Skip to content
Identity attack path management

See detected routes to Tier Zero, then fix the shared path.

Retrievy Identity X-Ray reconstructs evidence-backed Active Directory and supported Entra ID and Azure entitlement paths, shows the shortest detected route for each identity on the map, retains additional detected routes for drill-down within bounded limits, identifies shadow administrators, and ranks shared first-hop chokepoints. Every answer is scoped to the evidence the connected sources actually collected.

The privilege-list gap

An admin roster cannot show who can become an admin.

Direct membership is only one route to control. Nested groups, DCSync rights, AdminSDHolder control, cloud directory roles, ownership, managed identities, and Azure RBAC can place an ordinary identity a few evidence-backed relationships away from a crown jewel. Supported delegation findings add related risk context where that evidence is collected.

A graph also needs prioritization. Treating every route as an isolated finding sends teams after individual accounts while a shared group or entitlement keeps recreating the same exposure.

Identity X-Ray makes the shortest detected paths visible on the map, preserves additional detected routes in identity drill-down, and groups their immediate shared hops into chokepoints. It does not claim that incomplete source evidence proves no path exists.

Path analysis

Answer the four questions that turn a graph into a remediation plan.

The analysis combines reach, path evidence, grouped first-hop chokepoints, and later verification instead of stopping at a visually impressive graph.

Who can reach Tier Zero?

Identify ordinary users, computers, and supported cloud principals that have a detected route to Domain Admins, Global Administrator, or another configured crown-jewel target.

Through which path?

Draw the shortest evidence-backed route on the map and retain additional detected routes for identity drill-down, subject to depth, path-count, and walk-budget limits.

Which shared node comes first?

Group shortest-path chains by their immediate chokepoint and rank that first shared hop by the detected accounts behind it, while acknowledging that alternate routes can remain.

How is the correction verified?

Track the underlying findings and use later directory or entitlement evidence to prove that the relationship or risky state no longer appears.

What Retrievy examines

Collected relationships that can confer privilege.

The graph uses evidence-backed relationships. It does not invent an edge for a relationship the collector could not identify.

Check 01

Direct and nested group paths

Ordered Active Directory membership chains from an identity through intermediate groups into a Tier Zero target.

Check 02

Directory control rights

Supported DCSync, AdminSDHolder, dangerous ACL, and delegation findings where the evidence establishes privileged reach or related risk.

Check 03

Shadow administrators

Non-privileged users or computers with detected reach into the selected crown-jewel set, separated from direct by-design members.

Check 04

Entra directory roles and PIM

Supported standing and eligible Entra role relationships, including high-value directory-role reach where entitlement evidence is collected.

Check 05

Graph permissions and ownership

Supported Graph application permissions, application or service-principal ownership, and related credential-control paths from collected Entra evidence.

Check 06

Azure RBAC and managed identities

Supported Azure role assignments and managed-identity takeover relationships represented by the entitlement collector.

Check 07

Custom privileged zones

User-defined crown-jewel groups or accounts alongside built-in Tier Zero targets, with the same reach and shadow-admin analysis.

Check 08

Coverage state

Mapped, scanned-empty, and awaiting-source states distinguish observed absence from a source that has not supplied the necessary evidence.

Retrievy Identity X-Ray showing evidence-backed attack paths, shared chokepoints, and Tier Zero targets
Identity X-Ray attack paths and grouped chokepoints. Example product data is illustrative.
Product workflow

Build the evidence graph, prioritize shared paths, verify the change.

  1. 1 Detect

    Reconstruct collected relationships

    Identity findings contribute principals, ordered group chains, supported control rights, and Entra/Azure entitlement relationships to the graph.

  2. 2 Prioritize

    Rank reach and convergence

    Tier rank, shadow-admin status, shortest detected routes, risk flags, and shared chokepoints focus review on the relationships with the most leverage.

  3. 3 Remediate

    Fix the underlying edge

    Remove an unintended membership, right, ownership relationship, or entitlement through the organization’s normal identity change process, and address related delegation findings in their own evidence context.

  4. 4 Verify

    Rebuild from new evidence

    A later scan reconstructs the relationships again. The correction is verified when the relevant path and supporting finding no longer appear in collected evidence.

Illustrative example · fictional environment

Three identities enter the same legacy admin group

In this fictional lab, svc-deploy, alice.ops, and helpdesk-temp each enter Legacy Admin Bridge as the first hop in their shortest detected route to Domain Admins.

Detected sources
svc-deploy · alice.ops · helpdesk-temp
Shared node
Legacy Admin Bridge
Target
Domain Admins
Priority signal
Three grouped shortest paths share the same immediate chokepoint

Analysis

Reviewing the accounts one by one hides the leverage point. Grouping the detected shortest paths makes Legacy Admin Bridge the first relationship to investigate while identity drill-down preserves other detected routes that may also need remediation.

Remediation

The identity team validates the group’s remaining purpose, removes the unintended nesting, and separately reviews any alternate routes retained for the affected identities.

Verification

The next evidence collection rebuilds the graph. The grouped routes disappear when that collection no longer contains evidence of the relationship; another detected route remains visible rather than being treated as closed.

Why Identity X-Ray

A path-management view that stays honest about evidence.

Shortest path plus drill-down

The map stays readable with one shortest detected route per identity, while drill-down retains additional evidence-backed routes within bounded enumeration limits.

First-hop prioritization

Chokepoint ranking shows which immediate node is shared by the most grouped shortest paths without promising that one change removes unknown or alternate routes.

Fail-closed classification

Unknown principal types are not automatically labeled shadow administrators, reducing false confidence from ambiguous evidence.

Coverage-aware

The interface distinguishes mapped, scanned-empty, and awaiting sources so missing collection is not reported as a clean identity surface.

Related path questions

Investigations the graph is designed to support.

  • Which identities have detected reach into Tier Zero or a custom crown-jewel zone?
  • Which route is shortest, and which additional routes were also detected?
  • Which intermediate group or entitlement is shared by the most grouped paths?
  • Which shadow administrators are not direct, by-design privileged members?
  • Which Entra or Azure entitlement relationship creates high-value reach?
  • Did the next evidence collection actually remove the path?
Frequently asked

Identity Attack Path Management, answered.

1. Does Retrievy enumerate every possible identity attack path?
No tool can prove completeness beyond its source evidence. Identity X-Ray draws a shortest detected path per identity on the map and retains additional detected routes for drill-down within explicit depth, path-count, and walk-budget bounds.
2. What does “shadow administrator” mean in Retrievy?
It is a non-privileged user or computer that can reach the selected crown-jewel target through a detected relationship. Direct by-design members and unknown principal types are not automatically labeled shadow admins.
3. Which cloud identity paths are supported?
The current entitlement-path implementation supports collected Entra ID and Azure relationships such as directory roles, PIM, Graph permissions, ownership, managed identities, and Azure RBAC. This page does not claim equivalent path collection for every cloud provider.
4. Does fixing the top chokepoint remove every route?
It removes the grouped detected paths that depend on that node once the change is verified. Other detected, alternate, or previously uncollected routes may remain and must be reviewed separately.
5. Does exploring Identity X-Ray change the security score?
No. The graph is a read-only analysis lens over collected findings. Remediation and subsequent evidence can change finding state; exploring the map itself does not.
Next step

Find the relationship that puts the most identities at risk.

Map detected Tier Zero reach, inspect additional paths, prioritize shared chokepoints, and verify the correction with fresh evidence.