Skip to main content

How to interpret the demo attack path

The purpose of the demo attack path is to provide a relevant example of how an attacker could potentially move through the environment from an initial compromise to a high-value asset. By analyzing this example, you will gain a better understanding of how you can use the insights that Attack Path provides to strengthen your organization's security posture.

Reviewing the demo attack path will help you answer three important questions:

  1. Where does the attack start?

  2. How does the attacker move between assets?

  3. What are they ultimately able to reach?

Starting point

The path begins with DEMO\Alice, who is identified as the most likely entry point in this scenario, due to the presence of a phishing risk.

Alice represents the initial foothold that allows an attacker to gain access to the environment. Once Alice's account is compromised, the attacker can access DEMO-WS1, which becomes the first compromised device in the chain.

First pivot

From DEMO-WS1, the attacker is able to compromise DEMO\Bob by stealing credentials stored on a local computer.

This is the first major pivot on the path. The weaknesses associated with DEMO-WS1, including an exploitable vulnerability and an endpoint misconfiguration, enable the attacker to move from a compromised workstation to a more influential identity.

At this stage, the attack is no longer limited to a single user or device. The attacker now has access to an identity that can reach a much larger part of the environment.

Collapsed path

DEMO\Bob is one of the most important nodes on the attack path. Bob acts as a central connection point between the initial compromise and several downstream assets. Multiple attack routes depend on access to this account, which means it becomes a natural choke point.

If Bob's account were better protected, several branches of the attack path would be disrupted at the same time.

On a relatively complicated attack path, you might see one or more collapsed paths. A collapsed path refers to nodes and connections that were arbitrarily grouped together with the sole purpose of simplifying or shortening the path visualization. These nodes are not actually located together or sharing any common properties, and the grouping can be expanded to reveal the individual nodes.

Multiple alternate routes

After compromising Bob, several possible routes are available to the attacker.

The path shows access to multiple endpoints, including:

  • DEMO-WS2

  • DEMO-WS3

  • DEMO-WS4

These systems contain additional vulnerabilities and misconfigurations that can be used for lateral movement and privilege escalation.

The purpose of showing these branches is to demonstrate that the attacker is not dependent on a single route. Even if one endpoint is remediated, other paths may remain available. This explains why the visualization includes more than just the shortest path.

Critical assets

Some nodes on the path have a Critical asset label. These are assets that are considered especially valuable or sensitive within the environment. They may be business-critical systems, privileged identities, highly connected assets, or systems whose compromise would have a significant operational impact.

Currently, the Critical asset label refers solely to servers.

Target asset

The attack path ultimately leads to DEMO-WS5, which serves as the primary impact node for this scenario. The final target is always a Critical Asset.

DEMO-WS5 is the endpoint that the attacker could reach after moving through the environment. It contains 28 high and critical CVEs that might be exploited.

What the path shows

The demo attack path demonstrates how a series of individually manageable weaknesses can be combined into a realistic attack sequence:

DEMO\Alice > DEMO-WS1 > DEMO\Bob > Additional endpoints/users > DEMO-WS5

Understanding these relationships is the primary purpose of the attack path visualization. It helps identify not only what should be fixed, but where remediation is most likely to break the attack chain and reduce risk across multiple assets at once.