---
sidebar_position: 9
title: Exploit Chains
---

# Exploit Chains

An **exploit chain** is a named, versioned attack where one vulnerability enables
the next — an SSRF that reaches internal functionality a second flaw turns into
remote code execution, an auth-bypass that unlocks a command-injection, a SQLi
that escalates to a webshell. Pentest Swarm ships a **library of the exploit
chains behind real breaches** and hunts them autonomously.

:::info Three different "chain" concepts — don't confuse them
- **Exploit chain** (this page) — a *named, CVE-tied attack* the swarm fingerprints, safely verifies, and reports.
- **[Playbook](./playbooks.md)** — a *workflow* (which tools run, in what order).
- **Kill chain** — the runtime composition of *findings* into an attacker-lifecycle narrative (in the report).
:::

## What the swarm does autonomously (and what it does not)

- ✅ **Composes** attack paths at runtime from what it discovers.
- ✅ **Selects, fingerprints, safely verifies, and executes** known exploit chains from the library — no human driving each step.
- ❌ It does **not** invent brand-new 0-day chains. Every library chain is a known, disclosed issue.

Verification is deliberately **non-weaponized**: the swarm confirms each link is
*reachable/present* (a benign canary, a read-only unauthorized response, an OOB
callback) — it does **not** detonate payloads, write webshells, or run impactful
commands. It proves the path exists; it doesn't exploit it destructively.

## Using exploit chains

```bash
pentestswarm chain list                       # what's available
pentestswarm chain info <id>                  # CVEs, product, links, references
pentestswarm chain run <id> --target <url>    # fingerprint → verify each link → report
```

For example:

```bash
pentestswarm chain run sonicwall-sma1000-ssrf-rce --target https://vpn.example.com
```

Flags on `chain run`: `--target` (required), `--scope`, `--format` (md/json/html/all),
`--report-dir`.

## The library: lean binary + on-demand updates

The binary ships a **small curated default set embedded** (works offline, instant
install). The rest of the library — and fresh chains — arrive **on demand**, so a
new chain can ship the *day a CVE drops* without upgrading the binary:

```bash
pentestswarm chain update              # sync the latest chains
pentestswarm chain pull <id>           # fetch one
```

Fetched chains land in `~/.pentestswarm/chains` and override embedded ones of the
same id. Point at a different feed with `--registry` or `PENTESTSWARM_CHAINS_REGISTRY`.

## Bundled chains (default set)

Household-name chains behind real-world breaches, including:

| Chain | CVEs | Shape |
|------|------|-------|
| SonicWall SMA1000 | CVE-2026-83548 + CVE-2026-83549 | SSRF → unauth RCE |
| Ivanti Connect Secure | CVE-2023-46805 + CVE-2024-21887 | auth-bypass → command-injection → RCE |
| Exchange ProxyShell | CVE-2021-34473/34523/31207 | path-confusion → file-write → RCE |
| MOVEit Transfer | CVE-2023-34362 | pre-auth SQLi → RCE |
| Magento StyleSmuggler | CVE-2026-75650 | template injection → unauth RCE |
| Log4Shell | CVE-2021-44228 | JNDI lookup → RCE |
| Citrix Bleed | CVE-2023-4966 | memory over-read → session hijack |
| Confluence OGNL | CVE-2022-26134 | unauth OGNL injection → RCE |
| Spring4Shell | CVE-2022-22965 | data-binding → RCE |
| PAN-OS GlobalProtect | CVE-2024-3400 | command injection → unauth RCE |
| ConnectWise ScreenConnect | CVE-2024-1709 + CVE-2024-1708 | auth-bypass → traversal → RCE |
| FortiOS | CVE-2022-40684 | admin auth-bypass |
| F5 BIG-IP | CVE-2022-1388 | iControl auth-bypass → RCE |

`pentestswarm chain list` shows the current set; `chain update` pulls the rest.

## Chain Forge — draft a chain from an advisory

When a new critical CVE drops, you shouldn't have to hand-write the chain. **Chain
Forge** turns a vulnerability advisory into a *draft* exploit chain:

```bash
pentestswarm chain forge --url https://vendor.example/advisory --cve CVE-2026-1234
pentestswarm chain forge --from advisory.txt --save
cat advisory.txt | pentestswarm chain forge
```

It reads the advisory (text, `--from` file, `--url`, or stdin), asks your
**configured reasoning model** to author the chain — the fingerprint, the ordered
links with their CVEs, and a **safe, non-weaponized** verification for each —
validates the result against the schema, and prints it for review.

It is **provider-agnostic**: it uses whatever model you've set up — a local
**Ollama** model (fully offline), **Together**, **GLM**, **Claude**, **Gemini**,
or **Muse Spark** (Meta's reasoning model — `--provider musespark`), which is a
particularly strong fit for the multi-step reasoning here.

:::warning Draft, then review — never auto-published
Chain Forge writes nothing on its own. It prints a draft; you keep it with
`--save` (into `~/.pentestswarm/chains`) or `--out <path>`, or open a PR to the
public library. **Always review a forged chain** — the model drafts it, you
verify it. Verification stays non-weaponized by design.
:::

## Contributing a chain

An exploit chain is a small YAML file: metadata (CVEs, product, affected, CVSS),
a `fingerprint` block, and ordered `links` each with **safe** verification
guidance. It's one of the cleanest contributions to make — open a PR adding a
`chains/<id>.yaml`.

:::danger Authorized testing only
Run exploit chains only against systems you own or are explicitly contracted to
test. Verification is non-weaponized by design; you are still responsible for
authorization and scope. See [Security & Responsible Use](./security.md).
:::
