Wallarm API Security Wallarm updates logo

Wallarm updates

Discover the latest features, improvements, and updates in Wallarm API Security

Subscribe to Updates

Labels

  • All Posts
  • API Security
  • WAAP
  • ANNOUNCEMENT
  • Security Edge
  • IMPROVEMENT
  • FIX
  • Security Testing
  • AI Security
  • AI Hypervisor
  • Infrastructure Discovery

Jump to Month

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • March 2022
  • February 2022
  • December 2021
  • November 2021
  • October 2021
  • August 2021
  • April 2021
  • March 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • December 2019
  • October 2019
  • August 2019
  • April 2019
ANNOUNCEMENTInfrastructure Discovery
2 days ago

See how an attacker would reach your critical AWS assets

Your findings list tells you what's wrong. It can't tell you what's reachable.

Attack Paths works from a different input: the actual shape of your estate. Which AWS resources are exposed, which roles can be assumed by whom, which principals can read what. Those relationships are what a path is built from, whether or not anything along the chain has ever been flagged as a problem.

It's live in Infrastructure Discovery now, and there's nothing to install. If your AWS accounts are already connected, it's in your dashboard.

What's new

Paths built from configuration, not from CVEs A path exists because something is exposed, some permission is broader than intended, and something valuable sits at the end of it. Findings from Security Hub, Inspector, and GuardDuty can raise a path's priority, but they never create one and never gate one. Plenty of the paths worth your time have no finding attached anywhere along the chain.

Ranked paths, shown as a map Every path runs from an entry point, through any pivots along the way, to a crown jewel. You get the whole chain as a map, with a severity band and a plain-English reason it landed where it did.

Crown jewels you choose yourself You decide what counts as high value in your estate. Pin and unpin assets from the console, and path scoring reorganizes around your choices instead of our assumptions about your business.

Key nodes: entry points and choke points Entry points are ranked by what they actually open up. Choke points are the nodes that the most paths run through, which is usually where a single change does the most work.

Identity, not just network reachability Paths follow IAM as closely as they follow the network: role chaining, pass-role, policy attachment, self-escalation, and principals holding effective admin through AWS managed policies.

Why it matters

A severity list ranks problems one at a time, and it's genuinely good at that. What it can't do is tell you that a role you granted a vendor two years ago, with "read-only" in its name and a wildcard in its policy, sits one hop from every secret you own. There's no CVE on that role and nothing about it is broken. Someone made a reasonable call and the blast radius grew around it quietly. That's a path, and paths are what this is for.

Where to find it

Infrastructure Discovery → Attack Paths. 

Attack Paths is included in your Infrastructure Discovery license. No separate SKU, no add-on charge.

Full details in the Infrastructure Discovery documentation.

Avatar of authorTim Erlin