After initial access, the tester must enumerate the compromised environment to identify pivot routes, sensitive data, and additional vulnerabilities reachable from the new vantage point.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.