Parse Terraform, CloudFormation, Kubernetes, Helm and docker-compose for misconfig and public exposure.
Security groups open to 0.0.0.0/0, public RDS/S3, LoadBalancers.
Parsed components feed the threat model as facts, not guesses.
Detect new attack surface since the model was built.
Parse Terraform, CloudFormation, Kubernetes, Helm and docker-compose into typed components with real trust boundaries - so misconfiguration and public exposure are facts with a file:line, and they ground your threat model.
Turn IaC into typed resources, trust zones and data flows.
Find public exposure and misconfiguration: 0.0.0.0/0, public RDS/S3, open load balancers.
Feed the parsed architecture into the threat model and detect drift over time.
Every IaC finding deduplicates into one risk-weighted posture, correlates into attack-chains, and can block the build at the CI gate.
From discovery to a proven attack chain. A PoC in your own environment.