Edge types

Filtered: from Identity to Secret - 21 of 80. Clear

Credential/identity authenticates to a service/endpoint (incl. SaaS/DB).
cross_boundary walkable
Full control (admin/owner) over a resource - implies most other capabilities on it.
resource_control walkable high value
Derived summary: source effectively controls target (admin OR sufficient sub-capabilities).
resource_control walkable high value
Source can create new resources of a type within a scope.
resource_control walkable
Source can create keys (SA key creation overlaps CanCreateCredentialFor).
credential walkable
Source can use a key to decrypt data/secrets (gates CanReadData on encrypted stores).
credential walkable high value
Destructive; persistence/impact not escalation. Excluded from default paths. Produced by explicit normalization (delete-permission IAM actions) and by derived rules (evasion/cover-tracks primitives like disabling detective services).
resource_control
Source can export raw key material (rare; high impact - persistent offline decrypt/sign).
credential walkable
General modify capability (specialized by CanModifyCode/Configuration/Policy where meaningful). Produced by explicit normalization (modify permissions) and derived rules (config-modification attack paths like CloudTrail tampering, logging-service disablement).
resource_control walkable
Source can change config (env vars, layers, startup command, identity binding) to gain execution or escalate. Produced by explicit normalization (control-plane config-update permissions) and by derived rules (trigger hijacking, notification redirection).
execution walkable high value
Source can alter an identity/resource policy to grant itself/others more access. Produced both by explicit normalization (IAM/RBAC setPolicy grants) and by derived rules (deny-policy/org-policy modify capabilities that unlock gated edges).
identity_authz walkable high value
Read configuration/metadata of a resource (recon; low base value). Produced by explicit normalization (configuration-read IAM permissions) and by derived rules (recon primitives like reading Macie findings to identify sensitive-data targets).
resource_control walkable
Source can obtain a usable credential (instance metadata token, env var, key file).
credential walkable
Source can read secret material (often yields creds for another identity/service).
credential walkable high value
Delete+recreate to inherit name/identity/trust (config-drift escalation).
resource_control walkable
Source can obtain an access/OIDC token for an identity (metadata endpoint, token mint).
credential walkable
Source can sign tokens/blobs as the target (JWT/SAML signing -> forge identity).
credential walkable high value
Source can become owner (Azure SP/app owner, resource owner) and thereby self-grant control.
resource_control walkable
Modify a resource's configuration. Produced by explicit normalization (write permissions) and derived rules (config-write attack paths).
resource_control walkable
Terminal control edge: source can administer the target boundary/resource (objective attainment).
derived walkable high value
EFFECTIVE permission (post evaluation) of an action on a target. Produced by the permission engine / effective-permission evaluator.
identity_authz walkable
move · open · esc close