MappingΒΆ
Reachability maps to network movement, identity transitions govern impersonation, trust defines what systems honour without challenge, and structural dependency exposes operational fragility. Measuring only network reachability leaves the underlying estate unread because a position touches endpoints, is honoured by specific systems, and carries dependent services along every path.
BloodHound analysis may expose Kerberos delegation paths and group memberships that lead towards domain administration within Active Directory environments. Industrial architectures may reveal dual-homed engineering workstations bridging corporate networks to process historians, programmable logic controllers, or safety systems. Cloud environments may expose cross-account role assumption chains and Instance Metadata Service (IMDS) endpoints that provide temporary credentials, which may in turn grant access to data lakes or key management services. Web applications may contain server-side request forgery vulnerabilities that reach internal metadata services or adjacent administrative applications.
Each discovered element functions as a leverage point rather than an isolated trophy. An account carries execution authority, a host opens network routing paths, and a service introduces underlying system dependencies. Whether a node offers transit, who else occupies it, and what it holds locally sorts candidates faster than further discovery. Trust failures span internet-scale attacks such as Border Gateway Protocol (BGP) route hijacking and Domain Name System (DNS) spoofing down to routing protocols such as Open Shortest Path First (OSPF) or Routing Information Protocol (RIP) operating without authentication, where routing advertisements can disclose or manipulate local network topology.
Turn an edge into position, or keep drawing. Mapping reveals fresh paths, and discovery reveals new targets.