$59.00
CHAIN: Predictive Adversary Chaining Simulator
CHAIN predicts how an attacker moves next. Feed it a known adversary action — a phishing email, an exploited service, stolen credentials — and it chains the most likely follow-up MITRE ATT&CK techniques into a full attack path, scored, with procedures and detection guidance for each step. Built on the Unified Kill Chain and MITRE ATT&CK. Windows desktop app, no admin rights required.
Description
Predict the next move, not just the last one
CHAIN is an adversary emulation planner for red teams, purple teams, and detection engineers. Give it a known or suspected attacker action, and it predicts the most probable next steps a competent adversary would take to advance the intrusion — technique by technique, the way a MITRE ATT&CK / CALDERA-style emulation plan chains TTPs together.
Every prediction is a real ATT&CK technique with a likelihood score, a concrete procedure (“how”), and detection guidance (“what to hunt for”) — not a black-box guess.
What it does
- Seed from anything — free text (“phishing attachment to finance”) or a raw technique ID (T1003.001).
- Predicts ranked next steps — the most probable follow-up ATT&CK techniques, scored 0–100.
- Chains interactively — click a predicted action to commit it and reveal its own follow-ups, building an explorable branching attack-path tree in real time.
- Grounds every step in ATT&CK — technique ID, tactic, procedure, detection guidance, and data sources.
- Generates a full narrative report — the single most likely end-to-end path from initial foothold to objective, written for both leadership (plain-language, business-impact) and analysts (technical narrative), with an overall confidence score. Export to PDF or Markdown.
How predictions work
CHAIN blends two signals: a deterministic MITRE ATT&CK-grounded prior (kill-chain position + documented technique adjacency) with LLM reasoning that reads the path so far and your environment context to predict realistic, environment-aware follow-ups. Both scores are shown — nothing is hidden.
Runs fully offline in deterministic rules-only mode with no API key. Add an Anthropic API key for environment-aware reasoning, richer procedures, and broader technique coverage.
Who it’s for
- Red teams building CALDERA/Atomic-style emulation plans
- Purple teams mapping detection coverage to likely attacker paths
- Detection engineers prioritizing what to hunt for next
- Security leadership who need a plain-language “what happens if” narrative
What’s included
- Windows installer (per-user, no admin rights required)
- Runs entirely on your local machine — your environment context never leaves it except to the LLM provider you configure
- Full MITRE ATT&CK technique catalog and Unified Kill Chain mapping
Requirements
- Windows 10/11
- Optional: an Anthropic API key for hybrid (LLM-enhanced) mode
CHAIN is a planning and decision-support tool for authorized red-team emulation and defensive hunting. Predicted branches are hypotheses to guide emulation and detection — not ground truth.
Only logged in customers who have purchased this product may leave a review.

There are no reviews yet.