01 / Attack path
How the boundary is crossed
A test agent is decommissioned but its cloud role remains active and later gets reused by an unmanaged process.
- 01Lower-trust input
- 02Attempted instruction
- 03Protected action
- 04Enforced decision
02 / Containment
Where bounded authority limits the effect
Tie grants to accountable owner and task lifecycle, recertify access and disable unused grants when ownership disappears.
03 / Failure and evidence
The attacker’s opportunity and the defender’s record
Credential validity outlives the organizational authority that justified it.
Record owner change, last use, recertification decision, disabled grant and attempted later use.
04 / Canonical scope
Why this reference stands alone
Long-lived credentials focuses secret lifetime; this threat focuses missing authority ownership.
Protocol or attack trace
Owner-loss lifecycle
Test agent is retired, but cloud role remains and is later used by an unmanaged process.
On owner removal, suspend grant; later role use must be denied pending recertification.
Primary references