Realizing resources
aws aws
| resource | scope | enumerate | required permissions |
|---|---|---|---|
aws:directconnect:connection |
regional | directconnect:DescribeConnections |
directconnect:DescribeConnections |
As edge source
As edge target
Exposure sites
None.
Rules that touch VPN 7
A CA-issued certificate authenticates as the downstream identity a trust consumer maps it to.
aws
CredentialsForAn active S2S VPN connection (vpnConnections, connectionStatus=Connected) is an explicit routing fact: the Virtual Hub routes traffic to and from the on-premises branch via the VPN tunnel.
azure
RoutesToIssue a cert for an attacker-chosen subject/SAN that a downstream trust accepts, impersonating that identity.
gcp
CanImpersonateAn internal Application Load Balancer or internal passthrough NLB (loadBalancingScheme INTERNAL or INTERNAL_MANAGED) is reachable only from within the VPC, peered VPCs, or connected on-premises networks. A compute resource with a foothold in the same VPC can reach the internal LB frontend and, through it, the backends.
A source whose subnet routes to the destination's subnet (intra-VPC/VNet routing) reaches the destination when its ingress rule admits the source.
A source reaches a destination through a shared transit hub (Transit Gateway/VWAN/NCC/Direct Connect gateway/VPN gateway) that forwards between attachments - transitive across the hub's associated route table.