Edge types

Filtered: from Identity to Data - 24 of 80. Clear

Credential/identity authenticates to a service/endpoint (incl. SaaS/DB).
cross_boundary walkable
Full control (admin/owner) over a resource - implies most other capabilities on it.
resource_control walkable high value
Source can attach/replace the identity a compute resource runs as, including updating a workflow/orchestration service's execution identity. Also applies to data resources (caches, databases) where an identity is used for encryption or service-to-service auth. Produced both by explicit normalization (attach/assign permissions on target resources) and by derived rules (e.g., CanPassIdentity + CanModifyConfiguration on target).
execution walkable
Derived summary: source effectively controls target (admin OR sufficient sub-capabilities).
resource_control walkable high value
Source can create new resources of a type within a scope.
resource_control walkable
Destructive; persistence/impact not escalation. Excluded from default paths. Produced by explicit normalization (delete-permission IAM actions) and by derived rules (evasion/cover-tracks primitives like disabling detective services).
resource_control
Destructive impact; not escalation.
data
Source can run OS-level commands on a host/container/managed runtime (agent, run-command, exec, session-pool exec). Notebook targets cover managed notebook instances (Vertex AI Workbench, SageMaker) whose kernels execute arbitrary code as the instance's runtime identity.
execution walkable high value
Can move data out of boundary (share snapshot cross-account, presign URL, replicate).
data walkable
General modify capability (specialized by CanModifyCode/Configuration/Policy where meaningful). Produced by explicit normalization (modify permissions) and derived rules (config-modification attack paths like CloudTrail tampering, logging-service disablement).
resource_control walkable
Source can change the executable content a compute resource runs, including orchestration workflows and logic apps that are executable definitions. Produced by explicit normalization (code-update permissions) and by derived rules (supply-chain code-injection paths).
execution walkable high value
Source can change config (env vars, layers, startup command, identity binding) to gain execution or escalate. Produced by explicit normalization (control-plane config-update permissions) and by derived rules (trigger hijacking, notification redirection).
execution walkable high value
Source can alter an identity/resource policy to grant itself/others more access. Produced both by explicit normalization (IAM/RBAC setPolicy grants) and by derived rules (deny-policy/org-policy modify capabilities that unlock gated edges).
identity_authz walkable high value
Source can reach target over the network (post SG/firewall/route evaluation). Messaging source/target covers publicly- or privately-reachable messaging endpoints (a queue/topic/event-bus with a public resource policy is an internet-reachable target; a private messaging endpoint is a private-link source/target) - consistent with ExposedToInternet and PrivateReachability, which already admit the Messaging class.
network walkable
Read configuration/metadata of a resource (recon; low base value). Produced by explicit normalization (configuration-read IAM permissions) and by derived rules (recon primitives like reading Macie findings to identify sensitive-data targets).
resource_control walkable
Effective data-plane read (control-plane perm + network reach + decrypt if encrypted). Includes reading messages from a queue/topic/stream.
data walkable high value
Delete+recreate to inherit name/identity/trust (config-drift escalation).
resource_control walkable
Source can create a schedule/trigger to drive execution (persistence + trigger creation).
execution walkable
Source can become owner (Azure SP/app owner, resource owner) and thereby self-grant control.
resource_control walkable
Source can cause the target to execute (event source, schedule). Includes triggering compute workloads and orchestration workflows. AnalyticsService sources cover analytics engines that invoke compute as part of query execution (e.g. an Athena federated query invoking its Lambda data-source connector).
execution walkable
Modify a resource's configuration. Produced by explicit normalization (write permissions) and derived rules (config-write attack paths).
resource_control walkable
Effective data-plane write (can poison code/artifacts/config → onward execution). Includes publishing/sending to a queue/topic/event bus.
data walkable
Terminal control edge: source can administer the target boundary/resource (objective attainment).
derived walkable high value
EFFECTIVE permission (post evaluation) of an action on a target. Produced by the permission engine / effective-permission evaluator.
identity_authz walkable
move · open · esc close