logo

Attack Graph Model Design Requirements and Examples

ID: e0b8dc72-3372-5c6b-af1e-a3e3d3bf730d

STIX ID: report--e0b8dc72-3372-5c6b-af1e-a3e3d3bf730d

Feed Name: SpecterOps Blog

Date Published: 2025-08-01

Date Updated: 2026-04-30

Author: Andy Robbins

...
...

This blog post introduces BloodHound OpenGraph and provides guidance for designing effective attack graph models, stressing directed edges that reflect attack semantics, strong connectedness, and unique identifiers; it then demonstrates how to encode system mechanics and configurations into actionable paths through traversable vs. non‑traversable edges, post‑processing, and composition edges, with worked examples for Windows/AD DAC, Entra RBAC, and ADCS scenarios (ESC1 and Golden Certificate) to minimize false positives and maximize analytical value.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.