Defender CSPM capability showing how an attacker could chain exploitable weaknesses together to reach critical assets.
Also called attack path analysis.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Attack paths in context, with comparison tables and the common traps.
Terms in this definition
- Defender CSPM
Defender for Cloud's paid posture tier. On top of the free foundations it brings agentless scanning, attack path analysis, AI security posture management and the cloud security explorer.
- Capability
Something that a person, organisation or system is able to do.
Related terms
- AI security posture management
Part of Defender CSPM, absent from Foundational CSPM, that finds generative AI workloads, compiles an AI bill of materials and highlights AI-specific recommendations and attack paths.
- Blast radius analysis
Replacing attack path analysis on the incident graph, this Defender view shows how a compromised entity might reach critical assets. The Microsoft Sentinel data lake is a prerequisite.
- Cloud security graph
Context engine in Defender for Cloud that links inventory, exposure, permissions, vulnerabilities and lateral movement paths; attack path analysis and cloud security explorer both build on it, and Defender CSPM is required.
- Enterprise exposure graph
Exposure Management's map of assets, identities, findings and how they connect, fed by Entra ID, Defender for Cloud, Defender for Endpoint, Defender for Identity and connectors. Attack paths are built from it, and advanced hunting can query it.
- Foundational CSPM
The no-cost posture tier of Defender for Cloud, which supplies Secure Score, recommendations and the Microsoft cloud security benchmark. Attack paths, AI-SPM and threat protection are not part of it.
- Risk prioritization (Defender for Cloud)
Part of Defender CSPM that weighs attack paths, lateral movement, data sensitivity and internet exposure to label each recommendation's risk as Critical, High, Medium or Low. Without that plan, the label says Not evaluated.