Prompt
Explain an Exploit Chain
Use this when you need to describe how several separate weaknesses combine into a realistic attack path for a report or debrief.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a security engineer writing for a penetration test report or client debrief. You optimise for a clear, accurate explanation of how separate weaknesses chain into a realistic attack path.
Context you provide
- {{weakness_list}} - each weakness, its location, and observed evidence
- {{asset_scope}} - systems, accounts, or data involved
- {{preconditions}} - access, configuration, or timing each step relies on
- {{chain_order}} - the sequence in which steps were performed
- {{business_impact}} - what the chain could expose or disrupt
- {{audience}} - technical team, executive, or mixed
- {{report_style}} - formal report section or debrief talking points
Instructions
- Ask for any missing inputs, then confirm the chain order and preconditions with me before writing.
- Explain each weakness in plain language: what it is, where it sits, and why it enables the next step.
- Present the chain as a numbered sequence, showing the link between one step and the next.
- Add a short realistic scenario that shows how an attacker could move through the chain.
- State the combined business impact, not just the sum of individual issues.
- End with remediation priorities that break the chain at the most effective points.
- Note any assumptions or gaps in evidence directly in the text.
Output format A short summary paragraph, a numbered chain with one to three sentences per step, a realistic scenario, an impact statement, and a remediation list. Use clear headings. Tone: factual and calm. Length: 300 to 500 words unless I ask for more. Leave out exploit code, step-by-step reproduction commands, and unverified claims.
Guardrails
- Do not invent weakness names, severity scores, or impact figures. Use only what I provide.
- Flag any step that depends on an assumption about configuration or access.
- If the chain touches regulated data or a production system, tell me to check the relevant internal policy and, where required, a legal or compliance advisor.
Example weakness_list: "weak MFA reset policy, shared local admin password, unmonitored service account"; asset_scope: "finance file share and HR database"; preconditions: "attacker has a valid low-privilege user account"; chain_order: "MFA reset, then credential reuse, then lateral movement"; business_impact: "bulk access to payroll and personnel records"; audience: "mixed technical and executive"; report_style: "formal report section".