Attack Path Analysis

Which combination of misconfigurations leads directly to your most critical assets?

Attackers chain small issues into catastrophic breaches. Most tools only show you the individual links.

Onam builds a live security graph across posture, identity, network, and vulnerability data — then runs automated path analysis to show every route an attacker could take from an exposed entry point to your crown jewels.

10,000+
security rules
7
cloud providers
< 5 min
to first finding
100%
agentless
Why this matters

A medium-severity SSRF on an EC2 instance.

A dormant IAM role with S3 write. A subnet with an over-permissive NACL. Three findings, three teams, three sprints. Individually they are noise; chained together they exfiltrate your customer database in under an hour. Standard tools list them separately — an attacker sees the path.

The risk of not knowing

If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.

Real-time detection, not periodic audits
How does it actually work?

The mechanism, not the marketing

  1. 1

    Onam builds a unified graph across posture, identity, network, data, and vulnerability findings — every resource is a node, every relationship is an edge.

  2. 2

    Crown jewels are identified automatically (sensitive data, prod databases, cross-account admin) and can be tagged manually for business-specific assets.

  3. 3

    A graph traversal engine enumerates every path from an internet-reachable entry point to those crown jewels, scoring each by number of hops, blast radius, and exploit availability.

  4. 4

    Toxic combinations — pairs of individually medium findings that create a critical path together — are surfaced separately and ranked by how many paths they enable.

  5. 5

    Every step is tagged with MITRE ATT&CK for Cloud, so responders see the technique, and remediation guidance points to the single fix that collapses the most paths.

What do you actually get?

Specific outputs, measurable outcomes

Crown jewel path analysis
every route from exposed entry points to critical assets, as interactive graphs
Toxic combination detection
AI-identified pairs of misconfigurations that together create critical blast radius
MITRE ATT&CK tagging on every step
Blast radius scoring
Attack path prioritisation
rank by how many critical paths a finding appears in, not CVSS
One-click remediation guidance
the single fix that collapses the most paths
Historical path tracking
Integration with Risk engine
dollar-denominated exposure per path
See it live

Attack Path Analysis in the real console.

Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.

Attack Path Analysis
Export Report
Internet → Crown jewel · 4 hops
Reachable
Path Detail: EC2 → S3
MITRE ATT&CKT1552.005 · Credentials from APIs
Hops4 (EC2 → IMDSv1 → IAM → S3)
Crown Jewel Risk847K PII records at risk
Fix PriorityP0 — Disable IMDSv1
Watch an attack path build
EC2 → IMDSv1 → OpsAdminRole → S3 crown jewel — 4 hops, fix priority P0
Clip length
12s
Data
Demo account
FAQ

Questions we get a lot

CSPM tells you which resources are misconfigured. Attack path tells you which combinations of misconfigurations reach something you actually care about. A public bucket is a CSPM finding; a public bucket reachable from a lambda that can be triggered by an anonymous SNS topic is an attack path.
Ready to see it live

Ready to see Attack Path Analysis in your cloud?

Connect a read-only role in three minutes. Your first findings surface in under five.