Attack Path Management

Navigation

On this page

Attack Path Management
On this page

On this page

Modern organizations rely on an increasingly complex web of services and systems orchestrated via access management tools like Active Directory, Azure ID, and other identity-based utilities. These solutions can make it easier to manage who is allowed to access certain resources or perform specific actions; they can also give attackers a clear path from their initial access points to critical assets deeper in the organization’s infrastructure.

Attack paths are chains of vulnerable identities, abusable privileges, and misconfigured software lurking in an organization’s environment. Attack Path Management (APM) is a cybersecurity practice used to find those chains and break them, and it’s becoming more critical than ever in the AI era, with agentic workflows often relying on scores of non-human identities that can be given the same privileges and permissions as their human counterparts. That means more attack paths to manage—and they aren’t just going to resolve themselves.

Adapting to this new paradigm requires a proactive security program that views organizational infrastructure from an adversarial perspective so risks can be identified, prioritized, and remediated before they can be exploited. APM is a core component of such programs; read on to learn more about how it works, why organizations historically struggled to implement it, and the benefits it provides to those who have embraced it within their own security programs.

Key Attack Path Management concepts and terminology

Understanding Blast Radius and Choke Points

Attack paths can’t be viewed in isolation. Links between services and systems aren’t inherently problematic; they’re the reason why identity management tools exist in the first place. The capabilities afforded to attackers by compromising those links, both individually and as a whole, determine whether an attack path should be considered a “problem” or an “emergency.” We refer to these capabilities and their broader context as the *Blast Radius*.

Consider a compromised developer endpoint. An attacker could exploit it to:

  • Access source control 
  • Influence workflow execution 
  • Assume a cloud role 
  • Access production systems and deployment artifacts 

The severity of each of those actions depends on how the associated services and systems were configured. But if they’re chained together, attackers could use them to introduce vulnerabilities into an organization’s software, distribute malware to its customers, or simply make their way to an otherwise inaccessible attack path that has the access or privileges they’re looking for.

In that case, the developer endpoint could also be considered a *Choke Point*. These are significant points of control within an organization’s environment. Compromising them could represent significant progress to an attacker; securing them could be an optimal solution for blocking the most attack paths at once. A combination of its Blast Radius and whether or not it represents a Choke Point helps determine the priority defenders should assign a particular attack path.

How APM fits in alongside Vulnerability, Attack Surface, and Continuous Threat Exposure Management

Software vulnerabilities have been, are, and will continue to be a problem. While vendors are getting better at producing software with fewer bugs, they’re never going to produce bug-free code—nor should they be expected to. But new software isn’t the only risk here: old software, or old code that new software is written on top of, can also have exploitable bugs just waiting to be found. For this reason, organizations must be able to react to software vulnerabilities by testing, deploying, and auditing patches, as well as mitigating risks on systems where patches can’t be deployed.

*Vulnerability Management* solutions provide specific vulnerability risk using the Common Vulnerability Scoring System (CVSS). While vulnerabilities are an arrow in an adversary’s quiver, they come at a cost. First, each exploit leaves bread crumbs which defenders can find; potentially risking the adversary’s network access, exploit, or both. Second, developing, aggregating, and maintaining an exploit is time consuming for the adversary. Last, the use of exploits to pivot / move through a network is commonly time-consuming.

In contrast, an adversary with mastery of attacking Active Directory, Entra ID, and other identity management solutions suffer minimal risk of discovery from defenders as they traverse Active Directory attack paths and their equivalents in other identity platforms.  This makes taking advantage of attack paths a more compelling option than finding (and potentially burning) an exploitable vulnerability somewhere in their target’s tech stack.

*Continuous Threat Exposure Management* is an evolution of Vulnerability Management devoted to identifying and remediating the greatest threats to an organization regardless of whether they’re known vulnerabilities or not. Defending against unknown vulnerabilities (often known as “zero-days” because that’s how long a vendor and its customers have known about them) requires more than just a commitment to patching software as security fixes are released.

APM and Vulnerability Management or CTEM are twin pillars of a defensive operation—they’re more effective together than they are in isolation. 

*Attack Surface Management* is similar to APM in that Attack Surface Management essentially looks to break the first link in the chain of factors that create an attack path. The difference is that APM isn’t solely concerned with external threats; it also considers the risks associated with an attack path after the exterior defenses have been breached or bypassed. Attack Surface Management might not concern itself with insider threats, for example, and it furthers the outdated notion that having a well-defended exterior is enough to stop determined adversaries. It’s not. They will probably find a way in eventually—APM helps make life more difficult for them when they do.

