<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>BreachPath — Attack Path Library</title>
    <link>https://breachpath.org</link>
    <atom:link href="https://breachpath.org/feed.xml" rel="self" type="application/rss+xml" />
    <description>An interactive library of realistic attack paths — from initial access to business impact — mapped to MITRE ATT&amp;CK, with the controls, telemetry and red-team tests that break each chain.</description>
    <language>en-GB</language>
    <item>
      <title>Blocking Basic RDP Brute Force Attacks</title>
      <link>https://breachpath.org/notes/account-lockout-and-strong-unique-credentials</link>
      <guid isPermaLink="true">https://breachpath.org/notes/account-lockout-and-strong-unique-credentials</guid>
      <description>Implement high-entropy credentials and account lockout policies to prevent automated brute force attacks targeting exposed remote desktop protocol services.</description>
      <pubDate>Tue, 01 Sep 2026 09:00:00 GMT</pubDate>
      <category>One Control, Tested</category>
      <category>rdp</category>
      <category>brute-force</category>
      <category>account-lockout</category>
      <category>password-policy</category>
    </item>
    <item>
      <title>Bulk data egress detection for cloud storage</title>
      <link>https://breachpath.org/notes/access-logging-with-alerting-on-bulk-reads</link>
      <guid isPermaLink="true">https://breachpath.org/notes/access-logging-with-alerting-on-bulk-reads</guid>
      <description>This control detects bulk data exfiltration by flagging anomalous read volumes in cloud storage and databases via high-severity alerts within the SIEM system.</description>
      <pubDate>Fri, 28 Aug 2026 09:00:00 GMT</pubDate>
      <category>One Control, Tested</category>
      <category>cloud-storage</category>
      <category>data-exfiltration</category>
      <category>anomaly-detection</category>
      <category>siem</category>
    </item>
    <item>
      <title>Killing Active Sessions Across the Federated Fleet</title>
      <link>https://breachpath.org/notes/ability-to-break-federation-and-force-re-authentication-quickly</link>
      <guid isPermaLink="true">https://breachpath.org/notes/ability-to-break-federation-and-force-re-authentication-quickly</guid>
      <description>This control revokes active sessions across federated service providers to stop a compromised identity from maintaining persistence via hijacked tokens.</description>
      <pubDate>Tue, 25 Aug 2026 09:00:00 GMT</pubDate>
      <category>One Control, Tested</category>
      <category>session-revocation</category>
      <category>federation</category>
      <category>identity-provider</category>
      <category>saas-security</category>
    </item>
    <item>
      <title>Out-of-Band Verification for Urgent Requests</title>
      <link>https://breachpath.org/notes/a-culture-where-staff-can-question-unusual-executive-requests</link>
      <guid isPermaLink="true">https://breachpath.org/notes/a-culture-where-staff-can-question-unusual-executive-requests</guid>
      <description>This control mandates out-of-band verification to stop CEO fraud and business email compromise by requiring a second channel for all urgent payment requests.</description>
      <pubDate>Fri, 21 Aug 2026 09:00:00 GMT</pubDate>
      <category>One Control, Tested</category>
      <category>ceo-fraud</category>
      <category>bec</category>
      <category>social-engineering</category>
      <category>out-of-band</category>
      <category>impersonation</category>
    </item>
    <item>
      <title>Blocking Lateral Movement through Endpoint Hardening</title>
      <link>https://breachpath.org/notes/least-privilege-and-credential-theft-protections</link>
      <guid isPermaLink="true">https://breachpath.org/notes/least-privilege-and-credential-theft-protections</guid>
      <description>This security control limits lateral movement by blocking workstation RDP, preventing credential dumping from memory, and enforcing strict least privilege.</description>
      <pubDate>Tue, 18 Aug 2026 09:00:00 GMT</pubDate>
      <category>One Control, Tested</category>
      <category>lateral-movement</category>
      <category>endpoint-hardening</category>
      <category>rdp</category>
      <category>least-privilege</category>
      <category>credential-dumping</category>
    </item>
    <item>
      <title>Stopping Ransomware from Killing the Backups</title>
      <link>https://breachpath.org/notes/immutable-offline-backups-tested-for-restore</link>
      <guid isPermaLink="true">https://breachpath.org/notes/immutable-offline-backups-tested-for-restore</guid>
      <description>Implement immutable, offline backups to prevent ransomware from deleting recovery points, ensuring critical business data remains recoverable after an attack.</description>
      <pubDate>Tue, 18 Aug 2026 09:00:00 GMT</pubDate>
      <category>One Control, Tested</category>
      <category>ransomware-protection</category>
      <category>immutable-backups</category>
