Platform · From foothold to consequence, drawn out

Attack paths

Paths descend through the strata from an entry point to something that actually costs you. Each path carries a blast radius, a choke point and the findings it depends on.

7

live paths reaching a Core asset, down from 26

Capabilities

What attack paths actually does

01

Traversal modelling

Reachability is computed from network routes, trust policies, credential locations and admission rules — not from severity scores.

02

Choke points

The single hop whose removal closes the most paths, ranked by how much exposure it takes with it.

03

Blast radius

What the destination holds, who depends on it and which reports break if it is touched.

04

Containment record

When a path is contained rather than closed, that state is explicit, dated and reviewed.

In the console

See it working on demo data

  • Reachability is computed from network routes, trust policies, credential locations and admission rules.
  • Choke points are ranked by how many live paths they close and what the change costs the owning team.
  • Containment is a first-class state with a required review date, kept separate from closed.
LodemarkDemo tenantNorthfleet Group · 4 cloud accounts · 11 regions · 3 subsidiariesHead of Security OperationsSigned in as Asha Rehman
Attack paths4 live · entry point to consequence, drawn through the strata
AP-01 · live

Supplier exchange to invoice archive

critical

An anonymous listing on the supplier exchange leaks object keys. Those keys resolve through the ingest identity, which can read the invoice archive because the bucket policy grants the analytics role without a prefix restriction.

AP-01: Supplier exchange to invoice archiveAttack path from supplier-docs.northfleet.io to nfg-invoice-archive, 5 hops descending through the Edge, Gateway, Workload, Identity, Core strata.S1 · EdgeS2 · GatewayS3 · WorkloadS4 · IdentityS5 · Coresupplier-docs.northfleet.ioedge-proxy-rotnfg-analytics-lakesvc-datalake-ingestnfg-invoice-archiveCHOKE POINT

Scroll the figure sideways to follow the path

Hop 1 of 5supplier-docs.northfleet.ioAnonymous enumeration

Directory listing returns object keys for the whole exchange prefix.

Entry point
supplier-docs.northfleet.io
Destination
nfg-invoice-archive
Blast radius

7 years of invoices · 2,140 supplier records · 4 downstream reports

Choke point

Scope the ingest trust policy to the task role

Removes 4 of 7 live paths and drops the exposure score by 9 points.

Findings on this path
  • criticalUnauthenticated file listing on the partner document exchangeFND-8841
  • criticalMachine identity holds write access across three accountsFND-8829
  • criticalInvoice archive readable by the analytics lake roleFND-8824
Questions

About attack paths

Everything else is in the documentation.

No. Paths are derived from configuration, not from exploitation. If you want proof by exploitation, run a penetration test — the two methods complement each other.

Next step

Put attack paths against your own estate

A four-week proof of value connects one cloud account, your DNS and your identity provider, and ends with a written readout. Lodemark stays read-only throughout.

Book a walkthroughOpen the console demo

Illustrative product data. Nothing on this site performs a live scan.