Attack-Surface Graph
See your whole external footprint as one living graph — assets, services, exposures and how an attacker pivots between them.
Lists of findings hide the thing attackers care about most: how one weak point connects to the next. heimdallX assembles every asset, subdomain, service, identity and exposure into a single living attack-surface graph, then highlights the shortest paths an adversary would take to reach what matters. You see not just what's vulnerable, but what it unlocks.
From a list to a map
Every discovered host, service, credential and exposure becomes a node; correlations become edges. The graph updates on every scan and DRP collection, so the picture always reflects your live surface — not a stale spreadsheet.
Attacker paths & blast radius
Select any asset and heimdallX traces the shortest exploitable path to it, and the blast radius if it falls. Crown-jewel assets are tagged so the paths that reach them rise to the top of your priorities.
One graph across scan and DRP
The same graph fuses inside-out scan findings with outside-in external threats — leaked identities, look-alike domains, active actors — the full picture an attacker would assemble, in one view.
How it works
Ingest
Pull assets, services, identities and exposures from every module.
Connect
Correlate nodes into edges — reachability, ownership, exposure.
Path-find
Compute shortest attacker paths to crown-jewel assets.
Prioritize
Rank findings by what they unlock, not just severity.
$ graph paths --to crown-jewels→ leaked VPN cred → vpn.acme-corp.com → internal portalpath length 3 · reachable · TALON 88→ blast radius: 12 assets · 3 identities
Put it to work
Run your first scan in under two minutes. Free, no credit card, real findings.
Launch heimdallX