      <category>disaster-recovery</category>
      <category>data-integrity</category>
    </item>
    <item>
      <title>Supplier software update to ransomware</title>
      <link>https://breachpath.org/attack-paths/supplier-software-update-to-ransomware</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/supplier-software-update-to-ransomware</guid>
      <description>A trusted software update from a compromised supplier delivers attacker code into the environment, which is used to establish control and deploy ransomware from the inside.</description>
      <category>manufacturing</category>
      <category>healthcare</category>
      <category>retail</category>
      <category>financial-services</category>
      <category>professional-services</category>
      <category>ransomware</category>
    </item>
    <item>
      <title>Patient portal to clinical records</title>
      <link>https://breachpath.org/attack-paths/healthcare-portal-to-patient-data</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/healthcare-portal-to-patient-data</guid>
      <description>A weakness in a patient-facing portal or its integration is used to move from a single account's view to broad access to clinical records held in connected systems.</description>
      <category>healthcare</category>
      <category>data-theft</category>
    </item>
    <item>
      <title>Identity provider compromise to federated access</title>
      <link>https://breachpath.org/attack-paths/identity-provider-compromise-to-federated-access</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/identity-provider-compromise-to-federated-access</guid>
      <description>An attacker who reaches the single sign-on identity provider abuses its trust to grant themselves access across every federated application at once — turning one identity system into keys to the whole estate.</description>
      <category>saas</category>
      <category>financial-services</category>
      <category>professional-services</category>
      <category>manufacturing</category>
      <category>account-takeover</category>
      <category>data-theft</category>
    </item>
    <item>
      <title>SaaS API token to data theft</title>
      <link>https://breachpath.org/attack-paths/saas-api-token-to-data-theft</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/saas-api-token-to-data-theft</guid>
      <description>A leaked API token for a business SaaS platform is used to access its API directly, enumerate what the token can reach, and export data at scale — bypassing the login and its MFA entirely.</description>
      <category>saas</category>
      <category>professional-services</category>
      <category>financial-services</category>
      <category>retail</category>
      <category>data-theft</category>
    </item>
    <item>
      <title>Web skimming to payment fraud</title>
      <link>https://breachpath.org/attack-paths/web-skimming-to-payment-fraud</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/web-skimming-to-payment-fraud</guid>
      <description>A weakness in an e-commerce site or one of its third-party scripts is used to capture customers' payment details at checkout, which are then used or sold for fraud.</description>
      <category>retail</category>
      <category>charity</category>
      <category>saas</category>
      <category>invoice-fraud</category>
      <category>data-theft</category>
    </item>
    <item>
      <title>Exposed remote desktop to ransomware</title>
      <link>https://breachpath.org/attack-paths/exposed-rdp-to-ransomware</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/exposed-rdp-to-ransomware</guid>
      <description>An internet-exposed remote desktop service with weak authentication gives direct interactive access to a host, which is used to spread, escalate and deploy ransomware.</description>
      <category>manufacturing</category>
      <category>retail</category>
      <category>healthcare</category>
      <category>professional-services</category>
      <category>charity</category>
      <category>ransomware</category>
    </item>
    <item>
      <title>Phishing to executive communications compromise</title>
      <link>https://breachpath.org/attack-paths/phishing-to-executive-communications</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/phishing-to-executive-communications</guid>
      <description>A targeted lure compromises an executive or assistant mailbox, which is quietly monitored to harvest sensitive correspondence and impersonate leadership for further reach.</description>
      <category>legal</category>
      <category>financial-services</category>
      <category>professional-services</category>
      <category>manufacturing</category>
      <category>account-takeover</category>
      <category>data-theft</category>
    </item>
    <item>
      <title>Azure managed identity to subscription control</title>
      <link>https://breachpath.org/attack-paths/azure-managed-identity-to-subscription-control</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/azure-managed-identity-to-subscription-control</guid>
