Skip to content

Graph Reasoning

Cascade builds a graph of your application, walks it, and reasons about attack chains across endpoints, identities, and state transitions. Graph reasoning connects individual observations into an attack path.

What the Graph Contains

The reasoning graph Escape builds for every assessment is populated from:

  • Endpoints with their parameters, auth requirements, and observed response shapes.
  • Data: the shape and classification of every value the app produces and consumes.
  • Identity: the roles and permissions exercised by each authenticated run.
  • State transitions: how a call to one endpoint changes the responses of another.

Put together, that graph tells the agent what happens when it pulls a particular thread: which other endpoints become reachable, which fields become predictable, which authorization boundaries are now crossable.

Why It Matters

Graph reasoning helps Cascade test how endpoints, identities, and workflows interact. For BOLA, it tests whether one identity can access another's objects. For mass assignment, it tests whether changing a field lets an attacker cross a privilege boundary.

What You See in the UI

Every finding from an AI Pentesting assessment carries the chain of reasoning the agent followed: which endpoint it started from, which values it learned, what it tried next, and where the attack landed. That trace is what turns a claim into evidence. See Proof of Exploit for the evidence format and how to hand it to engineering.

See How It Works for how an AI Pentesting assessment runs end to end, and the individual agent pages under this section for the classes of attack each one runs.