Attack Path
Note
Attack Path is available as part of the GravityZone Exposure Management license.
Attack Path relies on data from multiple sources to identify and display potential paths that attackers could take to compromise your assets. To ensure that these data sources are available, the following prerequisites must be met:
You must enable the Risk Management module and configure the risk scan schedule for your endpoints. For details, refer to Risk Management.
If you have an active CSPM+ license, scanning must be enabled on your cloud accounts. For details on setting up cloud account scanning in CSPM+, refer to Getting started.
Note
Attack Path performs scans at 24-hour intervals to identify potential attack paths. These scans are not necessarily synchronized with the scans performed by other GravityZone features. For example, a risk scan performed by Risk Management may generate findings that will not be reflected in the list of attack paths until the daily Attack Path scan is performed.
Other GravityZone features, such as EASM, may provide additional context data that Attack Path uses for correlation.