For the complete documentation index, see llms.txt. This page is also available as Markdown.

Attack Surface Dashboard

The Attack Surface dashboard provides an external view of your cloud assets and helps you identify assets that are exposed to the internet, can be reached from outside your organization, and can be accessed without authentication.

Unlike other cloud security views that focus on the internal configuration of your cloud environment, the Attack Surface dashboard evaluates your cloud assets from an external perspective. OX validates whether internet-exposed assets can be reached from outside your organization and whether they require authentication, helping you prioritize assets that present the highest external risk.

Before you begin

Before using the Attack Surface dashboard, you need to enable this capability.

To enable reachability validation:

  1. Go to Settings > Cloud.

  2. Enable Internet Reachability Check.

Note

Enabling Internet Reachability Check allows OX to actively test your internet-exposed assets by attempting to connect to them from outside your organization. This may generate network activity against your environment. Enable this setting only if you want OX to validate the external reachability of your cloud assets.

Attack Path Funnel

The Attack Path Funnel summarizes how OX prioritizes the assets that present the highest external risk. The funnel helps reduce the overall cloud inventory to the relatively small number of assets that require immediate investigation.

Stage
Description

Cloud Assets

Total number of cloud assets discovered across connected cloud environments.

Internet Exposed

Assets that are accessible from the internet.

Reachability Confirmed

Internet-exposed assets that OX verified can be reached from outside your organization.

Authentication Not Required

Reachable assets that do not require authentication to access. These assets present the highest external exposure risk.

Simulated Assets

The Simulated Assets table lists the cloud assets evaluated by OX.

You can select an asset to open the Asset details page, where you can review its configuration, validation evidence, relationships, and associated cloud security findings.

Column
Description

Asset

Asset name and resource type.

Cloud

Cloud provider, account, project, subscription, or region.

Context

Security context collected by OX, including cloud and runtime information.

Reachability

Indicates whether OX verified that the asset can be reached from outside the organization. Confirmed: OX verified that the asset can be reached from outside the organization.

Authentication

Indicates whether OX verified whether authentication is required to access the asset. Not Required: OX verified that the asset can be accessed without authentication.

Verdict

Indicates the overall assessment of the asset's external exposure based on the reachability and authentication validation performed by OX. Breachable: OX classified the asset as breachable because it is reachable from outside the organization and does not require authentication.

Last updated