Generate an Attack Path Query with the Attack Path Query Builder
You can use the Attack Path Query Builder to generate an attack path from one asset to another. You can create a query from a specific node or asset origin, and then specify the target to which you want to compare.
Tip: To generate an attack path using a built-in query, see Generate an Attack Path with a Built-in Query.
To generate a custom attack path query:
-
Access the Top Attack Paths tab.
-
In the Custom Queries section, click Attack Path Query Builder.
The Query Builder pane appears.
-
In the Source box, click the
button.
The source options appear.
-
For each source you want to include in the query:
-
Select the radio button next to the type of origin you want to use for the query:
-
Asset type — Generate a query based on a certain type of asset.
-
Specific asset — Generate a query based on a specific asset.
-
-
In the text box, type the asset type or specific node/asset you want to use for the query.
-
(Optional) To apply filters to the origin:
-
Click the
button.
The Filters window appears.
-
In the Parameter drop-down, select the parameter by which you want to filter the origin.
-
In the Operator drop-down, select the operator to apply to the parameter.
-
In the text box, type or select the value or values you want to use for the filter.
Note: The values you can use differ depending on the parameter you selected.
-
Click Apply and search.
Tenable Exposure Management applies the filter to the origin.
-
-
-
In the Target section, click the
button.
The target options appear.
-
For each target you want to include in the query:
-
Select the radio button next to the type of target you want to use for the query:
-
Asset type — Generate a query based on a certain type of asset.
-
Specific asset — Generate a query based on a specific asset.
-
-
In the text box, type the asset type or specific node/asset you want to use for the query.
-
(Optional) To apply filters to the target:
-
Click the
button.
The Filters window appears.
-
In the Parameter drop-down, select the parameter by which you want to filter the target.
-
In the Operator drop-down, select the operator to apply to the parameter.
-
In the text box, type or select the value or values you want to use for the filter.
Note: The values you can use differ depending on the parameter you selected.
-
Click Apply and search.
Tenable Exposure Management applies the filter to the target.
-
-
- (Optional) Click
Swap to swap between Source and Target assets.
-
In the Attack Technique section, click the
button.
A text box in which you can search for and select techniques appears.
-
In the Technique box, type or select a specific attack technique.
Tenable Exposure Management updates the list based on the search criteria. For more information on supported techniques, see Supported Attack Path Techniques.
-
(Optional) Click
Add a Technique to add additional techniques.
Note: Tenable Exposure Management enablesAdd a Technique only after you add an initial technique.
Caution: You must add techniques to your query in the order in which they appear in an attack path. Tenable Exposure Management does not provide query results for incorrectly ordered techniques. -
Click Search
.
Tenable Exposure Management returns any attack paths that match the query you created. For more information on interacting with the data, see Interact with Attack Path Query Data.
-
(Optional) To reset the query pane, at the top of the pane, click the
button.
Tenable Exposure Management resets the selections within the pane.
-
At the top of the pane, click the
button.
The Save as preset window appears.
-
In the Name of preset text box, type a name for the query.
-
In the Description of preset text box, type a description of the query.
-
Click Save preset
.
Tenable Exposure Management saves the query as a preset. You can access your saved queries in the Bookmarks section of the Query Library.
(Optional) Save your Query as a Preset/Bookmark
Once you've built your custom query, you can save it as a preset, where you can then access it as a bookmark when creating new built-in attack path queries.
To save your query as a preset:
What to do next:
Interact with the attack path data provided by the query.