Introducing Pathbreak
Key takeaways
- Pathbreak finds the attack paths in your cloud that a real attacker would use, and proves they work.
- It thinks like an attacker across identities, roles and trust relationships, then checks each chain for real. Read-only, always.
- For every path it confirms, you get the one change that breaks it. Fix that, not a thousand findings.
- AWS today, with deep coverage of control-plane moves like IAM privilege escalation and cross-account trust abuse. Azure and Microsoft Entra ID are next.
- It's Adversarial Exposure Validation (AEV), and it feeds a CTEM program. It's not breach and attack simulation.
Most security tools are great at telling you what's wrong. They're terrible at telling you what matters. They scan every account, surface thousands of findings, and leave your team to work out which handful an attacker could actually string together. So the backlog grows. The one misconfiguration that gets you owned is sitting in row 4,000, and nobody has time to dig it out.
We built Pathbreak to flip that around. It doesn't hand you a longer list. It finds the paths.
Findings are not attacks
Attackers don't think in findings. They think in routes. How do I get from a foothold to something that matters, usually admin or data? That route is an attack path, and it's a chain of small steps across identities, roles, trust relationships and resources. Each step looks boring on its own. Strung together, they're a straight line to domain admin.
A permission here. A role you can assume there. An over-scoped policy nobody remembers attaching. No single one of these is worth a 3am page. The chain is. Scanners see the pieces and miss the line that connects them.
What Pathbreak actually does
Pathbreak runs an agent that pokes at your cloud the way an attacker would. It maps where privileges could escalate, then walks each candidate chain to the end to see if it holds up. When one does, it shows you the path and hands you the exact change that breaks it.
There's more on the mechanics in how it works, and the chains we cover on the attack paths page. The gist is simple. We find the candidates, prove which ones are real, and tell you the single edit that severs each one.
Why "validated" is the word that matters
Plenty of tools will draw you a scary graph of everything that could theoretically happen. Theory is cheap. Pathbreak follows the real authorization end to end and confirms the path resolves, so what you're looking at is a route that works, not a maybe you still have to test by hand.
And it does all of this read-only. The agent reasons over identity and policy metadata to work out whether a chain is exploitable. Nothing runs against your resources. Nothing gets changed. We dig into that on the Trust and Security page, because a product that maps how to take over your cloud had better be careful with the keys.
Where it runs today
Right now, Pathbreak is built for AWS, and it goes deep on the control plane: IAM privilege escalation, cross-account trust abuse, the moves that actually get used. Azure and Microsoft Entra ID are next. Google Cloud and hybrid are on the roadmap. We'd rather be genuinely good at one cloud than mediocre across five.
Where Pathbreak fits
If you like category labels, this is Adversarial Exposure Validation, and it feeds straight into a CTEM program. Pathbreak validates exposure the way an attacker would, continuously, and surfaces only the paths that are actually reachable.
One thing it isn't: breach and attack simulation. We don't fire test payloads at your controls to see what your detections catch. We reason over your real authorization and prove where an attacker could get. The FAQ spells out the distinction if you want it.
What's next
This is the first of many. We'll write about the specific chains we run into, how control-plane privilege escalation really plays out in AWS, and how to tell a path that matters from a finding that doesn't. Pathbreak is in private preview, and we're taking on design partners now. If that's you, come say hello.
Want to see the real attack paths in your cloud, then break them?
Request a demo