Edge types
Filtered:
from Identity
to Compute
- 27 of 80.
Clear
Physical/logical attachment. Semantic edges (ExecutesAs, HasPolicy) carry the security meaning.
structural
Credential/identity authenticates to a service/endpoint (incl. SaaS/DB).
cross_boundary
walkable
Full control (admin/owner) over a resource - implies most other capabilities on it.
resource_control
walkable
high value
Source can attach/replace the identity a compute resource runs as, including updating a workflow/orchestration service's execution identity. Also applies to data resources (caches, databases) where an identity is used for encryption or service-to-service auth. Produced both by explicit normalization (attach/assign permissions on target resources) and by derived rules (e.g., CanPassIdentity + CanModifyConfiguration on target).
execution
walkable
Derived summary: source effectively controls target (admin OR sufficient sub-capabilities).
resource_control
walkable
high value
Source can create new resources of a type within a scope.
resource_control
walkable
Destructive; persistence/impact not escalation. Excluded from default paths. Produced by explicit normalization (delete-permission IAM actions) and by derived rules (evasion/cover-tracks primitives like disabling detective services).
resource_control
Source can deploy new workloads to a platform (then attach identity).
execution
walkable
Source can run OS-level commands on a host/container/managed runtime (agent, run-command, exec, session-pool exec). Notebook targets cover managed notebook instances (Vertex AI Workbench, SageMaker) whose kernels execute arbitrary code as the instance's runtime identity.
execution
walkable
high value
Generalized 'can get code running on this resource' (superset of command/deploy/modify).
execution
walkable
Source can directly invoke the target (completes an ExecutesAs escalation when code already attacker-controlled or config changed). Messaging sources include service-to-service invocations (API Gateway invoking Lambda, EventBridge invoking Lambda, etc.).
execution
walkable
General modify capability (specialized by CanModifyCode/Configuration/Policy where meaningful). Produced by explicit normalization (modify permissions) and derived rules (config-modification attack paths like CloudTrail tampering, logging-service disablement).
resource_control
walkable
Source can change the executable content a compute resource runs, including orchestration workflows and logic apps that are executable definitions. Produced by explicit normalization (code-update permissions) and by derived rules (supply-chain code-injection paths).
execution
walkable
high value
Source can change config (env vars, layers, startup command, identity binding) to gain execution or escalate. Produced by explicit normalization (control-plane config-update permissions) and by derived rules (trigger hijacking, notification redirection).
execution
walkable
high value
Source can alter an identity/resource policy to grant itself/others more access. Produced both by explicit normalization (IAM/RBAC setPolicy grants) and by derived rules (deny-policy/org-policy modify capabilities that unlock gated edges).
identity_authz
walkable
high value
Source can reach target over the network (post SG/firewall/route evaluation). Messaging source/target covers publicly- or privately-reachable messaging endpoints (a queue/topic/event-bus with a public resource policy is an internet-reachable target; a private messaging endpoint is a private-link source/target) - consistent with ExposedToInternet and PrivateReachability, which already admit the Messaging class.
network
walkable
Source may attach/pass the target identity to a NEW or existing workload (prereq for CanExecuteAs).
identity_authz
walkable
high value
Read configuration/metadata of a resource (recon; low base value). Produced by explicit normalization (configuration-read IAM permissions) and by derived rules (recon primitives like reading Macie findings to identify sensitive-data targets).
resource_control
walkable
Effective data-plane read (control-plane perm + network reach + decrypt if encrypted). Includes reading messages from a queue/topic/stream.
data
walkable
high value
Source can read secret material (often yields creds for another identity/service).
credential
walkable
high value
Delete+recreate to inherit name/identity/trust (config-drift escalation).
resource_control
walkable
Source can start a stopped resource (needed to realize CONDITIONAL execution edges).
execution
walkable
Source can become owner (Azure SP/app owner, resource owner) and thereby self-grant control.
resource_control
walkable
Source can cause the target to execute (event source, schedule). Includes triggering compute workloads and orchestration workflows. AnalyticsService sources cover analytics engines that invoke compute as part of query execution (e.g. an Athena federated query invoking its Lambda data-source connector).
execution
walkable
Modify a resource's configuration. Produced by explicit normalization (write permissions) and derived rules (config-write attack paths).
resource_control
walkable
Terminal control edge: source can administer the target boundary/resource (objective attainment).
derived
walkable
high value
EFFECTIVE permission (post evaluation) of an action on a target. Produced by the permission engine / effective-permission evaluator.
identity_authz
walkable