Edge types

Filtered: from Storage to Secret - 5 of 80. Clear

Container holds child resources/objects: administrative boundaries, storage containers, data stores (SQL servers and their databases/firewall rules), secret vaults (Key Vault and its secrets/keys), management services and their artifacts.
structural
Resource stores a usable credential. Includes hardcoded credentials in workflow definitions, SAS keys in message connectors, and API keys in event subscriptions.
data walkable
Recon: resource references another (connection targets, IaC). Aids collection, not traversal. Network sources (e.g., Route 53 DNS zones) reference alias targets like ELB/CloudFront/S3; dangling aliases are a legitimate structural relationship.
data
Resource stores secret material (drives ExposesCredential).
data walkable
Resource contains/leaks a credential usable for the target identity (env var, code, connstring, metadata, API key). Target can be a Credential, Identity, or Secret/APIKey node.
credential walkable
move · open · esc close