The APM Maturity Model

Incorporating APM into an organization’s existing security policies and practices is a multi-step process. That’s why SpecterOps developed the Attack Path Management Maturity Model. This framework gives organizations a way to measure their identity Attack Path Management program and determine how prepared they are for a security paradigm where identities, both human and non-human, can pose the greatest risk to their operations. 

This model defines six levels of maturity based on the people, processes, and technologies an organization has devoted to APM:

  • Level 0: Nonexistent
  • Level 1: Initial
  • Level 2: Managed
  • Level 3: Defined
  • Level 4: Quantitatively Managed
  • Level 5: Optimizing

Learning how adversaries view attack paths and how effective defenders manage them is the first step towards embracing this paradigm.

The lifecycle of Attack Path Management

APM is a five-step process: discovering attack paths within the environment, analyzing them, determining how to address them, implementing those changes, and confirming they have been removed. Some of these steps involve additional work, such as attack path mapping in the discovery phase and ensuring the removal of an attack path truly mitigated potential risks. Organizations looking to develop mature APM programs are also ready for a sixth step: implementing continuous attack path discovery and analysis.

Step 1: Identify

It’s practically impossible to find all the attack paths within an organization’s environment by hand. There are too many identities to manually enumerate—and that doesn’t even account for the number of corresponding attack paths. That figure scales exponentially as the number of identities within the environment increases, and with the popularization of agentic workflows leading to rapid growth in reliance on non-human identities, attack paths are going to proliferate as well. That’s where tools like BloodHound Enterprise come in.

BloodHound Enterprise automates attack path mapping, identifying attack paths and mapping the relationships between them. This gives defenders an idea of the sheer scale of potential security risks in their environment. But simply listing these attack paths wouldn’t be helpful; defenders also need to know which attack paths pose the greatest risk to their organization so they can address them first.

Step 2: Analyze

That knowledge arrives via attack path analysis: a careful look at an attack path’s potential Blast Radius and whether or not some link in the chain could be considered a Choke Point. Attack paths with the greatest Blast Radius could be worth addressing immediately even if doing so would require a significant amount of time; attack paths that sit at Choke Points could offer defenders the greatest return on their investment even if the risk associated with the individual attack paths isn’t high. When to address the attack paths in between varies from org to org.

BloodHound Enterprise offers the capabilities defenders need to analyze the attack paths they find, including attack path Prioritization, discovering attack path Choke Points, and more. And once that analysis is done, BloodHound Enterprise can help defenders decide how to address a particular attack path.

Step 3: Strategize

It’s practically impossible to manage permissions in modern environments—that’s why attack paths are so common in the first place. Identifying and analyzing those attack paths won’t suddenly make identity management solutions and similar tools easy to use; even experienced network administrators might not know how to remediate the problems that led to a high-risk attack path or high-impact Choke Point without assistance.

BloodHound Enterprise features guided remediations that can walk defenders and the sysadmins they work beside through a particular attack path’s resolution process, eliminating the guesswork and ensuring practical and safe remediation. Using BloodHound Enterprise’s Privilege Zones to effectively segment a network and enforce theoretically widespread but practically rare industry practices such as the principle of least privilege in the most complex environments.

Step 4: Respond

Organizations that have identified the attack paths in their environment, analyzed them to determine which pose the greatest risk to critical assets, and figured out how to remediate or mitigate those risks now have to… well, actually implement those remediations or mitigations. Knowing is only half the battle; now it’s up to defenders and administrators to spring into action.

Step 5: Confirm

The remediations and mitigations have been applied. Job’s done, right? Not necessarily. Defenders already know that patching a specific vulnerability doesn’t mean their environments are now impervious to a particular exploit. Some patches are difficult to apply correctly, with missteps leading to lingering security flaws, and even properly applied patches won’t be enough to stop intrepid attackers who discover ways around the vendor’s so-called “fix.”

BloodHound removes the guesswork from determining whether or not the risks associated with an attack path have been appropriately addressed. If an attack path continues to be a problem, BloodHound will find it. And if it’s actually been taken care of, BloodHound can help defenders figure out which attack paths they should take on next, so they don’t have to worry about resting on their laurels. Effective security teams are tireless; their tools should be, too.

Implement continuous APM practices

Modern networks are not static. Privileged users log on to different systems every day, new applications require newly granted permissions, and security group memberships change to accommodate business requirements. This constant activity means that attack paths are changed and created all the time—which means that finding and fixing them once a month, quarter, or year won’t be enough to stop persistent attackers from making their way into the network.

