Generate an Attack Path Query with the Attack Path Query Builder
Required User Role: Basic, Scan Operator, Standard, Scan Manager, Administrator, or Custom Role
You can use the Attack Path Query Builder to generate an attack path from one asset to another. You can create a query from a specific node or asset origin, and then specify the target to which you want to compare.
Tip: To generate an attack path using a built-in query, see Generate an Attack Path with a Built-in Query.
To generate a custom attack path query:
-
Access the Top Attack Paths tab.
-
In the Custom Queries section, click Attack Path Query Builder.
The Query Builder pane appears.
-
In the Source box, click the
button.The source options appear.
-
For each source you want to include in the query:
-
Select the radio button next to the type of origin you want to use for the query:
-
Asset type — Generate a query based on a certain type of asset.
-
Specific asset — Generate a query based on a specific asset.
-
-
In the text box, type the asset type or specific node/asset you want to use for the query.
-
(Optional) To apply filters to the origin:
-
Click the
button.The Filters window appears.
-
In the Parameter drop-down, select the parameter by which you want to filter the origin.
-
In the Operator drop-down, select the operator to apply to the parameter.
-
In the text box, type or select the value or values you want to use for the filter.
Note: The values you can use differ depending on the parameter you selected.
-
Click Apply and search.
Tenable Exposure Management applies the filter to the origin.
-
-
-
In the Target section, click the
button.The target options appear.
-
For each target you want to include in the query:
-
Select the radio button next to the type of target you want to use for the query:
-
Asset type — Generate a query based on a certain type of asset.
-
Specific asset — Generate a query based on a specific asset.
-
-
In the text box, type the asset type or specific node/asset you want to use for the query.
-
(Optional) To apply filters to the target:
-
Click the
button.The Filters window appears.
-
In the Parameter drop-down, select the parameter by which you want to filter the target.
-
In the Operator drop-down, select the operator to apply to the parameter.
-
In the text box, type or select the value or values you want to use for the filter.
Note: The values you can use differ depending on the parameter you selected.
-
Click Apply and search.
Tenable Exposure Management applies the filter to the target.
-
-
- (Optional) Click
Swap to swap between Source and Target assets. -
In the Attack Technique section, click the
button. A text box in which you can search for and select techniques appears.
-
In the Technique box, type or select a specific attack technique.
Tenable Exposure Management updates the list based on the search criteria. For more information on supported techniques, see Supported Attack Path Techniques.
-
(Optional) Click
Add a Technique to add additional techniques.Note: Tenable Exposure Management enables
Add a Technique only after you add an initial technique.Caution: You must add techniques to your query in the order in which they appear in an attack path. Tenable Exposure Management does not provide query results for incorrectly ordered techniques. -
Click Search
.Tenable Exposure Management returns any attack paths that match the query you created. For more information on interacting with the data, see Interact with Attack Path Query Data.
-
(Optional) To reset the query pane, at the top of the pane, click the
button.Tenable Exposure Management resets the selections within the pane.
(Optional) Save your Query as a Preset/Bookmark
Required User Role: Standard, Scan Manager, Administrator, or Custom Role
Once you've built your custom query, you can save it as a preset, where you can then access it as a bookmark when creating new built-in attack path queries.
To save your query as a preset:
-
At the top of the pane, click the
button.The Save as preset window appears.
-
In the Name of preset text box, type a name for the query.
-
In the Description of preset text box, type a description of the query.
-
Click Save preset
.Tenable Exposure Management saves the query as a preset. You can access your saved queries in the Bookmarks section of the Query Library.
Tip: When you save a query as a preset, you can use it as a filter on the Top Attack Paths tab.
What to Do Next
Interact with the attack path data provided by the query.
