What can an attacker reach now?
The significance of a permission is not its name. It is the route that permission may open.
From configuration to reachability.
Attack paths are first-class objects with evidence, confidence, first observation, and temporal state. A changed trust relationship or permission can open a path that was not present in the previous genome state.
In the synthetic AWS/GitHub slice, deployment trust and IAM policy scope connect a repository to a potential production privilege-escalation route. Effective denies and other controls matter; the investigator should attempt to disprove reachability before treating a hypothesis as confirmed.
Recalculate after the response.
A ticket marked complete is not proof that a route disappeared. Authoritative sensor data must show the relevant change, and attack-path analysis must confirm that the path is no longer active.
The historical path remains useful evidence. If the same trust or permission pattern returns, immune memory can connect it to the earlier response and the organisation's recurring weakness.