Hollowpath
A unified security assessment environment.
Hollowpath brings reconnaissance, investigation, validation, exploitation, and reporting into one workspace built around a single engine — so context never gets lost between tools.
The core model: everything Hollowpath finds is tied together through this chain.
One continuous assessment, not six disconnected tools
Hollowpath is structured around how an assessment actually moves — each stage builds directly on the context the last one produced.
Discover
Map the attack surface — host and service discovery in lab environments, subdomain and endpoint discovery against external targets.
Investigate
Move through assets, services, and findings in one navigator, with the relationships between them always in view.
Validate
Confirm what you've found before acting on it — verified URLs, enumerated services, confidence-ranked candidates.
Exploit
Act on validated candidates against in-scope lab targets, with explicit, multi-step confirmation before anything runs.
Document
Findings and evidence collected throughout the assessment, exported as structured reports.
What Hollowpath does today
Hollowpath is not trying to out-perform every specialized tool at its own specialty — the value is a single workflow and shared context across all of them.
Recon & Attack Surface
Host and service discovery for lab targets, and subdomain, endpoint, and technology discovery for external targets.
Investigation Workspace
An asset-centric navigator through services, findings, and evidence, backed by a single relationship index so every view stays consistent.
Enumeration & Verification
Service and content enumeration, and URL verification, each run under explicit operator confirmation.
Exploitation
Confidence-ranked candidates against verified, in-scope lab targets, fired only after explicit, multi-step confirmation.
Findings & Evidence
Manual and automated findings, with raw and parsed evidence, and explicit links between related findings.
Scope Enforcement
A centralized, default-deny scope engine that blocks reconnaissance and exploitation against anything not explicitly in scope.
Reporting
Structured Markdown and HTML report generation, built directly from assessment data.
Context that survives the whole assessment
Everything in Hollowpath is tied together through one chain: an asset exposes a service, a service produces a finding, and a finding is backed by evidence. Selecting an asset narrows everything below it — its services, its findings, their evidence — without losing the rest of the assessment.
Related findings can be explicitly linked by the operator, building a picture of how individual results connect — without ever pretending that similarity is the same thing as correlation.
- Category, not a boolean
- A finding is an observation, a detection, or a confirmed vulnerability — never a flat “vulnerable: true/false.”
- Severity and confidence, kept separate
- How bad something would be, and how sure Hollowpath is that it's real, are tracked as distinct fields — never collapsed into one score.
- Verification is explicit
- Unverified, corroborated, or verified — a finding's verification status only changes when it's actually earned.
From engagement to report
Hollowpath generates structured Markdown and HTML reports directly from assessment data — every finding, its evidence, and its verification status, rendered from the same objects you investigated with.
Review Findings workflow
A dedicated review pass where an analyst validates, classifies, and annotates findings before final export — part of the roadmap, not yet shipped.
The messy part is the point
Real assessments don't move in a straight line — you discover, backtrack, re-validate, and document while still investigating. Hollowpath is built around that reality instead of assuming it away: one engine as the single source of truth, with every interface reading and writing the same state, so context survives the entire assessment instead of living in whichever tool produced it last.
A desktop tool in active development
Hollowpath is being built and used hands-on, one milestone at a time — not yet packaged for distribution.
Foundation
Core engine, domain model, scope enforcement, and the desktop interface.
Investigation
The asset-centric navigator, relationship index, and cross-finding linking.
What's ahead
Deeper web verification workflows, expanded exploitation awareness, and a dedicated findings-review pass before export.
