Predictive attack paths

3 modelled paths · blast radius 76 Elevated

Attack path prioritisation

Ranked by explicit dimensions

Rank 91

Ranking combines five measured dimensions rather than one opaque score. Each dimension is shown so an analyst can disagree with the ordering on its own terms.

Attack path graph · INC-2471

Stale OAuth grant to ledger signing key

active
Confirmed accessPossible accessPredicted accessBlocked access
Simulated telemetry · demo data

Future attack timeline · modelled, not observed

How the blast radius could expand

Likelihood 100%

Now · Signing key already read

The grant has assumed the ledger service identity and read prod-secret-42. Three entities are confirmed in scope.

Sensitive assets in reach

1

Scenario likelihood

100%

Predictive analysis

What could happen next?

Estimate

Current situation

A 214-day-old OAuth grant belonging to Mira Chen was refreshed from an unfamiliar network and used to assume svc-ledger-prod, which then read the payments signing key. Three hops are confirmed by telemetry; everything past the key is modelled, not observed.

Most likely next step

Forge a signed request to the payments API to confirm the key is still accepted

72%

Estimated window · next 3–6 minutes

Alternative possible paths

Pivot east-west to ledger-primary over the open VPC tier

41%

7–15 minutes

Mint a second service identity for persistence before acting

27%

10–25 minutes

Stop after collection and idle to avoid detection

14%

indefinite

Potential business impact

Unauthorised transaction signing at production scale, with settlement reversal costs and a likely payment-scheme notification if forged signatures reach the ledger.

Potential data exposure

Up to 2.4M customer records and the identity documents held in customer-vault, triggering regulated breach reporting.

Confidence

87% confidence in this assessment

High confidence on the confirmed hops (direct CloudTrail and IdP evidence); moderate confidence on progression, which relies on behavioural priors from similar grant-abuse cases.

Supporting evidence

  • · 08:57 · Grant refresh from ASN not seen in 90 days of history
  • · 08:58 · First AssumeRole by oauth-grant-7f2c in 214 days
  • · 08:59 · prod-secret-42 read; prior read 41 days earlier
  • · 09:00 · 1.4k control-plane events under the assumed role
  • · Behavioural divergence 4.8σ from the identity's 30-day baseline

Predictions are modelled likelihoods from simulated telemetry. They are not confirmed outcomes and do not guarantee prevention.