They had gone directly to the service accounts with the broadest permissions. They had used those accounts to access the data stores that held the most valuable data. They had avoided the systems that would have triggered the detection rules the security team had configured. They knew more about the organization's access landscape than the identity governance team had documented. The attacker's map was more complete than the governance program's.
How Attackers Learn Your Access Model
Attackers who gain initial access to an enterprise environment do not typically move immediately to their objective. They conduct reconnaissance — mapping the access landscape to identify the paths of least resistance to the data or systems they seek. This reconnaissance uses the same tools and queries that legitimate system administrators use: directory queries that enumerate group memberships, permission checks that reveal what access an account has, network scans that identify accessible systems and services.
The reconnaissance produces a map of the access model from the attacker's current position. It reveals which accounts have elevated permissions, which data stores are accessible from which accounts, which systems trust which identities, and which paths through the environment are monitored versus unmonitored. An attacker who conducts thorough reconnaissance before moving laterally knows more about the practical access landscape than most identity governance programs document — because governance programs document the intended access model, not the operational access reality that the attacker discovers by probing.
The intended access model is what the policy says should exist. The operational access reality is what an authenticated user can actually do. The attacker discovers the second. The governance program typically maps the first. The gap between them is the attack surface that governance does not see.
The Knowledge the Attacker Had That the Team Did Not
The Service Account With Undocumented Permissions
Service accounts accumulate permissions over time through the same process as human accounts: provisioning for specific needs without systematic deprovisioning when the need passes. A service account created for a data integration three years ago may have retained permissions across multiple systems as the integration expanded, was modified, or was partially decommissioned. The service account may no longer be actively used by any current business process but may still have broad access that was granted when the integration was active.
The identity governance program's service account inventory may show the account as active because it has valid credentials and has been accessed recently — by the attacker using it for lateral movement. The governance team does not know the account's current permissions are broader than any legitimate use case requires. The attacker knows, because they queried the account's permissions during reconnaissance.
The Trust Relationship Between Systems
Enterprise environments contain trust relationships between systems that are not always represented in access governance documentation: Kerberos delegation configurations that allow one system to authenticate on behalf of another, API keys that grant cross-system access, SAML configurations that extend trust across domains. These trust relationships are access paths. An attacker who discovers a trust relationship that allows a compromised system to authenticate to a higher-value system has found a lateral movement path that the governance team may not have mapped.
The Path Through the Monitoring Blind Spot
Security monitoring in most environments has gaps: systems whose logs are not ingested into the SIEM, authentication events that are not captured, API calls that are not logged, network paths that are not monitored. An attacker conducting reconnaissance can identify these gaps by observing what triggers alerts and what does not — essentially discovering the monitoring perimeter by probing it. The attacker then routes their movement through the unmonitored paths. The governance team configured monitoring for the systems they knew needed to be monitored. The gaps are in the systems they did not know to monitor.
Closing the Visibility Gap
The governance program that wants to see its access landscape the way an attacker sees it needs to conduct adversarial access mapping: systematically probing the environment from the perspective of various compromised accounts to discover what access each account actually has, what systems it can reach, and what paths exist through the environment that the governance documentation does not reflect.
This is the value that penetration testing and red team exercises provide when conducted with access to the identity governance program's documentation: the exercise can directly compare what the documentation says the access model should be with what a probing attacker can actually do. The gaps between the documented model and the discovered reality are the governance gaps that the exercise produces.
The specific findings that matter most are accounts with access significantly broader than their documented purpose, trust relationships that create lateral movement paths not represented in the governance model, and monitoring gaps that correspond to the lateral movement paths an attacker is most likely to use. These findings, addressed systematically, close the gap between the access model the governance team documented and the access reality the attacker would discover.
Map your access model from the attacker's perspective. The gaps between that map and your governance documentation are the gaps the attacker will exploit.
Conduct adversarial access mapping. Compare what an attacker can discover through reconnaissance to what your governance program documents. Close the gaps before the attacker finds them.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
