* [Blog](https://www.paloaltonetworks.com/blog) * [Cloud Security](https://www.paloaltonetworks.com/blog/cloud-security/) * [Cloud Posture Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security-posture-management/) * Neutralize Cloud Threats,... # Neutralize Cloud Threats, Stop the Attack Path [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2Fcloud-security%2Fneutralize-cloud-threats-stop-the-attack-path%2F) [](https://twitter.com/share?text=Neutralize+Cloud+Threats%2C+Stop+the+Attack+Path&url=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2Fcloud-security%2Fneutralize-cloud-threats-stop-the-attack-path%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.paloaltonetworks.com%2Fblog%2Fcloud-security%2Fneutralize-cloud-threats-stop-the-attack-path%2F&title=Neutralize+Cloud+Threats%2C+Stop+the+Attack+Path&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://www.paloaltonetworks.com/blog/cloud-security/neutralize-cloud-threats-stop-the-attack-path/&ts=markdown) \[\](mailto:?subject=Neutralize Cloud Threats, Stop the Attack Path) Link copied By [Cody Queen](https://www.paloaltonetworks.com/blog/author/cody-queen/?ts=markdown "Posts by Cody Queen") and [Guy Giat](https://www.paloaltonetworks.com/blog/author/guy-giat/?ts=markdown "Posts by Guy Giat") Aug 11, 2026 5 minutes [Cloud Posture Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security-posture-management/?ts=markdown) [CNAPP](https://www.paloaltonetworks.com/blog/cloud-security/category/cnapp/?ts=markdown) [Uncategorized](https://www.paloaltonetworks.com/blog/category/uncategorized/?ts=markdown) If you work in cloud security, you already know the problem isn't a lack of alerts. It's the volume of them. On any given day, your security tool might show three dozen "critical" vulnerabilities, overly permissive IAM roles, and publicly exposed public ports. But the question is, do any of these isolated risks actually matter? Can an attacker use that public port to compromise an IAM role, hop to a workload, and ultimately reach your sensitive data? In February, we laid the groundwork to solve this by introducing the Cortex Cloud Security Graph, a visual and context rich mapping of your entire cloud environment, mapping out assets, relations, and findings. Now, to enhance our customers' defensive posture we are introducing Graph-Powered Attack Path Detection, to leverage our threat intelligence and rich risk posture data, into a highly prioritized graph that tells you most risky attack paths so you can cut off attackers before they can start. ## The "Multi-Hop" Blind Spot Traditional cloud security tools evaluate risks in silos. They look at a VM, see a vulnerability, and flag it. They look at an identity, see broad permissions, and flag it. But modern attackers don't think in silos. They think in small steps that can exploit every available vulnerability. They find a tiny, low-severity entry point and chain together multiple steps to reach their target. For a standard, rule based security tool, linking a four or five step chain across identities, code, data, workloads, and cloud resources is incredibly complex and computationally expensive. This is where graph technology shines. Graphs are native pathfinders. By treating your cloud as a web of interconnected nodes, Cortex Cloud doesn't just find individual flaws; it calculates the weight and relationship of every link and highlights the actual highway a threat actor would take to reach your crown jewels. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/07/word-image-364065-1.png) Figure 1. A Graph Powered Attack Path Detection in Cortex Cloud ## What Makes Cortex Cloud's Approach Different? We didn't want to build another standard attack path tool that simply draws lines between assets, we focused on four specific technical pillars to ensure the most accurate depiction of vulnerabilities possible. ### 1. Effective Permissions at the Resource Level An IAM policy itself may read one way, but when you factor in resource policies, permission boundaries, and service control policies (SCPs), what an identity can actually access may be [different.](http://different.do) Since Cortex Cloud calculates **effective permissions** down to the object level by analyzing the actual, net-effective access an identity has to a resource, we can drastically reduce false positives. ### 2. Built for Rapid Tuning The cloud changes fast, and so do attacker techniques. We built this system with rapid adaptability in mind. This is because our research teams can write, test, and deploy new graph-based logic instantly. In order to give our customers the best defense, we focused on agility to ensure protection from the latest threats. Before a new detection rule goes live, Cortex Cloud tests it across anonymized data to ensure it is highly accurate and doesn't flood you with noise. Once validated, the platform promotes directly to your engine. This allows us to constantly tune, update, and improve our logic behind the scenes without requiring platform downtime. ### 3. One Platform as the Backbone By normalizing data across assets, findings, configurations, identities, and network flows into a single data lake, Cortex Cloud creates a unified graph of your environment. Every security module contributes its domain expertise, and Attack Path Detection connects that context into a single, actionable view of risk. