Attack Paths
An attack path is a chain SubImage reconstructs from your graph showing how an attacker could move from an entry point to something that matters: an admin role, a database, a secret. Each step is a real capability an attacker would gain (network access, code execution, identity assumption, administrative control) traced across your cloud, identity, and code resources. Instead of a flat list of misconfigurations, you see how they combine into a route.
Paths are discovered automatically each time your data is refreshed. A path can come from the routine discovery pass or from a specific finding.
The Attack Paths page
Open Attack Paths to see every discovered path.
Each path in the list shows:
- Name of the path.
- Criticality bars. Criticality combines how damaging the path is with how easy it is to walk.
- Confidence, as a percentage when SubImage has enough data to score it.
- Steps: how many hops are in the chain.
- Factors: the attack techniques the path uses, shown as icon chips.
- When it was last seen.
Sort by Criticality (the default), Last Seen, First Seen, Confidence, or Resources. Filter by Factors or search by name. Work top-down: a critical, high-confidence path reaching a crown-jewel asset is where to start.
Reading a path
Click a path to open it. The page follows the same layout as other detail views: a header, a step timeline, and a sidebar of scores and dates.
The header repeats the name, criticality, confidence, step count, and origin. Origin is scanner (the default discovery pass) or finding (a detection rule produced it), plus when the path was first created and last seen.
- Description: a plain-language explanation of the path, when available.
- Steps: each step names the resource involved and the capability the attacker gains there, with a short description of how. A step marked critical is called out visually. Read top to bottom: the first step is the entry point, the last is the impact.
- Sidebar: Criticality, Confidence, First seen, Last seen, and Factors.
The capabilities you will see across steps:
| Capability | What the attacker gains |
|---|---|
CAN_ACCESS |
Network or API access to a resource |
CAN_USE |
The ability to assume an identity |
CAN_EXEC |
Code execution on a resource |
CAN_ADMIN |
Full administrative control |
Entry points are typically internet-exposed resources (for example an internet-facing EC2 instance) that need no prior access. The end of a path is usually a critical asset: a database, a secret, or a high-privilege identity your deployment treats as high value.
Visualize opens the graph explorer around the path in a new tab.
How attack paths relate to the rest of SubImage
Attack paths are one of the raw signals behind Issues: a path that runs through an affected resource shows up as a supporting signal on the relevant issue, which is how path context feeds prioritization. A path can also raise the criticality of a finding: if a rule's result sits on a critical step, that step elevates the finding's priority.
Programmatic access
The same paths are available over MCP, so an agent can enumerate and walk them alongside you: subimageListAttackPaths, subimageGetAttackPathDetails, and subimageGetAttackPathsFromAsset. For a guided walkthrough, the subimage-mcp:review-attack-path skill steps through a path, hunts for credible extensions, and proposes the fastest fix. See Connect via MCP and Agent Skills.