Wednesday, September 30, 2026

Inside PCYBOX AttackGraph: how a browser lab turns attack paths into something you can watch and defend

Inside PCYBOX AttackGraph: how a browser lab turns attack paths into something you can watch and defend

PCYBOX AttackGraph is an open source, browser-only simulation lab where authorized professionals build fake infrastructures, replay conceptual attacks mapped to MITRE ATT&CK, and verify whether their defenses actually break the kill chain.

ToolMister-iks/pcybox-attackgraph — browser-based attack graph lab for simulating and defending conceptual attack paths
CategorySecurity education / attack path simulation (TypeScript, Apache-2.0)
Primary UseBuilding simulated labs with .attackgraph.json, replaying MITRE ATT&CK-mapped attack scenarios, and testing whether controls like segmentation or MFA contain them
Safe UsePurely educational simulation for authorized training, defensive architecture design, and lab exercises — the tool explicitly never scans, contacts, or attacks real systems
Telemetry NoteZero footprint: no server, no account, no tracking; labs travel in the URL fragment or exported files, so nothing observable leaves the browser

PCYBOX AttackGraph is one of those rare security projects that is deliberately not an attack tool at all. It is a fully client-side lab, written in TypeScript, where you assemble a simulated infrastructure on a canvas, press Run attack, and watch a conceptual adversary traverse it step by step. The tagline on the README — Build. Attack. Defend. Understand. — captures the loop it is built around, and the project's own words are emphatic that it is simulation only: the lab never scans, contacts, or attacks a real system, and techniques are described at a conceptual level mapped to MITRE ATT&CK without any exploitation procedure. That framing makes it suitable for training rooms, architecture reviews, and defensive exercises without any of the legal baggage of a live-fire range.

What makes the tool interesting technically is its explainability posture. Every step of the simulated attack comes with the reason it succeeded, and every control states exactly which precondition it breaks. A dedicated Why? panel lists the preconditions that held, the control that stopped a step, and — importantly — the controls that could have stopped it, with a one-click shortcut to try them. There is also a Before / after view that compares your hardened architecture against the same lab stripped of all controls, which is exactly the artifact you want in front of a stakeholder when arguing for segmentation budget. The README calls this design honest: MFA does not protect a service account, patching stops the entry point but not an attacker already inside, and a future WAF stops injection but not every vulnerable component. That refusal to give controls magic powers is unusual in educational tooling and worth appreciating.

The architecture, as documented in the repository layout, is clean and modular. The web application lives in apps/web/ and is built on React, React Flow, and Vite. The simulation core is isolated in packages/engine/ as pure TypeScript with no DOM dependency and a full test suite, which is the right call for determinism and portability. The lab format is formally specified in packages/schema/ as a JSON Schema for the .attackgraph.json file, localization strings are shared in packages/i18n/, and a command-line tool lives in packages/cli/ under the attackgraph command. Ready-to-use labs sit in content/templates/ under a CC BY 4.0 license for the educational content, while the code itself is Apache License 2.0.

The engine internals deserve a paragraph of their own. The pipeline is expressed as: lab (.attackgraph.json) flows into validation, then into the engine running inside a web worker, which produces a story of events that feeds the map, timeline, and Why? panel. The engine saturates the attacker's capabilities round by round — footholds, credentials, data access — and each technique carries explicit preconditions and effects, while each control breaks one precise precondition. Because rounds are processed breadth first, the story replayed for any reached target is one of its shortest derivations, meaning the timeline you watch is effectively a minimal attack path. That is a genuinely elegant property for teaching attack path analysis: the learner sees the skeleton of the compromise, not an arbitrary meandering trace.

For a defensive professional, the immediate use cases are threat modeling and control validation on paper architectures before they exist. The current engine ships with 8 techniques and 6 controls — network segmentation, secrets vault, MFA, patching, least privilege, and credential protection — which is a compact but meaningful catalog for demonstrating defense in depth, lateral movement, and blast radius. Three templates come bundled: Web Application (flat network, leftover secrets), Small Office (shared local admin password, remote desktop exposed to the Internet), and Active Directory (domain admins logging on to workstations, admin tiering). Each template mirrors the failure patterns most consultants see in real engagements, which makes them strong conversation starters in tabletop or training contexts.

