wallarm
Search Wallarm ⌘K Tenant Name 12345

Infrastructure discovery

Building topology…
grouping 339 assets across 9 regions
All accounts 9 regions 339 assets
prod-account
🇺🇸 us-east-1
23/120
assets
126
🇺🇸 us-west-2
23/56
assets
98
🇩🇪 eu-central-1
12/42
assets
87
🇮🇪 eu-west-1
67
🇮🇳 ap-south-1
8/12
assets
18
🇸🇬 ap-southeast-1
18
🇨🇦 ca-central-1
10
🇧🇷 sa-east-1
2/8
assets
4
🇸🇪 eu-north-1
6
🇺🇸 us-east-1
prod-main-vpc
18/72
assets
98
prod-payments-vpc
5/22
assets
28
staging-vpc
26
prod-main-vpc · vpc-0a1b2c3d subnet-0aaa1111pub1a · public subnet-0bbb1111priv1a · private subnet-0bbb2222priv1b · private igw-0a1b2c3d internet gateway 1 i-0abc…789e bastion · SSH open to 0.0.0.0/0 i-0abc…789c · public IP i-0abc…789a app · shared SG eni-0web1aaaa1111 i-0abc…789b app · shared SG eni-0web2bbbb2222 app/prod-web-alb :80 no HTTPS redirect http:80 https:443 prod-web-tg target group 1 prod-cluster EKS · public API endpoint sg-0web11111111 prod-workers node group prod-webhook-handler Lambda · shares sg-0app… sg-0app11111111 shared security group net/prod-internal-nlb internal prod-db-sg database perimeter
Region border = severity clean → critical · size = asset count
Overview · nothing selected
Your cloud
339 assets · 9 regions · 1 account · scanned 12s ago

Riskiest areas

us-east-1
120 assets · 126 findings · 23 at risk
us-west-2
56 assets · 98 findings · 23 at risk
eu-central-1
42 assets · 87 findings · 12 at risk
ap-south-1
12 assets · 18 findings · 8 at risk

Getting around

Click us-east-1 to zoom into its VPCs. Switch to Attack paths to trace how exposure reaches sensitive data.
Region · zoomed in
us-east-1
120 assets · 3 VPCs · 126 findings · 23 at risk

Riskiest VPCs

prod-main-vpc
72 assets · 98 findings · 18 at risk
prod-payments-vpc
22 assets · 28 findings · 5 at risk
staging-vpc
26 assets · clean

Getting around

Click prod-main-vpc to see its subnets and assets. Esc or − zooms back out.
VPC · zoomed in
prod-main-vpc
vpc-0a1b2c3d4e5f6a7b8
72 assets · 3 subnets · 98 findings

Riskiest assets

i-0abc…789e · bastion
sg-public-ssh · CRITICAL · public subnet
prod-cluster
eks-public-endpoint · CRITICAL
prod-webhook-handler
shares sg-0app… with app fleet · HIGH
prod-db-sg
database perimeter · reachable from app tier

Two criticals chained

The public bastion reaches prod-cluster, which carries its own CRITICAL. Open the potential attack path →
i-0abc1234def56789e
AccountprodServiceEC2 Regionus-east-1Typeinstance Discovered1 week agoRolebastion
Subnetsubnet-0aaa1111pub1a · public ARNarn:aws:ec2:us-east-1:123456789012:instance/i-0abc1234def56789e Resource IDi-0abc1234def56789e
Security findings
Critical: 1High: 1
SSH open to the whole internet
Explanation · sg-public-sshSecurity group sg-0web11111111 allows inbound SSH (port 22) from 0.0.0.0/0. The instance sits in the public subnet behind igw-0a1b2c3d, so anyone on the internet can attempt authentication.
RecommendationReplace the 0.0.0.0/0 rule with your VPN CIDR and restrict port 22 to the bastion range only.
Public IP assigned
Explanation · ec2-public-ip-assignedThe instance has a public IP directly attached, widening the attack surface beyond the load balancer front door.
RecommendationRemove the public IP; reach the host via SSM Session Manager or the VPN instead.
Attack path
Internet This asset prod-cluster Show on graph
Internet This asset prod-db-sg Show on graph
Configuration
{ "state": "running", "instance_type": "t3.medium", "vpc_id": "vpc-0a1b2c3d4e5f6a7b8", "subnet_id": "subnet-0aaa1111pub1a", "public_ip": "54.210.87.14", "security_groups": ["sg-0web11111111"] }