Edge types
Filtered:
from Identity
to ManagementService
- 16 of 80.
Clear
Credential/identity authenticates to a service/endpoint (incl. SaaS/DB).
cross_boundary
walkable
Full control (admin/owner) over a resource - implies most other capabilities on it.
resource_control
walkable
high value
Derived summary: source effectively controls target (admin OR sufficient sub-capabilities).
resource_control
walkable
high value
Source can create new resources of a type within a scope.
resource_control
walkable
Destructive; persistence/impact not escalation. Excluded from default paths. Produced by explicit normalization (delete-permission IAM actions) and by derived rules (evasion/cover-tracks primitives like disabling detective services).
resource_control
Source can run OS-level commands on a host/container/managed runtime (agent, run-command, exec, session-pool exec). Notebook targets cover managed notebook instances (Vertex AI Workbench, SageMaker) whose kernels execute arbitrary code as the instance's runtime identity.
execution
walkable
high value
General modify capability (specialized by CanModifyCode/Configuration/Policy where meaningful). Produced by explicit normalization (modify permissions) and derived rules (config-modification attack paths like CloudTrail tampering, logging-service disablement).
resource_control
walkable
Source can change the executable content a compute resource runs, including orchestration workflows and logic apps that are executable definitions. Produced by explicit normalization (code-update permissions) and by derived rules (supply-chain code-injection paths).
execution
walkable
high value
Source can change config (env vars, layers, startup command, identity binding) to gain execution or escalate. Produced by explicit normalization (control-plane config-update permissions) and by derived rules (trigger hijacking, notification redirection).
execution
walkable
high value
Source can alter an identity/resource policy to grant itself/others more access. Produced both by explicit normalization (IAM/RBAC setPolicy grants) and by derived rules (deny-policy/org-policy modify capabilities that unlock gated edges).
identity_authz
walkable
high value
Read configuration/metadata of a resource (recon; low base value). Produced by explicit normalization (configuration-read IAM permissions) and by derived rules (recon primitives like reading Macie findings to identify sensitive-data targets).
resource_control
walkable
Delete+recreate to inherit name/identity/trust (config-drift escalation).
resource_control
walkable
Source can become owner (Azure SP/app owner, resource owner) and thereby self-grant control.
resource_control
walkable
Modify a resource's configuration. Produced by explicit normalization (write permissions) and derived rules (config-write attack paths).
resource_control
walkable
Terminal control edge: source can administer the target boundary/resource (objective attainment).
derived
walkable
high value
EFFECTIVE permission (post evaluation) of an action on a target. Produced by the permission engine / effective-permission evaluator.
identity_authz
walkable