      <description>A compromised Azure workload is used to assume its managed identity, whose over-broad role assignments are escalated toward control of the subscription and the data it holds.</description>
      <category>saas</category>
      <category>financial-services</category>
      <category>manufacturing</category>
      <category>professional-services</category>
      <category>data-theft</category>
      <category>account-takeover</category>
    </item>
    <item>
      <title>MFA fatigue to Microsoft 365 takeover</title>
      <link>https://breachpath.org/attack-paths/mfa-fatigue-to-microsoft-365-takeover</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/mfa-fatigue-to-microsoft-365-takeover</guid>
      <description>With a valid password in hand, an attacker wears the user down with repeated approval prompts, registers their own authenticator for durable access, and takes over the Microsoft 365 account.</description>
      <category>saas</category>
      <category>professional-services</category>
      <category>financial-services</category>
      <category>retail</category>
      <category>charity</category>
      <category>account-takeover</category>
    </item>
    <item>
      <title>Stolen credentials to domain administrator</title>
      <link>https://breachpath.org/attack-paths/stolen-credentials-to-domain-admin</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/stolen-credentials-to-domain-admin</guid>
      <description>A single reused password gets a foothold in Active Directory, which is turned — through service-account weaknesses and credential reuse — into full domain-administrator control.</description>
      <category>professional-services</category>
      <category>manufacturing</category>
      <category>financial-services</category>
      <category>legal</category>
      <category>healthcare</category>
      <category>account-takeover</category>
    </item>
    <item>
      <title>Vulnerable web application to ransomware</title>
      <link>https://breachpath.org/attack-paths/vulnerable-web-application-to-ransomware</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/vulnerable-web-application-to-ransomware</guid>
      <description>A flaw in an internet-facing application provides a server foothold, which is used to move onto the internal network, escalate privilege and deploy ransomware against reachable systems.</description>
      <category>retail</category>
      <category>manufacturing</category>
      <category>healthcare</category>
      <category>professional-services</category>
      <category>ransomware</category>
    </item>
    <item>
      <title>Google Workspace account to data theft</title>
      <link>https://breachpath.org/attack-paths/google-workspace-account-to-data-theft</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/google-workspace-account-to-data-theft</guid>
      <description>A phished Google Workspace identity is turned into durable access through a third-party app grant, then used to search Drive and Gmail for sensitive material and export it.</description>
      <category>saas</category>
      <category>charity</category>
      <category>professional-services</category>
      <category>retail</category>
      <category>data-theft</category>
      <category>account-takeover</category>
    </item>
    <item>
      <title>SaaS administrator compromise</title>
      <link>https://breachpath.org/attack-paths/saas-administrator-compromise</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/saas-administrator-compromise</guid>
      <description>A phished SaaS administrator identity is used to weaken tenant security settings, establish persistence via integrations, and access or export the customer and business data the platform holds.</description>
      <category>saas</category>
      <category>professional-services</category>
      <category>retail</category>
      <category>charity</category>
      <category>financial-services</category>
      <category>account-takeover</category>
      <category>data-theft</category>
    </item>
    <item>
      <title>Supplier account to internal network</title>
      <link>https://breachpath.org/attack-paths/supplier-account-to-internal-network</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/supplier-account-to-internal-network</guid>
      <description>A compromised supplier's access is used to enter the organisation through a trusted connection, then to move from the supplier's limited footprint toward internal systems and data.</description>
      <category>manufacturing</category>
      <category>retail</category>
      <category>healthcare</category>
      <category>financial-services</category>
      <category>professional-services</category>
      <category>data-theft</category>
      <category>ransomware</category>
    </item>
    <item>
      <title>Business email compromise to invoice fraud</title>
