☁️ Attack Path Visualiser
Cloud Attack Path Visualiser
Select a misconfiguration and see the realistic attack chain — step by step, with detection and mitigation at each stage.
Select a starting misconfiguration to visualise the attack path:
AWS
S3 Public Bucket → Account Takeover
Exposed bucket contains credentials → full AWS account compromise
Critical Risk
AWS
SSRF on EC2 → IMDS Credential Theft → Lateral Movement
Web app SSRF exploited to steal EC2 instance role credentials
Critical Risk
AWS
Exposed IAM Access Key → Cloud Ransomware
Leaked key used to encrypt S3 data and demand ransom
Critical Risk
AZURE
Azure Blob Public → RBAC Escalation → Tenant Takeover
Public blob contains config with credentials → privilege escalation
Critical Risk
AZURE
Phishing → Azure AD → All M365 Data
Credential phishing bypasses MFA → full tenant access
Critical Risk
GCP
GCS Public Bucket → SA Key → Project Owner
Public bucket contains SA key → project-level compromise
Critical Risk
AWS
Open Security Group → RCE → Cryptominer
SSH exposed → brute force → crypto mining deployment
High Risk
AWS
Unencrypted RDS Snapshot → Data Theft
Public RDS snapshot copied and read by attacker account
High Risk