Know exactly what a
misconfiguration can
reach.
MetriGraph maps your cloud resources as a dependency graph and scores every finding by real-world reachability — not just severity on paper.
Core Intelligence
Blast Radius Scoring
Misconfiguration chaining shows you the path an attacker would actually take. We filter out the noise so you can focus on the critical intersections of your infrastructure while we finalize our engine.
Under the hood
How MetriGraph Works
Three-step analysis pipeline that turns raw cloud config data into actionable blast-radius intelligence.
01 — INGEST
Cloud Config Ingestion
Upload a snapshot JSON or connect your cloud account via read-only IAM role. MetriGraph snapshots your resource state in seconds.
02 — MAP
Dependency Graph Build
Every resource becomes a node. Trust relationships, network paths, and data flows become directed edges — revealing hidden attack surfaces.
03 — SCORE
Blast Radius Scoring
Each misconfiguration is scored 0–100 based on reachable blast radius — how many critical resources are compromisable downstream.
Curated Checks
Hand-engineered rules that surface real risk paths across AWS services — not just compliance noise.
S3
Public bucket with IAM role trust chained to sensitive data store
CriticalEC2
Overpermissive instance profile granting unscoped S3 write access
HighLambda
Environment variable exposing credentials readable via public invoke
CriticalVPC
Unrestricted peering with cross-account data path to production RDS
HighIAM
Wildcard resource permissions on assume-role without MFA condition
CriticalRDS
Publicly accessible database with weak subnet group isolation
HighCloudTrail
Logging disabled in region containing sensitive workloads
MediumSTS
Long-lived credentials in use with no rotation policy enforced
MediumEarly Access
Be first to see your blast radius.
MetriGraph is in closed beta. Join the waitlist and we'll reach out when your spot opens — no commitments, full access.