Skip to content

Add "non-tier-zero shortest path to tier zero" queries#51

Open
chryzsh wants to merge 1 commit intoSpecterOps:mainfrom
chryzsh:add-non-t0-shortest-paths
Open

Add "non-tier-zero shortest path to tier zero" queries#51
chryzsh wants to merge 1 commit intoSpecterOps:mainfrom
chryzsh:add-non-t0-shortest-paths

Conversation

@chryzsh
Copy link
Copy Markdown

@chryzsh chryzsh commented Mar 23, 2026

We found that breaking down paths to Tier Zero by source type makes sense during testing and helps vizualise specific attacks paths to Tier Zero in reporting. We found them to be a good alternative to the built-in "Shortest paths to Tier Zero / High Value targets" query, which doesn't exclude Tier Zero to Tier Zero paths. Each query filters sources that are NOT Tier Zero and targets that ARE Tier Zero using both Tag_Tier_Zero labels and system_tags.

  • Shortest paths from non-Tier Zero computers to Tier Zero
  • Shortest paths from non-Tier Zero groups to Tier Zero
  • Shortest paths from non-Tier Zero objects to Tier Zero
  • Shortest paths from non-Tier Zero user accounts to Tier Zero

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant