Edge types

Filtered: from Identity to Policy - 16 of 80. Clear

Credential/identity authenticates to a service/endpoint (incl. SaaS/DB).
cross_boundary walkable
Full control (admin/owner) over a resource - implies most other capabilities on it.
resource_control walkable high value
Derived summary: source effectively controls target (admin OR sufficient sub-capabilities).
resource_control walkable high value
Source can create new resources of a type within a scope.
resource_control walkable
Destructive; persistence/impact not escalation. Excluded from default paths. Produced by explicit normalization (delete-permission IAM actions) and by derived rules (evasion/cover-tracks primitives like disabling detective services).
resource_control
General modify capability (specialized by CanModifyCode/Configuration/Policy where meaningful). Produced by explicit normalization (modify permissions) and derived rules (config-modification attack paths like CloudTrail tampering, logging-service disablement).
resource_control walkable
Source can change config (env vars, layers, startup command, identity binding) to gain execution or escalate. Produced by explicit normalization (control-plane config-update permissions) and by derived rules (trigger hijacking, notification redirection).
execution walkable high value
Source can alter an identity/resource policy to grant itself/others more access. Produced both by explicit normalization (IAM/RBAC setPolicy grants) and by derived rules (deny-policy/org-policy modify capabilities that unlock gated edges).
identity_authz walkable high value
Source can rewrite who may assume/impersonate the target - self-grant assumption.
identity_authz walkable high value
Read configuration/metadata of a resource (recon; low base value). Produced by explicit normalization (configuration-read IAM permissions) and by derived rules (recon primitives like reading Macie findings to identify sensitive-data targets).
resource_control walkable
Delete+recreate to inherit name/identity/trust (config-drift escalation).
resource_control walkable
Source can become owner (Azure SP/app owner, resource owner) and thereby self-grant control.
resource_control walkable
Modify a resource's configuration. Produced by explicit normalization (write permissions) and derived rules (config-write attack paths).
resource_control walkable
Terminal control edge: source can administer the target boundary/resource (objective attainment).
derived walkable high value
EFFECTIVE permission (post evaluation) of an action on a target. Produced by the permission engine / effective-permission evaluator.
identity_authz walkable
A policy artifact is attached to a principal/resource. Feeds the permission evaluator; not walked directly.
identity_authz
move · open · esc close