explain_attack_path
Get the full kill chain for an attack route: each hop, relationship type, probability, and MITRE technique, with provenance showing which evidence is observed and which is estimated.
Instructions
Give the full kill chain for one route: every hop, the relationship type, that hop's probability, where the probability came from (kev/epss/runtime are observed evidence; cvss/severity/heuristic are estimates), and the MITRE ATT&CK technique. Use this before explaining or acting on a route - the hop provenance is what tells you which parts of the story are evidence and which are assumption.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| path_id | Yes | The id from list_attack_paths. |