Case Study - Attack Path Analysis (Connect the Dots Attackers Connect)
6 “mediums” nobody prioritized = 1 path from guest Wi-Fi to core banking DB. We walked it in staging.
Client Context
Manufacturing + finance conglomerate — corporate IT + plant OT + core banking subsidiary sharing IAM. Red team budget limited; needed to know which paths matter most.
Challenge
Single findings looked “medium”. Combined, they were critical. Need to link weaknesses into attack paths from entry point to critical assets — and prove which paths are real vs theoretical.
Scope - Snipeyes Attack Path Analysis
- Identity + network + app graph: users, hosts, trusts, sessions, ACLs, vulns correlated
- Path enumeration to crown jewels (DC, core DB, HMI, payment switch) ranked by steps + noise + controls
- Controlled validation of top paths in lab/staging (no prod impact)
- Output: attack paths with choke points + fix that breaks most paths cheapest
Key Findings (redacted)
- 14 paths to Tier-0, 3 fully validated; cheapest break: 2 fixes (SMB signing + tiered admin) killed 11 paths
- Guest Wi-Fi → printer → NTLM relay → jump host → DB read (6 mediums chained)
- Service account with
*ALLOBJ-equivalent + password in deployment script = instant domain path
Outcome
- 2 fixes broke 79% of paths; remaining paths required 4+ steps with detection — SOC tuned to choke points
- Board finally understood “medium” risk: one diagram did more than 40 pages
- Path graph re-runs monthly; new paths alert within 24h of infra change
Relevance for you: If you fix findings one-by-one — map the paths and break the graph instead.