trident/cloud

The paths thatreach your data.

One graph across AWS, Azure, GCP and Kubernetes. See the attack paths that end at your crown jewels, ranked by what they reach.

  • AWS
  • Azure
  • GCP
  • Kubernetes

READ-ONLY CONNECTION · NO AGENTS DEPLOYED

gcp · dataStorage bucketacme-invoicesSensitiveDatasetanalyticsService accountetl-runnerFunctionnightly-syncBucketexportsaws · ciRoledeploy-roleBucketbuild-cacheComputeci-runnerQueueartifactsFunctionnotifyaws · prodLoad balancershop-webContainer serviceorders-apiFunctionthumbs-resizeDatabaseorders-dbQueueorder-eventsJOINING WHAT AN ATTACKER CAN REACH …what the internet sees03shop-web · publicorders-api · behind lbexports · privateEXPOSUREwho can assume what03orders-api → deploy-roleci-runner → deploy-roledeploy-role → acme-invoicesIAM EDGESwhat can reach what02shop-web → orders-apiorders-api → orders-dbNETWORKwhat is worth reaching03acme-invoices · sensitiveanalyticsorders-dbDATApath · ranked #3path · ranked #1path · ranked #2ranked paths#1 high#2 medium#3 mediumcut deploy-role · closes 2Internet → acme-invoicesHigh · 4 hops · 3 accountsChoke point · deploy-role

01THE PROBLEM

Paths, not counters.Ranked by what they reach.

Scanners flag each condition on its own. An attacker chains them. Trident looks at the chain.

Four conditions on four resources: shop-web is public, orders-api is a workload, deploy-role is assumable, acme-invoices is sensitive. One line threads them from the internet into a single path.
A TOXIC COMBINATION
  • 6to 1Scanners merged into one list, ranked by risk.
  • 1 hopEvery path names the one hop that closes it, usually an over-privileged role.
  • 0 agentsA read-only connection builds the graph. Nothing is deployed.

Scanners dump thousands of standalone misconfiguration alerts, with no way to tell which reach production data. Trident joins exposure, IAM edges and findings into ordered, multi-hop paths that end at a named data store.

SEE HOW IT WORKS

02ONE RANKED LIST

Six scanners in.One ranked list out.

Exposure, IAM and findings correlate into ranked attack paths, so the list starts with what reaches your data.

Trident Cloud

Alerts in, attack paths out

Standalone alerts from six kinds of scanner, joined into one list ordered by what each path reaches.

alertsalertsalertsalertsalertsalertsCSPMVulnerabilityIAM analyzerNetworkContainerKubernetes6 → 1
[ ONE LIST · RANKED BY RISK ]01Internet → acme-invoicesaws · prod → aws · ci → gcp · dataHigh02ci-runner → analyticsaws · ci → gcp · dataMedium03orders-api → orders-dbaws · prodMedium04nightly-sync → exportsgcp · dataLowEach path names its choke point and ships a fix.

Illustrative. Bar heights show alert volume, not measured counts.

03KNOW THE PATH

Know the path.Close the risk.

Every path names the one hop that closes it, usually an over-privileged role. Each path opens a draft PR with remediation and a regression test.

Trident attack path: Internet to customer invoices in 4 hops, joined across 3 accounts and ranked #1 of 3. shop-web → orders-api → deploy-role → acme-invoices, with the High finding “Customer invoices reachable from the internet”.
Draft pull request #412 on acme/infra, opened by Trident: “Close the path at deploy-role”. iam/deploy_role.tf drops orders-api from trusted_services (+1 −1); a regression test is added and the path is retested after merge.
  • Choke-point remediation

    Every path names the one hop that closes it, usually an over-privileged role.

  • Proven, not theoretical

    Paths rank by evidence Trident can reproduce, not by configuration noise.

  • Fixes engineers can merge

    Each path opens a draft PR with remediation and a regression test.

04HOW IT WORKS

From read-only roleto a merged fix.

  1. Exposure, identity and scanner findings collapse into ranked paths to crown-jewel data.

Attach a read-only role. Trident inventories assets, identities and data stores across every account.

aws · prodshop-weborders-apiorders-dbthumbseventsstaticaws · cideploy-rolebuild-cacheartifactsci-runnernotifyreleasesgcp · dataacme-invoicesanalyticsexportsetl-runnernightly-syncwarehousegcp · dataaws · ciaws · prodREAD-ONLY ROLE

Assumes-role, reaches, exposes and stores resolve into one graph. Exposure, identity and findings join into paths.

[ RANK ][ GRAPH ]TRIDENT ▶[ CORRELATE ]JOINING PATHS

Each path ships its choke-point fix with proof and a test.

[ RANKED ATTACK PATHS ]PATHCHOKE POINTRISK1Internet → acme-invoices4 hops · 3 accountsdeploy-roleHigh2ci-runner → analytics2 hops · 2 accountsdeploy-roleMedium3orders-api → orders-db1 hop · aws · prodorders-db policyMedium4nightly-sync → exports1 hop · gcp · dataexports bucketLowPathsGraphDraft PR

05COVERAGE

AWS, Azure, GCPand Kubernetes. One graph.

Inventory every resource and identity, then trace blast radius from any asset. SOC 2, CIS and PCI posture sit on the same graph as the risk.

  • AWS

    Accounts and organizations

    READ-ONLY

  • Azure

    Subscriptions

    READ-ONLY

  • GCP

    Projects

    READ-ONLY

  • Kubernetes

    Clusters

    READ-ONLY

  • AWS · Azure · GCPCLOUD CONTEXT
  • Read-onlyCONNECTION MODEL
  • ConnectedASSETS, IDENTITIES AND DATA
  • RetestedAFTER REMEDIATION
COMPLIANCE MAPPED TO RISKSOC 2CISPCI

06QUESTIONS

Frequentlyasked.

An ordered set of reachable relationships that could let an attacker move from an initial foothold to a material target. A path can combine internet exposure, a workload weakness, IAM permissions, trust policies, network reachability and access to sensitive data.

CSPM continuously identifies configuration and posture issues. Attack path analysis connects selected issues with identity, network, workload and data relationships to find which combinations create a route to a critical target. The two complement each other.

A set of individually limited conditions that becomes materially risky when combined, such as public reachability, a vulnerable workload, an assumable role and access to a sensitive data store.

A relationship or control shared by one or more attack paths. Narrowing a role trust policy, reducing a permission or isolating a data store can break several paths with one change.

A read-only role. No agents are deployed.

[07]GET STARTED+

Find it beforethey do.

Start a free trial. Your first verified findings land within a day of connecting.

  • SOC 2 audited by Sensiba LLP
  • Read-only cloud access