plus PoC, KEV plus no patch, identity bypass plus privilege escalation, and exploit pressure plus weak guidance.
Chain Candidates
Items with multiple dangerous signals
Breakpoints