Edge types

Filtered: from Identity to ManagementService - 16 of 80. Clear

Credential/identity authenticates to a service/endpoint (incl. SaaS/DB).
cross_boundary walkable
Full control (admin/owner) over a resource - implies most other capabilities on it.
resource_control walkable high value
Derived summary: source effectively controls target (admin OR sufficient sub-capabilities).
resource_control walkable high value
Source can create new resources of a type within a scope.
resource_control walkable
Destructive; persistence/impact not escalation. Excluded from default paths. Produced by explicit normalization (delete-permission IAM actions) and by derived rules (evasion/cover-tracks primitives like disabling detective services).
resource_control
Source can run OS-level commands on a host/container/managed runtime (agent, run-command, exec, session-pool exec). Notebook targets cover managed notebook instances (Vertex AI Workbench, SageMaker) whose kernels execute arbitrary code as the instance's runtime identity.
execution walkable high value
General modify capability (specialized by CanModifyCode/Configuration/Policy where meaningful). Produced by explicit normalization (modify permissions) and derived rules (config-modification attack paths like CloudTrail tampering, logging-service disablement).
resource_control walkable
Source can change the executable content a compute resource runs, including orchestration workflows and logic apps that are executable definitions. Produced by explicit normalization (code-update permissions) and by derived rules (supply-chain code-injection paths).
execution walkable high value
Source can change config (env vars, layers, startup command, identity binding) to gain execution or escalate. Produced by explicit normalization (control-plane config-update permissions) and by derived rules (trigger hijacking, notification redirection).
execution walkable high value
Source can alter an identity/resource policy to grant itself/others more access. Produced both by explicit normalization (IAM/RBAC setPolicy grants) and by derived rules (deny-policy/org-policy modify capabilities that unlock gated edges).
identity_authz walkable high value
Read configuration/metadata of a resource (recon; low base value). Produced by explicit normalization (configuration-read IAM permissions) and by derived rules (recon primitives like reading Macie findings to identify sensitive-data targets).
resource_control walkable
Delete+recreate to inherit name/identity/trust (config-drift escalation).
resource_control walkable
Source can become owner (Azure SP/app owner, resource owner) and thereby self-grant control.
resource_control walkable
Modify a resource's configuration. Produced by explicit normalization (write permissions) and derived rules (config-write attack paths).
resource_control walkable
Terminal control edge: source can administer the target boundary/resource (objective attainment).
derived walkable high value
EFFECTIVE permission (post evaluation) of an action on a target. Produced by the permission engine / effective-permission evaluator.
identity_authz walkable
move · open · esc close