Join our Newsletter — 33% off our NHI Course
Home Glossary Threats, Abuse & Incident Response Cross-door attack
Threats, Abuse & Incident Response

Cross-door attack

← Back to Glossary
By NHI Mgmt Group Updated August 18, 2026 Domain: Threats, Abuse & Incident Response

An attack pattern where malicious behaviour enters through one governance layer and exits through another, so neither control plane sees the full sequence. The risk is greatest when identity, policy, and telemetry are split across separate products or teams.

Expanded Definition

Cross-door attack describes a path in which malicious activity crosses from one governance boundary to another, so the initial access point and the eventual impact are managed by different teams, products, or control planes. In NHI operations, that often means an action begins in identity, policy, or orchestration, then completes in logging, secrets, or runtime execution without any single system seeing the full chain. This pattern is especially relevant where service accounts, API keys, and agent permissions are fragmented across cloud, CI/CD, and AI tooling. Industry usage is still evolving, but the practical meaning is clear: the attacker relies on organisational seams rather than technical novelty. That is why NHI Management Group treats cross-door attacks as a governance failure as much as a threat pattern, and why a standards anchor such as NIST SP 800-53 Rev 5 Security and Privacy Controls matters when mapping responsibilities across domains. The most common misapplication is assuming separate alerts from separate tools equal coverage, which occurs when identity and telemetry are not correlated end to end.

Examples and Use Cases

Implementing detection and response for cross-door attack paths often introduces correlation overhead, requiring organisations to weigh broader visibility against added integration and tuning effort.

  • An AI agent receives a valid tool token through one workflow, then uses that access to query a separate system where logging is incomplete, leaving no unified incident trail. That pattern aligns with the kind of multi-stage abuse seen in the 52 NHI Breaches Analysis and with attacker tradecraft catalogued in the MITRE ATT&CK Enterprise Matrix.
  • A CI/CD secret is read from a pipeline vault, but the real abuse occurs later when the credential is reused in a cloud control plane that belongs to a different operations team.
  • A policy engine approves an action for one service account, while the actual execution happens under a different workload identity that bypasses the original approval context.
  • An API key is rotated in a secrets manager, yet downstream caches, containers, or agent memory still hold the old credential, allowing the sequence to continue across control boundaries.
  • Telemetry shows a deny event in one product and a successful action in another, but the two events are never stitched together during investigation.

These cases are easier to spot when practitioners compare control boundaries against the end-to-end patterns described in OWASP NHI Top 10 and threat reporting such as the Anthropic report on AI-orchestrated cyber espionage.

Why It Matters in NHI Security

Cross-door attack risk is dangerous because NHI environments already suffer from fragmented ownership, excessive privilege, and weak visibility. NHI Management Group’s Ultimate Guide to NHIs notes that only 5.7% of organisations have full visibility into their service accounts, which makes cross-boundary abuse hard to detect and even harder to contain. The issue is not just the initial compromise of a secret or token; it is the handoff between systems where enforcement assumptions change. When identity, secrets, policy, and logging are owned separately, attackers can assemble a complete intrusion from partial actions that each look benign in isolation. That is why governance teams should pair runtime telemetry with secrets hygiene, access reviews, and workload identity mapping, using resources such as Ultimate Guide to NHIs — Why NHI Security Matters Now and CISA cyber threat advisories to keep detection and response aligned. Organisations typically encounter the full cost of a cross-door attack only after an incident review reveals that no single team owned the complete attack path, at which point the term becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02Cross-door attacks often begin with secret misuse and boundary hopping.
OWASP Agentic AI Top 10A-04Agent tool-use can bridge separate governance layers and hide the full chain.
NIST CSF 2.0DE.CM-1Cross-door activity evades isolated monitoring unless events are correlated.
NIST Zero Trust (SP 800-207)SC-7Zero trust requires policy enforcement across boundaries, not inside one product.
NIST SP 800-63Identity assurance principles help separate authentic access from chained misuse.

Validate workload identity strength and re-authentication points along the full request path.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org