Microsoft Defender for Cloud

Download 0
Last updated Oct 5, 2026

defender-cloud-attack-paths

Lists attack paths collected from Microsoft Defender for Cloud. Empty unless the Defender CSPM plan is enabled on the subscription.

defender-cloud-attack-paths [profile=VALUE] [subscription=VALUE]
profile=VALUE
Optional. e.g. mdc
subscription=VALUE
Optional. e.g. 00000000-0000-0000-0000-000000000000

Output fields

FieldTypeNameDescription
profileStringProfilee.g. mdc
cloud_accountStringSubscription IDe.g. 00000000-0000-0000-0000-000000000000
attack_path_nameStringAttack pathe.g. Internet exposed VM with high severity vulnerabilities
attack_path_typeStringPath typee.g. VmToDataStore
risk_categoriesArrayRisk categoriese.g. ["DataExposure"]
entity_countIntegerResources on pathe.g. 4
entry_point_entityStringEntry pointInternal entity ID of where the path starts
target_entityStringTargetInternal entity ID of what the path reaches
potential_impactStringPotential impactWhat an attacker reaches if the path is walked. e.g. Data exposure
descriptionStringDescriptionHow the path connects, in Azure's words
remediation_stepsStringRemediationManual remediation steps reported by Azure
attack_path_idStringAttack path IDe.g. 33333333-3333-3333-3333-333333333333
graph_componentMapPath graphThe full node and edge list as JSON, for rendering the path
row_keyStringRow keySHA-256 of the identity columns, stable across cycles. e.g. a1b2c3d4e5f6...
snapshot_idStringSnapshot IDThe collection cycle that last wrote this row. e.g. 00000000-0000-0000-...
updatedDateCollected ate.g. 2026-10-05 00:34:15