Exposure funnel
how attack surface narrows to real risk
12
Exposed to internet
view in graph7 +5
Reachable to sensitive
view in graph5 +2
Confirmed attack paths
view in graph2 +3
Reach crown-jewel data
see both pathsSummary
Two internet paths reach customer data — fixing 2 security groups closes 4 of 5.
Coverage
1 account not connected
3 of 4 accounts · 2 regions scanned
Fix these first
5 choke points, ranked by how much risk each fix removes · 2 changed since last scan
All accounts
All services
All regions
AllAssigned to meIn progressChanged 2
PriorityFixWhy it mattersOwnerAction
CRITICALbreaks 4 paths
sg-prod-web-openNEW
SSH open to 0.0.0.0/0 · security group
Open to the whole internet — an attacker can reach customer-db and secrets in as few as 2 hops.
@deploy-bot
created 3d ago
Attack paths · 4
Internetbastion→cluster→customer-db
3 hops · reaches customer PIIInternetbastion→secrets
2 hops · prod credentialsInternetbastion→cluster→s3-backups
3 hops · backup exfilInternetbastion→rds-replica
2 hops · read replicaUnderlying findings · 3
CRITSG_ALL_TRAFFIC— inbound from 0.0.0.0/0 on all ports
HIGHSG_OPEN_SSH— port 22 reachable from any IP
MEDSG_UNUSED_RULE— stale allow rule, no traffic in 90 days
CRITICALbreaks 2 paths
eks-public-endpoint
Public Kubernetes API · prod-cluster
The cluster API is public — one leaked credential exposes all prod workloads.
@terraform-ci
created 6d ago
HIGHbreaks 1 path
DiscoveryRole-prodREGRESSED
IAM wildcard policy · Action: *
A wildcard policy lets any foothold escalate straight into the data tier.
@admin-console
created 12d ago
HIGHbreaks 1 path
prod-web-alb
Listener :80 with no HTTPS redirect
An unencrypted :80 listener exposes web-01 traffic to interception.
@deploy-bot
created 3d ago
MEDIUMbreaks 0 paths
prod-worker-1
EBS volume unencrypted at rest
No reachable path — at-rest exposure only, low urgency.
@eks-nodegroup
created 1d ago