Esc
Access Modeling
Definition
Access modeling captures and records the access permissions granted to identities (e.g., administrators, users, groups, systems) and optionally includes details on how these identities are stored, managed, and shared across systems.
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Related Offensive Techniques:
These mappings are inferred, experimental, and will improve as the
knowledge graph grows.
These offensive techniques are determined related because of the way this defensive technique,, , , and .
Persistence
Valid Accounts
Create Account
Account Manipulation
Modify Authentication Process
Privilege Escalation
Account Manipulation
Valid Accounts
Abuse Elevation Control Mechanism
Domain or Tenant Policy Modification
Access Token Manipulation
Stealth
Valid Accounts
Access Token Manipulation
Defense Impairment
Domain or Tenant Policy Modification
Modify Authentication Process
File and Directory Permissions Modification
Impact
Account Access Removal
Credential Access
Unsecured Credentials
Modify Authentication Process
References
All
Specification
The following references were used to develop the Access Modeling knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)
RFC7642: System for Cross-domain Identity Management: Definitions, Overview, Concepts, and Requirements
Reference Type: Specification Organization: IETF Author: K. LI, B. Khasnabish, A. Nadalin, Z. Zeltsan