Edge types

Filtered: from Identity to AdministrativeBoundary - 26 of 80. Clear

Credential/identity authenticates to a service/endpoint (incl. SaaS/DB).
cross_boundary walkable
Full control (admin/owner) over a resource - implies most other capabilities on it.
resource_control walkable high value
Derived summary: source effectively controls target (admin OR sufficient sub-capabilities).
resource_control walkable high value
Source can create new resources of a type within a scope.
resource_control walkable
Destructive; persistence/impact not escalation. Excluded from default paths. Produced by explicit normalization (delete-permission IAM actions) and by derived rules (evasion/cover-tracks primitives like disabling detective services).
resource_control
Source can obtain a principal/session inside the target AWS account.
cross_boundary walkable high value
Source reaches org-level control (management account, org policy admin).
cross_boundary walkable high value
Source can gain access within the target GCP project.
cross_boundary walkable high value
Source can gain control-plane access within the target subscription.
cross_boundary walkable high value
Source can obtain a principal in the target Entra tenant (guest, multi-tenant app, B2B).
cross_boundary walkable high value
Source can assign a role/permission to a principal (incl. itself) - privilege escalation primitive.
identity_authz walkable high value
General modify capability (specialized by CanModifyCode/Configuration/Policy where meaningful). Produced by explicit normalization (modify permissions) and derived rules (config-modification attack paths like CloudTrail tampering, logging-service disablement).
resource_control walkable
Source can change config (env vars, layers, startup command, identity binding) to gain execution or escalate. Produced by explicit normalization (control-plane config-update permissions) and by derived rules (trigger hijacking, notification redirection).
execution walkable high value
Source can alter an identity/resource policy to grant itself/others more access. Produced both by explicit normalization (IAM/RBAC setPolicy grants) and by derived rules (deny-policy/org-policy modify capabilities that unlock gated edges).
identity_authz walkable high value
Read configuration/metadata of a resource (recon; low base value). Produced by explicit normalization (configuration-read IAM permissions) and by derived rules (recon primitives like reading Macie findings to identify sensitive-data targets).
resource_control walkable
Delete+recreate to inherit name/identity/trust (config-drift escalation).
resource_control walkable
Source can become owner (Azure SP/app owner, resource owner) and thereby self-grant control.
resource_control walkable
Modify a resource's configuration. Produced by explicit normalization (write permissions) and derived rules (config-write attack paths).
resource_control walkable
Terminal control edge: source can administer the target boundary/resource (objective attainment).
derived walkable high value
A trust/resource policy names a principal in another account (feeds CanAssume/CanEnterAccount). Produced by explicit normalization (policy artifact parsing) and by derived rules (cross-account data-resource sharing patterns like S3 bucket policy with foreign principal). Subscription targets cover Azure's account-boundary analog - a cross-subscription trust (e.g. an approved cross-subscription Private Endpoint connection, or cross-subscription VNet peering).
cross_boundary walkable
Cross-project IAM binding / SA usage. ServiceAccount targets cover a workload in one project running as (trusting) a service account owned by another project (e.g. a Vertex AI job or Workbench instance with a cross-project runtime SA) - symmetric with ServiceAccount as a source.
cross_boundary walkable
B2B/guest/multi-tenant app trust across Entra tenants.
cross_boundary walkable
Reachable/usable account/subscription/project-wide.
network walkable
Reachable/usable by any principal in the tenant/org (broad blast radius).
network walkable
EFFECTIVE permission (post evaluation) of an action on a target. Produced by the permission engine / effective-permission evaluator.
identity_authz walkable
Placement metadata (region/subnet). Useful for filtering, not traversal.
structural
move · open · esc close