Skip to content
BreachPathAttack Path LibraryStart

Attack path library

How separate weaknesses, identities and controls get chained into a real outcome. Filter by what matters to you, then generate a red-team brief from the paths that apply.

21 paths

IntermediateMicrosoft 365

Microsoft 365 account to sensitive data

A phished Microsoft 365 identity is turned into durable access, used to discover where sensitive data lives in SharePoint and Teams, and finally to quietly extract it — all without dropping malware.

Credential phishingOAuth applicationSharePoint andSensitive data
Data theftAccount takeover
AdvancedCustom web applications

Web application flaw to cloud credentials

A flaw in an internet-facing custom application is used to reach the workload's identity, harvest cloud credentials, and pivot into the wider cloud account where production data lives.

A flawThe workloadCloud permissionsProduction data
Data theftIntellectual-property theft
AdvancedOn-premises Active Directory

Exposed VPN to Active Directory ransomware

Weakly protected remote access is used to reach the internal network, escalate to domain-wide control of Active Directory, neutralise backups and stage ransomware across the estate.

Remote accessActive DirectoryDomain-wide controlBackups are
Ransomware
IntermediateMicrosoft 365

Entra ID guest account to privileged access

An over-permissioned external guest identity is used to enumerate the tenant, abuse excessive directory rights and escalate toward privileged roles and the resources they unlock.

An externalThe directoryPrivileged role
Account takeoverData theft
AdvancedCustom web applications

Source-control token to production environment

A leaked source-control token grants access to private repositories, where hardcoded secrets and CI/CD trust are used to reach and exfiltrate from the production environment and its source code.

A leakedSecrets andProduction isSource code
Intellectual-property theftData theft
IntermediateAWS

AWS access key to data exfiltration

A leaked long-lived AWS access key is used to enumerate the account, escalate through permissive IAM, and read and exfiltrate data from cloud storage and databases.

A leakedPermissions areData is
Data theft
FoundationalMicrosoft 365

Business email compromise to invoice fraud

A compromised finance or executive mailbox is used to study payment processes, establish stealthy persistence, and redirect a legitimate payment to an attacker-controlled account.

A financePayment processesA payment
Payment / invoice fraud
AdvancedOn-premises Active Directory

Supplier account to internal network

A compromised supplier's access is used to enter the organisation through a trusted connection, then to move from the supplier's limited footprint toward internal systems and data.

A supplier'sThe trustedInternal systems
Data theftRansomware
IntermediateSaaS (generic)

SaaS administrator compromise

A phished SaaS administrator identity is used to weaken tenant security settings, establish persistence via integrations, and access or export the customer and business data the platform holds.

A SaaSSecurity isCustomer and
Account takeoverData theft
IntermediateGoogle Workspace

Google Workspace account to data theft

A phished Google Workspace identity is turned into durable access through a third-party app grant, then used to search Drive and Gmail for sensitive material and export it.

A WorkspaceA third-partySensitive data
Data theftAccount takeover
AdvancedCustom web applications

Vulnerable web application to ransomware

A flaw in an internet-facing application provides a server foothold, which is used to move onto the internal network, escalate privilege and deploy ransomware against reachable systems.

The internet-facingThe attackerRansomware is
Ransomware
AdvancedOn-premises Active Directory

Stolen credentials to domain administrator

A single reused password gets a foothold in Active Directory, which is turned — through service-account weaknesses and credential reuse — into full domain-administrator control.

A reusedWeak serviceDomain-administrator control
Account takeover
FoundationalMicrosoft 365

MFA fatigue to Microsoft 365 takeover

With a valid password in hand, an attacker wears the user down with repeated approval prompts, registers their own authenticator for durable access, and takes over the Microsoft 365 account.

A validThe userThe attacker
Account takeover
AdvancedAzure

Azure managed identity to subscription control

A compromised Azure workload is used to assume its managed identity, whose over-broad role assignments are escalated toward control of the subscription and the data it holds.

A workloadOver-broad roleSubscription data
Data theftAccount takeover
IntermediateMicrosoft 365

Phishing to executive communications compromise

A targeted lure compromises an executive or assistant mailbox, which is quietly monitored to harvest sensitive correspondence and impersonate leadership for further reach.

An executiveThe mailboxLeadership is
Account takeoverData theft
IntermediateOn-premises Active Directory

Exposed remote desktop to ransomware

An internet-exposed remote desktop service with weak authentication gives direct interactive access to a host, which is used to spread, escalate and deploy ransomware.

Exposed remoteThe attackerRansomware is
Ransomware
IntermediateCustom web applications

Web skimming to payment fraud

A weakness in an e-commerce site or one of its third-party scripts is used to capture customers' payment details at checkout, which are then used or sold for fraud.

The checkoutPayment detailsStolen card
Payment / invoice fraudData theft
FoundationalSaaS (generic)

SaaS API token to data theft

A leaked API token for a business SaaS platform is used to access its API directly, enumerate what the token can reach, and export data at scale — bypassing the login and its MFA entirely.

A leakedThe token'sData is
Data theft
AdvancedSaaS (generic)

Identity provider compromise to federated access

An attacker who reaches the single sign-on identity provider abuses its trust to grant themselves access across every federated application at once — turning one identity system into keys to the whole estate.

Administrative accessFederation trustFederated applications
Account takeoverData theft
IntermediateCustom web applications

Patient portal to clinical records

A weakness in a patient-facing portal or its integration is used to move from a single account's view to broad access to clinical records held in connected systems.

A weaknessPortal integrationsPatient records
Data theft
AdvancedSaaS (generic)

Supplier software update to ransomware

A trusted software update from a compromised supplier delivers attacker code into the environment, which is used to establish control and deploy ransomware from the inside.

Attacker codeControl isRansomware is
Ransomware