Findings without a subject
A misconfiguration with no link to the workload, image or repository that caused it has no owner.
A public bucket is a finding. A public bucket that a workload running a vulnerable image can write to, through a role anyone can assume, is an attack path. SecurityVault stores the second kind.
A misconfiguration with no link to the workload, image or repository that caused it has no owner.
Posture is reported as a list at collection time; what changed since yesterday is a diff nobody runs.
Who can reach the bucket is answered by a CIEM product that does not know about the CVE.
Cluster findings stop at the namespace; nobody knows which image digest is actually running.
Compliance mapping is a report generated from the same list, one framework at a time.
Runtime visibility requires an agent fleet before the first result.
hosted_in, assumes and can_access edges.affect the resource; drift detection produces change, not just state.Every account, resource and principal has a 360 view.
Registry watchers and sensors bind what runs.
Data stores, classifications and external endpoints.
Chokepoints and interventions.
One finding, every dependent control.
Sensors and scan band can run in your environment.
Watch a bucket finding become an attack path with a workload, an image digest and a commit on it.