Skip to content
All workCybersecurity
Sablefort SecurityExposure management
Cybersecurity

Find the attack paths that turn weaknesses into business risk.

A security exposure workbench that resolves assets and identities into a graph, identifies exploitable paths to critical systems, and turns them into owned remediation actions.

31,884 resolvedAssets
146 openAttack paths
23 sharedChoke points
119 taggedCritical assets

Scale and interface figures on this page are illustrative.

Operating thesis

Risk is a path, not a finding count.

The interface is designed around reachability and shared choke points so teams can remove meaningful attack paths instead of chasing severity queues.

01

Fragmented context

CVSS and raw finding volume did not explain whether a weakness could actually contribute to compromise of a critical asset.

02

Decision logic

Cloud resources, identities, entitlements, endpoints, and vulnerabilities needed a shared graph with evidence lineage.

03

Operational handoff

Infrastructure owners needed fixable actions with blast radius and verification—not security screenshots copied into tickets.

Product model

Model relationships before dashboards.

The product treats assets, identities, permissions, findings, and criticality as a graph first.

M01

Exposure graph

Cross-workload relationships between identities, endpoints, cloud resources, secrets and vulnerabilities.

M02

Attack paths

Entry point → technique → privilege → lateral movement → critical asset, with evidence per edge.

M03

Choke points

Shared weaknesses or permissions whose remediation breaks multiple attack paths.

M04

Remediation

Owner, SLA, affected paths, recommended fix, ticket sync and verification state.

M05

Exceptions

Risk acceptance with approver, compensating control, expiry and re-review.

Workflow logic

Remediation should break paths.

Actions are prioritized by what they disconnect and verified against fresh evidence.

01ResolveUnify scanner/cloud/IAM records into canonical assets
02ModelGenerate paths to designated critical assets
03PrioritizeRank by reachability, exploitability and business criticality
04RemediateCreate one action for the shared choke point
05VerifyRe-ingest evidence and confirm path closure
Product surfaces

Representative application states.

Representative application states from the product. Figures shown on screen are illustrative.

SCREEN 01 · EXPOSURE GRAPH

Attack path explorer

Internet → finance-prod

SablefortAssets31,884Open paths146Choke points23Evidence11 min freshprod · all accounts
Query

reach(internet) → tier0 where exploitable

Internet-reachableExploit observedTier 0 target
EXTERNALENTRY POINTSIDENTITIESPRIVILEGECROWN JEWELSInternetexternalcheckout-webCVE-2026-18412 · exploitededge-gw-03unpatched · 9 daysdeploy tokenexposed in repowi-paymentsbroad secret readci-deploy rolestanding adminsvc-finance-etlstanding adminvault-readersecretsnode-pool-2privileged podsfinance-prod-db-02Tier 0payments-ledgerTier 0
Paths14
Choke points3
Critical reach2 assets
Shortest firstof 14
RouteHopsTarget
checkout-web → wi-payments → svc-finance-etl4finance-prod-db-02
checkout-web → wi-payments → svc-finance-etl4payments-ledger
checkout-web → wi-payments → vault-reader4finance-prod-db-02
checkout-web → wi-payments → vault-reader4payments-ledger
edge-gw-03 → wi-payments → svc-finance-etl4finance-prod-db-02

Dashed rings mark nodes on 50% or more of these paths. Evidence 11 minutes old.

SCREEN 02 · REMEDIATION

Priority actions

Break the most paths first

SablefortAssets31,884Open paths146Choke points23Evidence11 min freshprod · all accounts
Ranked by paths removed

41 open actions

6 past SLA
Open actions41
Paths removable79of 146
Auto-verifiable31
ActionPathsOwnerSLA
Rotate exposed deploy token−18PL Platform3d left
Constrain svc-finance-etl role−11FE Finance Eng2d over
Patch edge-gw-03−9IN Infra5d left
Restrict wi-payments secret read−8PA Payments1d left
Remove standing admin from ci-deploy−7PL Platform9d left
Isolate node-pool-2 privileged pods−6IN Infra4d over

Top 6: 59 paths. 35 more actions remove the remaining 20.

Diminishing returns paths removed
806040200Top 6 actions: 59 pathsActions, ranked by paths removed41
SCREEN 03 · EXECUTIVE

Exposure posture

Quarter-to-date

SablefortAssets31,884Open paths146Choke points23Evidence11 min freshprod · all accounts
Board view

Exposure posture

Q3 to date
Critical attack paths open weekly
220180140100203146 (−28%)Jul 1Aug 1Sep 1Sep 25
By domain
146open paths
  • Identity46%
  • Network22%
  • Vulnerabilities19%
  • Data13%
What changed
  • Identity paths remain dominant in production.
  • Two overdue actions account for 21 reachable paths.
  • Exception EX-442 expires in 6 days.
Crown jewels exposed
4
Accepted risk
9
Median age
8.2 days
SCREEN 04 · ASSET

Critical asset detail

finance-prod-db-02

SablefortAssets31,884Open paths146Choke points23Evidence11 min freshprod · all accounts
Asset · Tier 0

finance-prod-db-02

Owners: Data Platform, Finance EngLast seen 4m ago
svc-finance-etltrust · 4 hopsvault-readersecret · 3 hopsdba-break-glassrole · 2 hopsbackup-agentnetwork · 2 hopsbi-gatewaynetwork · 3 hopsmigration-jobtoken · 2 hopsfinance-prod-db-02Postgres 15 · eu-east-1Tier 0 · 18 paths in
Findings
HighLocal privilege escalationOpen
MedLegacy TLS 1.0 listenerFixed Sep 18
Compensating controls
PAM session required for adminEnforced
Network policy NET-18Enforced
Paths in
18
Environment
Production
Data class
Financial records
SCREEN 05 · EXCEPTIONS

Risk acceptance

EX-442

SablefortAssets31,884Open paths146Choke points23Evidence11 min freshprod · all accounts
Exception

EX-442 · Legacy gateway patch

Expires in 6 days
Aug 15RequestedAug 17Approved · VP InfraToday · Sep 25Oct 01Expires · 6 days
Justification

Vendor compatibility blocks the patch on edge-gw-03 until the next maintenance release.

Reason
Vendor compatibility
Approver
VP Infrastructure
Paths covered
4
Review
In 6 days
Conditions
Network isolation policy NET-18 in force
Control evidence collected daily
Reopen automatically if evidence fails

The exposure stays on record; accepting risk never deletes it.

Edge-state design

Failure states are part of the product model.

The cases below are intentionally modeled because real operating software is defined by what happens when data, people, or dependencies do not line up.

EDGE 01

Two scanners disagree

Preserve source evidence, resolve to one canonical asset, and expose the conflict instead of averaging severity.

EDGE 02

Accepted risk expires

Automatically re-open the exposure for review; acceptance never deletes graph edges.

EDGE 03

Fix ticket closes without evidence

Keep remediation in verification until a fresh ingest proves the relevant path is broken.

System logic

The data model behind the interface.

The interface follows the domain relationships and rules below.

Canonical objects

Canonical assetIdentityFindingRelationship edgeAttack pathChoke pointCritical assetRemediation actionExceptionEvidence

Domain rules

✓Removing an edge must recalculate affected paths rather than merely mark findings closed.
✓A remediation action may resolve many paths; path count is derived, not manually entered.
✓Accepted risk never deletes the underlying exposure and always carries an expiry/reviewer.
Sablefort Security · Case studyInterface figures are illustrative

Contact

Have something like this to build?

Tell us what you're trying to build and who it's for. If it isn't a fit, we'll say so and point you somewhere better.