BreachLab

Model the breach before it happens.

BreachLab is a persistent adversarial lab for asking questions, modelling Identity Progression Vectors, simulating compromised identities and testing which changes break paths to sensitive data.

For

Cloud security, IAM security, detection engineering and security architecture teams.

Answers

How do we model, test and reduce Identity Progression Vectors before changes go live?

Tests

Whether controls, permission changes and architecture decisions actually reduce paths to sensitive data.

When teams bring it in

01

Before changing permissions

Test whether a role, policy or account change reduces paths to sensitive data.

02

When an identity looks overpowered

Simulate what happens if a user, service account or workload is compromised.

03

When fixes compete for attention

Compare which remediation option breaks the most important paths.

04

When the path from login to data is unclear

Model how a compromised user, service account or workload could move from initial access toward sensitive data.

Next step

Test which changes reduce paths from identity to sensitive data.

Related reading

Related reading.

Further reading on modelling identity-to-data paths, breach progression, and the access chains attackers exploit.

What are Identity Progression Attacks?

A practical definition of Identity Progression Attacks and why defenders need to detect movement from foothold to high-value target.

The real breach starts before attackers exfiltrate data

Why security teams need to detect attacker progression before confirmed data loss.

Supply chain attacks are a credential theft problem

Why software supply chain compromises often become fast-moving identity-to-data attacks once credentials are stolen.