Attack Paths
Use Attack Paths to understand the risks around an EC2 instance and its connected resources.
Open an instance graph
- Open Attack Paths from the sidebar.
- Search the instance list, or filter by account and region.
- Select an EC2 instance to display its graph.
- Click an icon to open its details in the panel on the right.
You can pan, zoom, and drag icons to make the graph easier to read. Use the reset control to restore the layout.
What you can investigate
| Graph item | What to look for |
|---|---|
| Attacker and public IP | A public address associated with the instance and its potential external exposure. |
| EC2 instance | The selected instance and its critical configuration issues. |
| Security groups | Attached groups and their failed checks, including issues below critical severity. |
| Critical CVEs | A grouped view of the instance's critical software vulnerabilities. |
| Instance profile and role | The identity attached to the instance. |
| AMI | The image name or ID when a matching deprecated-image check has failed. |
| Related resources | Connected resources, with critical misconfigurations attached to the affected resource. |
| Database at risk | A database that may be affected through a risky EC2 instance. |
Explore critical CVEs
Click Critical CVEs to see the list in the right panel. Select a CVE to open its full finding page and review the affected package, status, and available guidance.
The full graph can include historical findings. Check each finding's current status before treating it as an active issue.
Understand database risk
When Byrsa finds evidence of a potential connection from a critically affected EC2 instance to an RDS database, the graph highlights Database at risk. This works with the recorded database engine and connection details, rather than being limited to PostgreSQL.
Select the database to review the relationship and supporting evidence. It may be at risk even without a critical finding of its own. The highlight indicates potential impact; it does not mean the database has been compromised.
A public IP, role attachment, or graph connection is a starting point for investigation. The graph only shows relationships supported by the collected data, so not every storage service or possible route will appear.
Share the selected instance
Select the instance, then copy the URL from your browser's address bar. Send that complete link to your coworker so they can open the same selection. They must sign in and have access to the relevant workspace.