Attack-path mapping
SkillAI & modelsModel the target as an attack graph, nodes (assets, identities, trust) and edges (a technique that gets you from one to the next), and find the shortest path to the objective. Load when many findings need to be assembled into a route, on "how do these bugs connect", AD/cloud lateral- movement planning, or to explain how a foothold reaches crown jewels.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Attack-path mapping skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/tradecraft/tradecraft-attack-path-mapping/SKILL.md and read by ahel’s review.
When it applies
You have several footholds/findings and need to see how they combine into a route to the objective — or you're defending and want to know which single edge, if cut, breaks the most paths.
Why it works
Attackers think in graphs; defenders who do too find the choke points. Modelling principals → permissions → resources as edges makes "can A reach D?" a reachability query, and surfaces multi-step paths no single finding reveals (this is why BloodHound changed AD assessment).
Method
- Nodes: assets (hosts, buckets, DBs), identities (users, roles, service accounts), and secrets.
- Edges = a technique you can actually run: "user→host" (valid creds / RCE), "host→identity"
(token/cred theft —
privesc-*,cloud-imds-ssrf), "identity→identity" (delegation, role assumption —ad-*,cloud-iam-privesc), "identity→data" (read access). Label each edge with its skill. - Build the graph: BloodHound (AD), PMapper/Cartography (AWS/cloud IAM), or a hand-drawn graph
in
notes.mdfor smaller scopes. - Query for paths: shortest path from a controlled node to the objective; enumerate alternates.
- Pick the path: lowest cost/noise, highest reliability. Each edge becomes an ordered lead in
the scenario (
tradecraft-attack-scenarios). - Defensive read: rank edges by how many objective-paths traverse them — those are the remediation priorities (kill the edge, not just the node).
Gotchas
- An edge you can't actually execute is not an edge — validate the technique, don't assume it.
- Graphs go stale as you change the environment (new creds, revoked tokens); re-query after each win.
- Don't collect the whole graph when one path proves impact — least action.
Verify success
You can state the full path — node by node, edge by edge, each edge a runnable technique — from a starting position to the objective, and name the one edge whose removal breaks it.
References
BloodHound / SharpHound; NCC PMapper; AWS/GCP Cartography; MITRE ATT&CK flow.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
tradecraft-attack-path-mapping- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · awslabs
The pick for AWSaws-health-events
Skill · aws
The pick for AWSgcp-config-connector
Skill · gke-labs
The pick for GCPgcp-compute
Skill · bagelhole
The pick for GCPenrich-with-aws-security-agent
Skill · aws
The pick for AWSdeploying-on-aws
Skill · ancoleman
The pick for AWS