CanEscalateTo

Derived: source can become an identity with strictly greater privilege (rolls up an escalation chain).

derived DERIVED_ATTACK_PATH nature: derived walkable weight 0 high value
Identity  ── CanEscalateTo ──▸  Identity

Source types

Identity

Target types

Identity

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

naturederived

Rules that emit CanEscalateTo 27

Forging a cert to act as a more-privileged identity is privilege escalation.
awsderived
Signing with an HSM key that issues tokens/certs for a more-privileged identity is escalation.
awsderived
Executing as a more-privileged Data Pipeline resourceRole or pipeline role is privilege escalation - an ACTIVE CanExecuteAs where the target role outranks the attacker.
awsderived
Resetting the password of a domain-admin directory user yields privilege escalation to domain-admin access over all domain-joined resources.
awsderived
Create a new role with admin trust + policy, then assume it.
awsderived
Forging a signature for a more-privileged identity is privilege escalation.
awsderived
Decrypting a KMS-encrypted secret whose credential is a more-privileged identity is privilege escalation.
awsderived
Executing as a more-privileged Lambda role is privilege escalation.
awsderived
A principal with es:UpdateDomainConfig on a FGAC-enabled domain can disable FGAC and grant all IAM-permitted principals cluster-admin data access.
awsderived
PutResourcePolicy self-grants GetSecretValue on a secret that is credentials for a more-privileged identity - escalation.
awsderived
Reading a secret that is credentials for a strictly-more-privileged identity is escalation.
awsderived
Reading a SecureString that holds creds for a more-privileged identity is escalation.
awsderived
Reading a secret that is a credential for a more-privileged identity is escalation.
azurederived
A self-grant of a crypto role (via roleAssignments/write) is privilege escalation to key usage.
azurederived
Executing as a strictly-more-privileged identity is escalation.
derived
Impersonating a strictly-more-privileged identity is privilege escalation.
derived
App Engine execution-as a more-privileged SA rolls up to an escalation edge.
gcpderived
CanExecuteAs a runtime SA of strictly greater privilege.
gcpderived
A principal with bigquery.datasets.setIamPolicy can self-grant roles/bigquery.dataOwner and escalate its data-plane privilege.
gcpderived
Forging a cert that impersonates a strictly more-privileged identity is escalation.
gcpderived
A principal who can reset the root DB user password and then read all data in a Cloud SQL instance has escalated to full DBA-level database privilege.
gcpderived
CanExecuteAs on a consumer's runtime SA of strictly greater privilege than the attacker, reached via an Eventarc trigger, is privilege escalation.
gcpderived
CanExecuteAs a runtime SA of strictly greater privilege.
gcpderived
Generating an HMAC key for a Service Account with greater GCS-scoped access and using it via the S3-compatible GCS API constitutes privilege escalation (storage-scoped only, not full SA impersonation).
gcpderived
A key manager self-granting crypto use gains the key's crypto capability.
gcpderived
Forging a signature as a key that anchors a more-privileged identity is escalation.
gcpderived
Reading a secret that yields credentials for a strictly more-privileged identity is escalation.
gcpderived
move · open · esc close