If you work in cloud security, you already know the problem isn't a lack of alerts. It’s the volume of them. On any given day, your security tool might show three dozen "critical" vulnerabilities, overly permissive IAM roles, and publicly exposed public ports.
But the question is, do any of these isolated risks actually matter? Can an attacker use that public port to compromise an IAM role, hop to a workload, and ultimately reach your sensitive data?
In February, we laid the groundwork to solve this by introducing the Cortex Cloud Security Graph, a visual and context rich mapping of your entire cloud environment, mapping out assets, relations, and findings. Now, to enhance our customers' defensive posture we are introducing Graph-Powered Attack Path Detection, to leverage our threat intelligence and rich risk posture data, into a highly prioritized graph that tells you most risky attack paths so you can cut off attackers before they can start.
The "Multi-Hop" Blind Spot
Traditional cloud security tools evaluate risks in silos. They look at a VM, see a vulnerability, and flag it. They look at an identity, see broad permissions, and flag it. But modern attackers don't think in silos. They think in small steps that can exploit every available vulnerability. They find a tiny, low-severity entry point and chain together multiple steps to reach their target. For a standard, rule based security tool, linking a four or five step chain across identities, code, data, workloads, and cloud resources is incredibly complex and computationally expensive.
This is where graph technology shines. Graphs are native pathfinders. By treating your cloud as a web of interconnected nodes, Cortex Cloud doesn’t just find individual flaws; it calculates the weight and relationship of every link and highlights the actual highway a threat actor would take to reach your crown jewels.

What Makes Cortex Cloud’s Approach Different?
We didn't want to build another standard attack path tool that simply draws lines between assets, we focused on four specific technical pillars to ensure the most accurate depiction of vulnerabilities possible.
1. Effective Permissions at the Resource Level
An IAM policy itself may read one way, but when you factor in resource policies, permission boundaries, and service control policies (SCPs), what an identity can actually access may be different.
Since Cortex Cloud calculates effective permissions down to the object level by analyzing the actual, net-effective access an identity has to a resource, we can drastically reduce false positives.
2. Built for Rapid Tuning
The cloud changes fast, and so do attacker techniques. We built this system with rapid adaptability in mind. This is because our research teams can write, test, and deploy new graph-based logic instantly. In order to give our customers the best defense, we focused on agility to ensure protection from the latest threats.
Before a new detection rule goes live, Cortex Cloud tests it across anonymized data to ensure it is highly accurate and doesn't flood you with noise. Once validated, the platform promotes directly to your engine. This allows us to constantly tune, update, and improve our logic behind the scenes without requiring platform downtime.
3. One Platform as the Backbone
By normalizing data across assets, findings, configurations, identities, and network flows into a single data lake, Cortex Cloud creates a unified graph of your environment. Every security module contributes its domain expertise, and Attack Path Detection connects that context into a single, actionable view of risk.

4. AI & Data-Driven Accuracy
Cloud environments are rapidly changing, often too fast for manual rules alone. Cortex Cloud leverages AI to continuously discover complex paths, evaluate their feasibility, and ensure the paths we highlight are actually exploitable. This feedback loop ensures the engine gets smarter and more contextualized to your specific environment over time.
Threat Intel, Not Exaggerated Hype
It's easy to generate countless potential attack paths. But security teams don't have time to investigate every theoretical scenario. They need to focus on the attack paths that reflect real-world adversary behavior and represent the greatest risk to the business.
To keep our detections as realistic as possible for customers, we rely on two core resources:
- ADedicated Cortex Threat Research Team: Our team of specialists who spend their days analyzing cloud exploits. These Specialists build the graph logic based on actual threat mechanics to ensure that paths that present real, structural danger are flagged.
- The Unit 42 Feed: By working directly with Palo Alto Networks’ Unit 42 threat intelligence team, we inject real-world incident response data into our rules. When Unit 42 sees a new multi-stage attack technique used in the wild, that intelligence is automatically translated directly into our attack path logic.
The Result: You are blocking the exact routes real attackers are actively using right now, not chasing false positives.

Get Time Back, Fix What Matters Most
The goal of Graph-Powered Attack Path Detection is to give you your time back.
Instead of handing your engineering team a spreadsheet of 10,000 disconnected vulnerabilities, you can hand them a visual map of the three specific paths that lead directly to your production databases. By breaking just one link in that chain, often a simple configuration tweak or credential rotation, you can neutralize the entire threat path.
It’s time to stop treating cloud security like a checklist of individual flaws. By looking at your security posture through the lens of a graph, you can finally see your cloud the way attackers do, and shut the door before they even arrive.
To learn more about this new innovation, request a personalized demo.