A medium-severity SSRF on an EC2 instance.
A dormant IAM role with S3 write. A subnet with an over-permissive NACL. Three findings, three teams, three sprints. Individually they are noise; chained together they exfiltrate your customer database in under an hour. Standard tools list them separately — an attacker sees the path.
The risk of not knowing
If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.
The mechanism, not the marketing
- 1
Onam builds a unified graph across posture, identity, network, data, and vulnerability findings — every resource is a node, every relationship is an edge.
- 2
Crown jewels are identified automatically (sensitive data, prod databases, cross-account admin) and can be tagged manually for business-specific assets.
- 3
A graph traversal engine enumerates every path from an internet-reachable entry point to those crown jewels, scoring each by number of hops, blast radius, and exploit availability.
- 4
Toxic combinations — pairs of individually medium findings that create a critical path together — are surfaced separately and ranked by how many paths they enable.
- 5
Every step is tagged with MITRE ATT&CK for Cloud, so responders see the technique, and remediation guidance points to the single fix that collapses the most paths.
Specific outputs, measurable outcomes
Attack Path Analysis in the real console.
Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.
Questions we get a lot
Ready to see Attack Path Analysis in your cloud?
Connect a read-only role in three minutes. Your first findings surface in under five.