logo

Taming the Attack Graph: A Many Subgraphs Approach to Attack Path Analysis

ID: 8fcc1d17-a735-5c35-bdac-e49ca439d7c4

STIX ID: report--8fcc1d17-a735-5c35-bdac-e49ca439d7c4

Feed Name: SpecterOps Blog

Date Published: 2025-11-13

Date Updated: 2026-04-30

Author: Jd Crandell

...
...

This blog proposes a framework using technology subgraphs, decomposition, and graph abstraction to model hybrid attack paths across enterprise platforms, highlighting “credential watering holes” like GitHub Secret Scanning that can fan out access to many systems. It illustrates the approach with a red team scenario that leveraged GitHub org-admin access to enumerate secret-scanning alerts and harvest credentials (e.g., GCP service accounts), and introduces SecretHound for modeling secrets within BloodHound OpenGraph. The article emphasizes identifying subgraph-local tier-zero nodes and applying OpenGraph collectors to manage and visualize cross-platform attack paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.