Attack paths
Paths descend through the strata from an entry point to something that actually costs you. Each path carries a blast radius, a choke point and the findings it depends on.
live paths reaching a Core asset, down from 26
What attack paths actually does
Traversal modelling
Reachability is computed from network routes, trust policies, credential locations and admission rules — not from severity scores.
Choke points
The single hop whose removal closes the most paths, ranked by how much exposure it takes with it.
Blast radius
What the destination holds, who depends on it and which reports break if it is touched.
Containment record
When a path is contained rather than closed, that state is explicit, dated and reviewed.
See it working on demo data
- Reachability is computed from network routes, trust policies, credential locations and admission rules.
- Choke points are ranked by how many live paths they close and what the change costs the owning team.
- Containment is a first-class state with a required review date, kept separate from closed.
Supplier exchange to invoice archive
An anonymous listing on the supplier exchange leaks object keys. Those keys resolve through the ingest identity, which can read the invoice archive because the bucket policy grants the analytics role without a prefix restriction.
Scroll the figure sideways to follow the path
Directory listing returns object keys for the whole exchange prefix.
- Entry point
- supplier-docs.northfleet.io
- Destination
- nfg-invoice-archive
7 years of invoices · 2,140 supplier records · 4 downstream reports
Scope the ingest trust policy to the task role
Removes 4 of 7 live paths and drops the exposure score by 9 points.
- criticalUnauthenticated file listing on the partner document exchangeFND-8841
- criticalMachine identity holds write access across three accountsFND-8829
- criticalInvoice archive readable by the analytics lake roleFND-8824
No. Paths are derived from configuration, not from exploitation. If you want proof by exploitation, run a penetration test — the two methods complement each other.
You tell us. Crown-jewel assets are labelled during onboarding, and the label can be inherited from data classification tags where you already have them.
It is still modelled, and it is flagged as third-party. The choke point ranking accounts for the fact that you cannot change someone else's configuration.
Put attack paths against your own estate
A four-week proof of value connects one cloud account, your DNS and your identity provider, and ends with a written readout. Lodemark stays read-only throughout.
Illustrative product data. Nothing on this site performs a live scan.