Getting started is deliberately frictionless. The README points to a live demo hosted on GitHub Pages that requires no account and no installation, or you can run it locally with pnpm install and pnpm dev after cloning the repository. Keyboard controls are documented: Space plays or pauses, arrow keys step through the attack, and Home returns to the start. The editor supports drag-and-drop placement from a palette, connections drawn by dragging from an element's side dot, undo and redo via Ctrl+Z and Ctrl+Y, autosave to browser storage, and export/import plus sharing by link — the entire lab travels in the URL fragment, so nothing is ever stored on a server.

The CLI extends the tool beyond the browser and into scripted or CI-adjacent workflows. The README documents attackgraph validate for checking lab files, attackgraph list for inspecting scenarios, attackgraph simulate with flags like --scenario phishing and --enable tiering, and attackgraph compare for contrasting control configurations, including a --lang fr switch for French output. A --format markdown or --format json option on simulate makes the results consumable by other tooling, which hints at the project's ambition to become a composable component in security education pipelines rather than just a toy visualization.

Accessibility and privacy are treated as first-class requirements rather than afterthoughts. The README highlights a Text view that is a full equivalent of the graphical map for screen reader users, keyboard operability throughout, reduced motion support, light and dark themes, and English and French localizations. The performance discipline is also notable: a hard budget of at most 250 kB of initial JavaScript (gzip), enforced by CI — the build fails if it is exceeded. Combined with the pnpm verify pipeline covering text checks, types, tests, build, and bundle budget, the repository reads like a project run by someone who cares about engineering hygiene as much as pedagogy.

The roadmap shows a coherent progression rather than a feature grab. Version v0.2, marked in progress, covers the lab editor, the three templates, and the command line tool. Version v0.3 promises attack paths, choke points, blast radius analysis, an embeddable view, and an offline PWA. Version v0.5 targets a challenge mode, a teacher mode, and 10 missions aligned with NICE, ECSF, and CyBOK frameworks — a strong signal that the author is building for formal security curricula. Version v1.0 aims for a stable lab format, 8 templates, and 9 languages including Arabic and Chinese. A full French specification document in docs/ underpins the plan.

From a defender's telemetry perspective, there is nothing to observe because there is nothing to leave behind: no server, no account, no tracking. The only artifacts are local — browser autosave, exported .attackgraph.json files, and URLs carrying labs in their fragment. This is worth stating explicitly in an industry where even training tools sometimes phone home; here the privacy claim is architectural, not just a policy promise.

The contribution model rounds out the picture: the README invites code, labs, and translations, and explicitly asks for reviews by security practitioners of the technique catalog, with a CONTRIBUTING.md, a code of conduct, and a SECURITY.md for vulnerability reporting. With 38 stars, the project is early, but the documentation depth — engine docs, lab format docs, a specification, and bilingual READMEs — is well beyond what most projects at this stage ship. The trademark note clarifies that MITRE ATT&CK® belongs to The MITRE Corporation and the project is unaffiliated, which is a properly careful attribution.

If your work involves teaching attackers' logic to defenders, defending architecture proposals before they are built, or running tabletop exercises that need visual, explainable attack paths, PCYBOX AttackGraph earns a bookmark. It is a simulation and education tool in the strictest sense, its deterministic and explainable engine makes the reasoning behind each step inspectable rather than magical, and its browser-only, zero-telemetry design means it can be used in restricted training environments with minimal friction. The honest-controls philosophy — where MFA cannot save a service account and patching cannot evict a resident intruder — is the kind of nuance that separates useful security education from checkbox theater.

Official project repository for Mister-iks/pcybox-attackgraph.
Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.

Share articleFacebookXLinkedIn

Continue exploring

Browse all articles →

0 comentários:

Post a Comment

Note: Only a member of this blog may post a comment.