wallarm
Search Wallarm ⌘K Tenant Name 12345

Infrastructure discovery

Exposure score 38/100 10
8 scans
6 wks agonow
Open attack-path graph
Exposure funnel
how attack surface narrows to real risk
12
Exposed to internet
view in graph
7 +5
Reachable to sensitive
view in graph
5 +2
Confirmed attack paths
view in graph
2 +3
Reach crown-jewel data
see both paths
Summary
Two internet paths reach customer data — fixing 2 security groups closes 4 of 5.
308 risky findings across 21 of 65 assets · 3 accounts · us-east-1, eu-central-1 · last scan 12s ago
Coverage
1 account not connected
3 of 4 accounts · 2 regions scanned

Fix these first

5 choke points, ranked by how much risk each fix removes · 2 changed since last scan
View all 472 findings
All accounts All services All regions
AllAssigned to meIn progressChanged 2
PriorityFixWhy it mattersOwnerAction
CRITICALbreaks 4 paths
sg-prod-web-openNEW
SSH open to 0.0.0.0/0 · security group
Open to the whole internet — an attacker can reach customer-db and secrets in as few as 2 hops.
@deploy-bot
created 3d ago
Investigate

Attack paths · 4

Internetbastionclustercustomer-db
3 hops · reaches customer PII
Internetbastionsecrets
2 hops · prod credentials
Internetbastionclusters3-backups
3 hops · backup exfil
Internetbastionrds-replica
2 hops · read replica

Underlying findings · 3

CRITSG_ALL_TRAFFIC— inbound from 0.0.0.0/0 on all ports
HIGHSG_OPEN_SSH— port 22 reachable from any IP
MEDSG_UNUSED_RULE— stale allow rule, no traffic in 90 days
Provenance · CloudTrail
Created by@deploy-bot
API callCreateSecurityGroup
Source IP203.0.113.9
When3 days ago
Remediation
  1. Replace the 0.0.0.0/0 rule with your VPN CIDR.
  2. Restrict port 22 to the bastion range only.
CRITICALbreaks 2 paths
eks-public-endpoint
Public Kubernetes API · prod-cluster
The cluster API is public — one leaked credential exposes all prod workloads.
@terraform-ci
created 6d ago
Investigate
HIGHbreaks 1 path
DiscoveryRole-prodREGRESSED
IAM wildcard policy · Action: *
A wildcard policy lets any foothold escalate straight into the data tier.
@admin-console
created 12d ago
HIGHbreaks 1 path
prod-web-alb
Listener :80 with no HTTPS redirect
An unencrypted :80 listener exposes web-01 traffic to interception.
@deploy-bot
created 3d ago
Investigate
MEDIUMbreaks 0 paths
prod-worker-1
EBS volume unencrypted at rest
No reachable path — at-rest exposure only, low urgency.
@eks-nodegroup
created 1d ago