IDENTITY ATTACK PATH ANALYSIS

Lateral-movement paths through identities and permissions are invisible until an attacker walks them, so the routes from a low-value account to a crown jewel go unmapped. Defence is blind to the graph.

Actors

  • Identity & Access (IAM) Lead
  • SOC Manager
  • Security Analysts

Systems / Vendors

  • IAM / IGA
  • Identity graph / ITDR
  • Directory

Business Question

"If an attacker landed on any account, what's the shortest path from there to our crown jewels?"

What SPoG Does

  • Maps lateral-movement paths using identities and permissions.
  • Highlights the shortest routes to critical assets.
  • Directs remediation to break the key paths.

Outcome Metrics

−40%

Exploitable attack paths

1

Live path analysis

6–10 wks

To first outcomes