Cloud posture · CSPM

Cloud Security Posture (CSPM)

Catch the cloud misconfigurations attackers love — public buckets, open ports, over-broad IAM — mapped to the same fix-first queue.

Launch heimdallXAll capabilities

Most breaches start with a misconfigured cloud resource, not a zero-day. heimdallX extends its scanning into your cloud footprint — public storage, exposed services, over-broad IAM roles and weak defaults — and folds every misconfiguration into the same exploitability-ranked queue as your web and code findings, so cloud risk isn't a separate silo.

heimdallx.ai/appheimdallXPROUpgradeAI analystNew scanSign outAAcme Securityacme-prodCommand centerOverviewExecutive BriefFindings24Remediation7Assets18OperationsDiscoveryAttack Surface5Breach SimThreat IntelMonitoring3Compliance12IntegrationsActivityExternal ThreatsExternal Threats9Threat FeedAI BriefingFindingsCloud (CSPM · CIEM)Resources312Misconfigs18Identity risks7providersAWS · GCP · K8s☣ TOXIC COMBINATIONInternet-exposed cloud resource with an over-privileged identity98Cloud misconfigurationsCRITWorld-readable S3 bucket · acme-backupsCloud Storage · AWS S3HIGHRole assumable by any principal (*)Excessive Cloud Permissions · AWS IAMHIGHSecurity group opens 0.0.0.0/0:5432Public Cloud Resource · AWS EC2MEDConsole user without MFACloud Identity Risk · AWS IAM

Misconfig, not just CVEs

Cloud risk is mostly configuration: a public bucket, a wide-open security group, an unused-but-privileged key. heimdallX checks these against CIS-benchmark expectations and flags the ones that actually expose data or grant a foothold.

One queue, cloud included

Cloud findings carry the same severity, EPSS/KEV context where applicable and remediation guidance as the rest of the platform, and re-rank in the same fix-first queue — no separate tool, no separate triage.

IAM blast radius

Over-permissive roles are scored by what they unlock. An unused key with admin rights is treated as the pivot it is, and surfaced in the attack-surface graph alongside everything else.

How it works

1

Connect

Read-only access to your cloud inventory.

2

Check

Test storage, network, IAM & defaults vs CIS.

3

Correlate

Fold misconfigs into the unified surface graph.

4

Rank

Prioritize by exposure and blast radius.

Cloud posture example
$ cspm scan --provider aws
→ S3 acme-backups: public READ · CRIT
→ SG sg-0af: 0.0.0.0/0 : 22 open · HIGH
→ IAM role ci-deploy: * : * (admin) · HIGH

Put it to work

Run your first scan in under two minutes. Free, no credit card, real findings.

Launch heimdallX
Cloud Security Posture (CSPM) — heimdallX