Skip to main content

Attack Paths

Use Attack Paths to understand the risks around an EC2 instance and its connected resources.

Open an instance graph​

  1. Open Attack Paths from the sidebar.
  2. Search the instance list, or filter by account and region.
  3. Select an EC2 instance to display its graph.
  4. Click an icon to open its details in the panel on the right.

You can pan, zoom, and drag icons to make the graph easier to read. Use the reset control to restore the layout.

What you can investigate​

Graph itemWhat to look for
Attacker and public IPA public address associated with the instance and its potential external exposure.
EC2 instanceThe selected instance and its critical configuration issues.
Security groupsAttached groups and their failed checks, including issues below critical severity.
Critical CVEsA grouped view of the instance's critical software vulnerabilities.
Instance profile and roleThe identity attached to the instance.
AMIThe image name or ID when a matching deprecated-image check has failed.
Related resourcesConnected resources, with critical misconfigurations attached to the affected resource.
Database at riskA database that may be affected through a risky EC2 instance.

Explore critical CVEs​

Click Critical CVEs to see the list in the right panel. Select a CVE to open its full finding page and review the affected package, status, and available guidance.

The full graph can include historical findings. Check each finding's current status before treating it as an active issue.

Understand database risk​

When Byrsa finds evidence of a potential connection from a critically affected EC2 instance to an RDS database, the graph highlights Database at risk. This works with the recorded database engine and connection details, rather than being limited to PostgreSQL.

Select the database to review the relationship and supporting evidence. It may be at risk even without a critical finding of its own. The highlight indicates potential impact; it does not mean the database has been compromised.

A public IP, role attachment, or graph connection is a starting point for investigation. The graph only shows relationships supported by the collected data, so not every storage service or possible route will appear.

Share the selected instance​

Select the instance, then copy the URL from your browser's address bar. Send that complete link to your coworker so they can open the same selection. They must sign in and have access to the relevant workspace.