Massarمسار
Attack Path Hypothesis Engine

Massarمسار

Which exposure should we fix first, and why?

Massar turns a host scan into a ranked list of what to fix first. It maps how an attacker could chain a host's vulnerabilities into attack paths, then ranks them by likelihood times impact.

ftp:21internethosthttp:80CVEroot
rank 1 · one route of many, scored and explained
The problem

Hundreds of findings become a handful of decisions.

A single host can return hundreds of vulnerabilities. A list sorted by severity tells you which are scary, not which are reachable, or which one fix removes the most risk. Massar answers the question a defender actually has: what do I fix first, and how sure are you.

01
How a run works

From a scan to a plan, in five steps.

1

Scan

nmap finds the open ports and the software behind them.

2

Identify

each service gets a standard software id, a CPE.

3

Look up

NVD and CISA supply its known vulnerabilities.

4

Connect

what each weakness grants becomes a map of routes.

5

Rank

each route is scored: how likely, times how bad.

02
Why it is different

Prioritisation you can trust, and check.

Outcome, not just severity

Massar scores where an attacker ends up. A longer route that reaches root can outrank a scarier single finding that goes nowhere.

Honest on screen

Everything shown is a hypothesis, never a confirmed break in. Every link says how we know it: observed, measured, derived or assumed. Every score shows its own arithmetic.

AI that explains, never decides

The model judges how plausible each route looks and writes the plain language why. Delete every AI verdict and the ranking is unchanged, a test proves it.

By the numbers
Real
validated on a live machine, not a fixture
259
findings ranked in about 9 seconds
56 / 70
attack paths one fix can remove
0
exploits fired, it hypothesises, never attacks
03
The path we took

How Massar grew, one rung at a time.

A capstone measured in working software. Each step made the last one real.

Foundation

A walking skeleton

One thin slice running end to end on sample data, every stage a real function, so the seams were proven before the depth went in.

Intelligence

Real vulnerability intel

Live NVD and CISA KEV, matched by version range rather than exact strings, so a scanned service meets its actual CVEs.

Reasoning

The engine core

Deterministic chaining by privilege: a step is added only when one weakness grants what the next one needs. The ranking became explainable arithmetic.

Proof

The first real machine

A live Metasploitable host, hundreds of findings turned into a ranked, grouped worklist in seconds. The tool stopped being a demo.

Language

The AI layer

A model that judges plausibility and writes the explanation, wired in so it can never invent a route or move one up the list.

Trust

Honest by design

Provenance on every link, a coverage line so an empty result never reads as safe, and every score opening to show its own math.

04
The team

Five students, one engine.

NA
Naif
Team lead
LinkedIn
NW
Nawaf
Engineer
LinkedIn
OS
Osama
Engineer
LinkedIn
AZ
Azzam
Engineer
LinkedIn
AB
Abdallah
Engineer
LinkedIn
Academic sign off by Prof. Mudassar Aslam
NCAKAUSTKAUST AcademySITE
05
Contact

Talk to the team.

Questions, a demo, or a collaboration? Reach us by email.

[email protected]