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/07/word-image-364065-2.png) Figure 2. A Graph Powered Attack Path Detection in Cortex Cloud ### 4. AI \& Data-Driven Accuracy Cloud environments are rapidly changing, often too fast for manual rules alone. Cortex Cloud leverages AI to continuously discover complex paths, evaluate their feasibility, and ensure the paths we highlight are actually exploitable. This feedback loop ensures the engine gets smarter and more contextualized to your specific environment over time. ## Threat Intel, Not Exaggerated Hype It's easy to generate countless potential attack paths. But security teams don't have time to investigate every theoretical scenario. They need to focus on the attack paths that reflect real-world adversary behavior and represent the greatest risk to the business. To keep our detections as realistic as possible for customers, we rely on two core resources: * **ADedicated Cortex Threat Research Team:** Our team of specialists who spend their days analyzing cloud exploits. These Specialists build the graph logic based on actual threat mechanics to ensure that paths that present real, structural danger are flagged. * **The Unit 42 Feed:** By working directly with Palo Alto Networks' Unit 42 threat intelligence team, we inject real-world incident response data into our rules. When Unit 42 sees a new multi-stage attack technique used in the wild, that intelligence is automatically translated directly into our attack path logic. **The Result:** You are blocking the exact routes real attackers are actively using right now, not chasing false positives. ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/07/word-image-364065-3.png) Figure 3. Remediating risk with automated playbooks and agents. ## Get Time Back, Fix What Matters Most The goal of Graph-Powered Attack Path Detection is to give you your time back. Instead of handing your engineering team a spreadsheet of 10,000 disconnected vulnerabilities, you can hand them a visual map of the three specific paths that lead directly to your production databases. By breaking just one link in that chain, often a simple configuration tweak or credential rotation, you can neutralize the entire threat path. It's time to stop treating cloud security like a checklist of individual flaws. By looking at your security posture through the lens of a graph, you can finally see your cloud the way attackers do, and shut the door before they even arrive. To learn more about this new innovation, request a [personalized demo](https://www.paloaltonetworks.com/cortex/cloud/demo?utm_source=google-jg-amer-prisma_cloud-scpc-cstp&utm_medium=paid_search&utm_campaign=google-prisma_cloud-cloud_st_portfolio-amer-multi-lead_gen-en-brand&utm_content=701Ki000000LqJaIAK&utm_term=cortex%20cloud&cq_plac=&cq_net=g&gclsrc=aw.ds&gad_source=1&gad_campaignid=23524071560&gbraid=0AAAAADHVeKkULSgzp3tCyz-9qYDWciFs8&gclid=CjwKCAjw1IHTBhAaEiwA4AYNFiV3CxV5F2uE5e6aVEoj4Au4BSUP5_L4HVLSdWKn-Fbja9N85Q6_JhoC7AIQAvD_BwE&ts=markdown). *** ** * ** *** ## Related Blogs ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [AppSec](https://www.paloaltonetworks.com/blog/cloud-security/category/appsec/?ts=markdown), [Cloud Detection and Response](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-detection-and-response/?ts=markdown), [Cloud Posture Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security-posture-management/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security/?ts=markdown), [CNAPP](https://www.paloaltonetworks.com/blog/cloud-security/category/cnapp/?ts=markdown) [#### Introducing Cortex Cloud 2.2: Defend Against Frontier AI Threats](https://www.paloaltonetworks.com/blog/cloud-security/cortex-cloud-2-2/) ### [Cloud Posture Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security-posture-management/?ts=markdown), [Cloud Runtime Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-runtime-security/?ts=markdown), [Cloud Security](https://www.paloaltonetworks.com/blog/category/cloud-security/?ts=markdown), [CNAPP](https://www.paloaltonetworks.com/blog/cloud-security/category/cnapp/?ts=markdown) [#### Your Riskiest Kubernetes Workload Is Hiding in Plain Sight](https://www.paloaltonetworks.com/blog/cloud-security/your-riskiest-kubernetes-workload-is-hiding-in-plain-sight/) ### [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cloud ASM](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-asm/?ts=markdown), [Cloud Posture Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security-posture-management/?ts=markdown), [CNAPP](https://www.paloaltonetworks.com/blog/cloud-security/category/cnapp/?ts=markdown), [CSPM](https://www.paloaltonetworks.com/blog/cloud-security/category/cspm/?ts=markdown) [#### Cloud Attack Surface Management: See What Other CNAPPs Miss](https://www.paloaltonetworks.com/blog/cloud-security/closing-cloud-gap-attack-surface-management/) ### [Cloud Posture Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security-posture-management/?ts=markdown), [Uncategorized](https://www.paloaltonetworks.com/blog/category/uncategorized/?ts=markdown) [#### Enhancing Threat Intelligence in Isolated Environments](https://www.paloaltonetworks.com/blog/cloud-security/threat-intelligence-isolated-environments/) ### [Cloud Posture Security](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-security-posture-management/?ts=markdown), [Cloud Workload Protection Platform](https://www.paloaltonetworks.com/blog/cloud-security/category/cloud-workload-protection-platform/?ts=markdown), [Uncategorized](https://www.paloaltonetworks.com/blog/category/uncategorized/?ts=markdown) [#### How to Manage Kubernetes Pod Security Policy Deprecation](https://www.paloaltonetworks.com/blog/cloud-security/kubernetes-psp-deprecation/) ### [Cloud Delivered Security Services](https://www.paloaltonetworks.com/blog/network-security/category/cloud-delivered-security-services/?ts=markdown), [Cloud NGFW](https://www.paloaltonetworks.com/blog/network-security/category/cloud-ngfw/?ts=markdown), [Uncategorized](https://www.paloaltonetworks.com/blog/category/uncategorized/?ts=markdown) [#### Palo Alto Networks Collaborates with Google Cloud to Redefine Protection Against AI-Generated Malware](https://www.paloaltonetworks.com/blog/network-security/palo-alto-networks-google-cloud-ai-malware-protection/) ### Subscribe to Cloud Security Blogs! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://www.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/prisma/prisma-ai-runtime-security?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess?ts=markdown) * [Incident Response](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) * [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform?ts=markdown) * [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![PAN logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language