BloodHound Enterprise continuously identifies and prioritizes attack paths to give defenders an adversarial view of their environment. Attackers don’t look for attack paths on set schedules; defenders shouldn’t limit themselves to point-in-time assessments of potential threats, either. Otherwise they’ll find themselves back in the same pattern of responding to incidents after the fact rather than identifying the underlying risks so they can be fixed ahead of time.

Benefits of effective Attack Path Management

Enhanced visibility and context
Continuously mapping attack paths requires organizations to chart every connection between services and systems as well as identities and their associated privileges. From critical servers like Domain Controllers to individual endpoints, comprehensive enumeration of relationships and connections enables full understanding of the real permissions against any given object, computer, user, etc. and the impact of any particular connection.

This visibility also enables better architectural design within the environment; productivity gains for IT and security teams; and the end of penetration tests leading to tedious, unproductive changes because their findings were misunderstood, misused, or misconstrued.

Elimination of ‘band-aid’ fixes
APM allows organizations to directly address the risks associated with attack paths at precise Choke Points rather than applying thousands of cosmetic ‘improvements’ that do not hinder an adversary’s advancement. Remediations suggested by APM tools like BloodHound Enterprise are designed to be practical, precise, and safe so organizations can implement them with confidence. That means they:

  • Should not require drastic changes to the environment’s directory services architecture
  • Should not require the organization to migrate from one directory services platform to another
  • Should not require expert-level knowledge to implement
  • Should have expected, verifiable outcomes

Proactive threat prevention and disruption
The primary objective of APM is to help organizations eliminate key Choke Points so it’s no longer worth the adversary’s effort to enumerate or exploit attack paths within their networks. Attackers can’t exploit identities, privileges, and system configurations that have already been locked down, and even though no environment can ever truly be declared “secure,” effective APM should make adversaries’ lives difficult enough that they think twice before committing to a particular target.

Strengthening overall security posture
There is no silver bullet for securing an environment. APM is no exception. Instead, it’s best implemented as part of a broader security program that incorporates APM as well as Vulnerability Management (or the associated Continuous Threat Exposure Management) and Attack Surface Management. Those practices also depend on effective training programs, regular assessments of the organization’s security posture, and the adoption of best practices such as multi-factor authentication.

The ultimate result of continuously mapping, measuring, and eliminating high risk attack path Choke Points with Attack Path Management is that you have hardened Active Directory, Entra ID, and other identity management tools against abuse; bolstered Directory Services availability; and protected the “keys to the kingdom” rather than simply figuring out how to respond after they’ve been compromised. Being proactive is no longer optional—it’s a requirement for modern defenders who need to fend off modern adversaries.

Frequently asked questions

What is the difference between attack path and attack surface?

This is similar to the difference between attack path and attack vector. The attack path is the full chain of exploitable identities, privileges, etc. that attackers can take advantage of to work their way through an environment; the “attack surface” is the number of links in those chains that can be externally compromised. APM looks to address the sheer number of attack paths within the environment while Attack Surface Management is meant to reduce how many of those attack paths can be found by adversaries outside of that environment.

What is the difference between attack path and attack vector?

An attack path refers to exploitable connections between services and systems, while an “attack vector” refers to the point of initial compromise. To continue with our chain metaphor, an attack path is the entire chain while an attack vector is simply the first link in that chain.

How often should Attack Path Analysis be conducted?

Analyzing the attack paths within an organization’s environment—by which we mean determining each individual attack path’s potential Blast Radius, deciding whether or not it should be considered a Choke Point, and deliberating its priority relative to other attack paths—is most effective when it’s part of a continuous program that doesn’t rely on point-in-time assessments. Put another way: the best time to conduct attack path analysis is “all the time.”

Is Attack Path Management applicable to all organization sizes?

APM can be applied to organizations of all sizes. How many resources should be devoted to APM compared to other parts of their security program depends on the size of the organization, their overall security posture, and where they fit on the APM Maturity Model. Some orgs can go all-in on APM from the get-go; others will have to gradually improve their APM implementations over time. The most important thing is not to let the “perfect” be the enemy of the “good.”

What is the relationship between APM and Zero Trust?

Zero Trust can span from tools to policies and procedures, with varying levels of enforcement. Regardless of how the term is used by a particular organization, Zero Trust doesn’t eliminate attack paths on its own because workstations are still gateways to identity providers, device management systems create new trust relationships of their own, existing segmentation tools remain difficult to use, and the connections between user devices and cloud services still create opportunities for attack. Instead, Zero Trust and APM should be implemented side-by-side within an org.