For the complete documentation index, see llms.txt. This page is also available as Markdown.

Attack Surface Asset Details

The Asset details page provides detailed information about a cloud asset, including its configuration, external reachability validation, relationships to other cloud resources, and associated security findings.

To open the page, select an asset in the Simulated Assets table.

The page contains the following tabs:

Explore

The Explore tab provides an overview of the selected asset, including its cloud configuration, exposure status, and associated cloud security findings.

Summary

Section
Description

Policies

Displays the cloud security issues associated with the asset. Select View n Issues to open the related issues.

Cloud Information

Displays information about the cloud provider, account, region, resource type, category, internet exposure, and authentication requirements.

General Details

The General Details section displays metadata for the selected resource.

Depending on the resource type, the information may include:

Property
Description

Resource ID

Unique identifier of the cloud resource.

ARN

Amazon Resource Name for AWS resources.

Detected Environment

Environment associated with the resource, such as Development or Production.

Resource-specific properties

Additional metadata specific to the selected cloud resource.

Reachability

The Reachability tab explains how OX validated the external reachability of the selected asset.

Reachability Playbook

The Reachability Playbook provides transparency into the validation performed by OX.

Section
Description

Validation Summary

Displays the validation result and whether authentication is required.

Playbook

Describes the validation steps performed by OX, including the endpoints evaluated, requests sent, and responses received.

Manual Check

The Manual Check section provides commands that you can copy and run to validate the findings independently.

Item
Description

Command

Command used to validate the selected asset.

Response

Response returned when the command is executed.

Additional Details

The Additional Details section displays metadata collected during the validation.

Property
Description

Public Access

Indicates whether the asset is publicly accessible.

Endpoint Type

Type of public endpoint associated with the asset.

API Key Source

Location from which an API key is expected, if applicable.

Has Resource Policy

Indicates whether the resource has an associated access policy.

Graph View

The Graph View tab visualizes the selected asset and its relationships to connected cloud resources.

Use this view to understand how the asset fits into your cloud environment and identify resources that may be affected by configuration changes or remediation activities.

Element
Description

Selected Asset

The cloud asset being analyzed.

Connected Resources

Cloud resources connected to the selected asset.

Relationships

Connections between the selected asset and related resources.

Issue Statistics

The Issue Statistics tab summarizes the cloud security findings associated with the selected asset.

Use this tab to understand the overall security posture of the selected asset before investigating individual findings.

Widget
Description

Category

Distribution of findings by category.

Severity

Distribution of findings by severity.

Issue Owner

Distribution of findings by assigned owner.

Source Tool

Distribution of findings by the OX capability that generated the findings.

Last updated