      <link>https://breachpath.org/attack-paths/business-email-compromise-to-invoice-fraud</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/business-email-compromise-to-invoice-fraud</guid>
      <description>A compromised finance or executive mailbox is used to study payment processes, establish stealthy persistence, and redirect a legitimate payment to an attacker-controlled account.</description>
      <category>professional-services</category>
      <category>legal</category>
      <category>manufacturing</category>
      <category>charity</category>
      <category>retail</category>
      <category>invoice-fraud</category>
    </item>
    <item>
      <title>AWS access key to data exfiltration</title>
      <link>https://breachpath.org/attack-paths/aws-access-key-to-data-exfiltration</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/aws-access-key-to-data-exfiltration</guid>
      <description>A leaked long-lived AWS access key is used to enumerate the account, escalate through permissive IAM, and read and exfiltrate data from cloud storage and databases.</description>
      <category>saas</category>
      <category>retail</category>
      <category>financial-services</category>
      <category>healthcare</category>
      <category>data-theft</category>
    </item>
    <item>
      <title>Source-control token to production environment</title>
      <link>https://breachpath.org/attack-paths/source-control-token-to-production</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/source-control-token-to-production</guid>
      <description>A leaked source-control token grants access to private repositories, where hardcoded secrets and CI/CD trust are used to reach and exfiltrate from the production environment and its source code.</description>
      <category>saas</category>
      <category>financial-services</category>
      <category>manufacturing</category>
      <category>ip-theft</category>
      <category>data-theft</category>
    </item>
    <item>
      <title>Entra ID guest account to privileged access</title>
      <link>https://breachpath.org/attack-paths/entra-id-guest-to-privileged-access</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/entra-id-guest-to-privileged-access</guid>
      <description>An over-permissioned external guest identity is used to enumerate the tenant, abuse excessive directory rights and escalate toward privileged roles and the resources they unlock.</description>
      <category>saas</category>
      <category>professional-services</category>
      <category>financial-services</category>
      <category>legal</category>
      <category>account-takeover</category>
      <category>data-theft</category>
    </item>
    <item>
      <title>Exposed VPN to Active Directory ransomware</title>
      <link>https://breachpath.org/attack-paths/exposed-vpn-to-active-directory-ransomware</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/exposed-vpn-to-active-directory-ransomware</guid>
      <description>Weakly protected remote access is used to reach the internal network, escalate to domain-wide control of Active Directory, neutralise backups and stage ransomware across the estate.</description>
      <category>manufacturing</category>
      <category>healthcare</category>
      <category>retail</category>
      <category>professional-services</category>
      <category>financial-services</category>
      <category>ransomware</category>
    </item>
    <item>
      <title>Web application flaw to cloud credentials</title>
      <link>https://breachpath.org/attack-paths/web-application-flaw-to-cloud-credentials</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/web-application-flaw-to-cloud-credentials</guid>
      <description>A flaw in an internet-facing custom application is used to reach the workload's identity, harvest cloud credentials, and pivot into the wider cloud account where production data lives.</description>
      <category>saas</category>
      <category>retail</category>
      <category>financial-services</category>
      <category>manufacturing</category>
      <category>professional-services</category>
      <category>data-theft</category>
      <category>ip-theft</category>
    </item>
    <item>
      <title>Microsoft 365 account to sensitive data</title>
      <link>https://breachpath.org/attack-paths/microsoft-365-account-to-sensitive-data</link>
      <guid isPermaLink="true">https://breachpath.org/attack-paths/microsoft-365-account-to-sensitive-data</guid>
      <description>A phished Microsoft 365 identity is turned into durable access, used to discover where sensitive data lives in SharePoint and Teams, and finally to quietly extract it — all without dropping malware.</description>
      <category>legal</category>
      <category>financial-services</category>
      <category>professional-services</category>
      <category>healthcare</category>
      <category>saas</category>
      <category>data-theft</category>
      <category>account-takeover</category>
    </item>
  </channel>
</rss>
