AzureHow-To & HardeningRetrospectives

How to Use Attack Path Analysis to Prioritize Cloud Fixes

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2024, written in 2026 with the benefit of hindsight.

Not all vulnerabilities and misconfigurations matter equally. Attack path analysis shows which ones an attacker could chain to reach your critical assets. Here is how to use it in Microsoft Defender.

Where attack paths appear

  • Microsoft Defender for Cloud (Defender CSPM): cloud attack paths across Azure, AWS and GCP — for example, an internet-exposed VM with a vulnerability and a managed identity that can read a storage account with sensitive data.
  • Microsoft Security Exposure Management: attack paths across identities, devices and cloud resources from multiple Defender products.

Step 1: Define critical assets

Mark crown jewels: domain controllers, identity infrastructure, key databases, storage with sensitive data, Key Vaults, privileged identities. Exposure Management includes predefined classifications and lets you add custom ones.

Step 2: Review attack paths

In Defender for Cloud, open Attack path analysis. Sort by risk level. For each path, note:

  • Entry point (for example, internet exposure).
  • Steps (vulnerability, permissions, lateral movement).
  • Target (critical asset).

Step 3: Find choke points

Look for steps that appear in many paths — for example, one over-privileged managed identity or one exposed VM. Fixing a choke point breaks multiple paths at once.

Step 4: Fix and verify

Assign remediation to owners, then confirm the path disappears after the next assessment.

Step 5: Use cloud security explorer

Query your environment for patterns, such as "VMs exposed to the internet with high-severity vulnerabilities and permissions to Key Vault."

Step 6: Report by exposure, not by count

Report to leadership: number of attack paths to critical assets, trend over time, and top choke points fixed.

cloud attack path analysisIgnite 2024 Exposure Management2024

More on this story