Attack Path
To assist you in identifying and addressing the findings and vulnerabilities that require your attention, Attack Path analyzes and correlates multiple data sources to build a visual representation of the sequence of steps that an attacker could take in order to compromise your assets. This context-driven approach reduces noise and allows you to prioritize the risks that are most likely to be exploited.
Note
Attack Path is available as part of the Exposure Management license.
An attack path always leads to a main asset that a potential attacker may target, such as a server or container. Each path also includes the intermediate nodes that an attacker may use to reach the main asset. These nodes may include two types of entities:
Entities that are part of your resource inventory, such as security groups, load balancers, workstations, servers, etc.
Derived resources, which are not part of the resource inventory but are included in the attack path because they provide crucial insight into how an attacker may reach the main asset. For example, an attack path may include the SMB service running on a server as a derived resource, because the exposed SMB service can act as an entry point for attackers looking to gain access to the server.
For information on using Attack Path, refer to the following sections: