defender-cloud-attack-paths
Lists attack paths collected from Microsoft Defender for Cloud. Empty unless the Defender CSPM plan is enabled on the subscription.
defender-cloud-attack-paths [profile=VALUE] [subscription=VALUE]
- profile=VALUE
- Optional. e.g. mdc
- subscription=VALUE
- Optional. e.g. 00000000-0000-0000-0000-000000000000
Output fields
| Field | Type | Name | Description |
|---|---|---|---|
| profile | String | Profile | e.g. mdc |
| cloud_account | String | Subscription ID | e.g. 00000000-0000-0000-0000-000000000000 |
| attack_path_name | String | Attack path | e.g. Internet exposed VM with high severity vulnerabilities |
| attack_path_type | String | Path type | e.g. VmToDataStore |
| risk_categories | Array | Risk categories | e.g. ["DataExposure"] |
| entity_count | Integer | Resources on path | e.g. 4 |
| entry_point_entity | String | Entry point | Internal entity ID of where the path starts |
| target_entity | String | Target | Internal entity ID of what the path reaches |
| potential_impact | String | Potential impact | What an attacker reaches if the path is walked. e.g. Data exposure |
| description | String | Description | How the path connects, in Azure's words |
| remediation_steps | String | Remediation | Manual remediation steps reported by Azure |
| attack_path_id | String | Attack path ID | e.g. 33333333-3333-3333-3333-333333333333 |
| graph_component | Map | Path graph | The full node and edge list as JSON, for rendering the path |
| row_key | String | Row key | SHA-256 of the identity columns, stable across cycles. e.g. a1b2c3d4e5f6... |
| snapshot_id | String | Snapshot ID | The collection cycle that last wrote this row. e.g. 00000000-0000-0000-... |
| updated | Date | Collected at | e.g. 2026-10-05 00:34:15 |