Find the attack paths that turn weaknesses into business risk.
A security exposure workbench that resolves assets and identities into a graph, identifies exploitable paths to critical systems, and turns them into owned remediation actions.
Scale and interface figures on this page are illustrative.
Risk is a path, not a finding count.
The interface is designed around reachability and shared choke points so teams can remove meaningful attack paths instead of chasing severity queues.
Fragmented context
CVSS and raw finding volume did not explain whether a weakness could actually contribute to compromise of a critical asset.
Decision logic
Cloud resources, identities, entitlements, endpoints, and vulnerabilities needed a shared graph with evidence lineage.
Operational handoff
Infrastructure owners needed fixable actions with blast radius and verification—not security screenshots copied into tickets.
Model relationships before dashboards.
The product treats assets, identities, permissions, findings, and criticality as a graph first.
Exposure graph
Cross-workload relationships between identities, endpoints, cloud resources, secrets and vulnerabilities.
Attack paths
Entry point → technique → privilege → lateral movement → critical asset, with evidence per edge.
Choke points
Shared weaknesses or permissions whose remediation breaks multiple attack paths.
Remediation
Owner, SLA, affected paths, recommended fix, ticket sync and verification state.
Exceptions
Risk acceptance with approver, compensating control, expiry and re-review.
Remediation should break paths.
Actions are prioritized by what they disconnect and verified against fresh evidence.
Representative application states.
Representative application states from the product. Figures shown on screen are illustrative.
Attack path explorer
Internet → finance-prod
reach(internet) → tier0 where exploitable
Shortest firstof 14
| Route | Hops | Target |
|---|---|---|
| checkout-web → wi-payments → svc-finance-etl | 4 | finance-prod-db-02 |
| checkout-web → wi-payments → svc-finance-etl | 4 | payments-ledger |
| checkout-web → wi-payments → vault-reader | 4 | finance-prod-db-02 |
| checkout-web → wi-payments → vault-reader | 4 | payments-ledger |
| edge-gw-03 → wi-payments → svc-finance-etl | 4 | finance-prod-db-02 |
Dashed rings mark nodes on 50% or more of these paths. Evidence 11 minutes old.
Priority actions
Break the most paths first
41 open actions
| Action | Paths | Owner | SLA |
|---|---|---|---|
| Rotate exposed deploy token | −18 | PL Platform | 3d left |
| Constrain svc-finance-etl role | −11 | FE Finance Eng | 2d over |
| Patch edge-gw-03 | −9 | IN Infra | 5d left |
| Restrict wi-payments secret read | −8 | PA Payments | 1d left |
| Remove standing admin from ci-deploy | −7 | PL Platform | 9d left |
| Isolate node-pool-2 privileged pods | −6 | IN Infra | 4d over |
Top 6: 59 paths. 35 more actions remove the remaining 20.
Diminishing returns paths removed
Exposure posture
Quarter-to-date
Exposure posture
Critical attack paths open weekly
By domain
- Identity46%
- Network22%
- Vulnerabilities19%
- Data13%
What changed
- Identity paths remain dominant in production.
- Two overdue actions account for 21 reachable paths.
- Exception EX-442 expires in 6 days.
- Crown jewels exposed
- 4
- Accepted risk
- 9
- Median age
- 8.2 days
Critical asset detail
finance-prod-db-02
finance-prod-db-02
Findings
Compensating controls
- Paths in
- 18
- Environment
- Production
- Data class
- Financial records
Risk acceptance
EX-442
EX-442 · Legacy gateway patch
Justification
Vendor compatibility blocks the patch on edge-gw-03 until the next maintenance release.
- Reason
- Vendor compatibility
- Approver
- VP Infrastructure
- Paths covered
- 4
- Review
- In 6 days
Conditions
The exposure stays on record; accepting risk never deletes it.
Failure states are part of the product model.
The cases below are intentionally modeled because real operating software is defined by what happens when data, people, or dependencies do not line up.
Two scanners disagree
Preserve source evidence, resolve to one canonical asset, and expose the conflict instead of averaging severity.
Accepted risk expires
Automatically re-open the exposure for review; acceptance never deletes graph edges.
Fix ticket closes without evidence
Keep remediation in verification until a fresh ingest proves the relevant path is broken.
The data model behind the interface.
The interface follows the domain relationships and rules below.