How attack path mapping helps AI security agents prioritize risk Security teams have spent years chasing alerts in isolation while attackers move fluidly across cloud, identity and device boundaries. That mismatch is pushing more practitioners toward attack path mapping — using graph databases to show AI agents exactly how a threat could reach sensitive data, and where to act first. Alex Chantavy (pictured), co-founder and CEO of SubImage Inc., a cybersecurity startup that maps enterprise cloud, identity and device data into a single graph, has spent more than a decade working with graph databases. Chantavy previously worked in government cybersecurity and on Microsoft Corp.’s Azure Red Team before founding SubImage to bring an attacker’s map-based instincts to enterprise defense. “There’s a saying that attackers think in graphs, defenders think in lists,” Chantavy said. “As long as that is true, the attackers will always win.” Chantavy spoke with theCUBE’s John Furrier at the Neo4j GraphTalk event, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed why attack path mapping is critical for reliable AI security agents and how graph databases help prioritize risk. (* Disclosure below.) Attack path mapping for AI security agents SubImage traces its roots to Cartography, an open-source mapping tool Chantavy helped build at Lyft Inc. before donating it to the Cloud Native Computing Foundation. The startup finished Y Combinator’s winter 2025 batch, raised $4.2 million in seed funding, and counts Neo4j Inc. among its earliest customers. “One of the key properties of graphs is locality,” Chantavy said. “I need to know: Is this instance open to the internet? What permissions does it operate as? Who touched it last?” The stakes are rising as enterprises race to define who governs AI agent identity, a question SiliconANGLE has tracked as security teams confront agents with broad, unsupervised access. Chantavy compared the moment to cloud-native computing’s early days, when Lyft and its peers built their own open-source tooling because no vendor category yet existed. “You want to represent those many-to-many relationships faithfully,” Chantavy said. “You just can’t really do that in relational land.” Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of the Neo4j GraphTalk event: (* Disclosure: TheCUBE is a paid media partner for the Neo4j GraphTalk event. Neither Neo4j, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.) Photo: SiliconANGLE A message from John Furrier, co-founder of SiliconANGLE: Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network. Are you AWS customer? Support SiliconANGLE Financially by buying your AWS services from our Marketplace portal page and links. About SiliconANGLE Media SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.
How attack path mapping helps AI security agents prioritize risk
Full Article
Original Source
Read the full article at Siliconangle →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.