KEVCVE-2026-31047 added to CISA KEV|EXPOSUREOllama endpoint, no auth, port 11434|CVECVE-2026-30988 scored 9.8 before NVD|DRIFTS3 bucket policy changed, re-scored in 30s|SHADOW AIWeaviate instance, open schema|SBOM412 components read from running image|PATHNew cross-cloud path, AWS to GCP, depth 6|ADVISORYCisco advisory ingested, 3 products|
CVEs published ahead of NVD by 16-35 min

Know your blast radius.

EchelonGraph builds one asset inventory across AWS, GCP and Azure and turns it into a single attack graph, so you can see in one click everything a single exposed identity can actually reach.

Attack Graphblast radius · 1 path selectedREPRESENTATIVE
depth 6 · 41 reachable
ROUTES_TORUNS_ASCAN_ASSUMECAN_ACCESSInternet0.0.0.0/0Load balanceralb/edgeComputeec2/api-7f2IAM roleci-deployerStorages3/artifactsGCP SAdata-syncCustomer DBrds/prod

Representative attack path. Node types, colours and edge semantics are the ones the product ships; the topology is an example, not a customer environment.

CoversAWSGoogle CloudAzureKubernetesTerraform

One graph. Five tools it replaces.

Five separate tools build five separate inventories, and the gaps between them are where the path hides. These are five views of one.

Cloud posture

Misconfiguration across AWS, GCP and Azure, scored against the same inventory the graph runs on.

Learn more
Findingscloud posture · 3 accountsREPRESENTATIVE
CRITICAL
12
HIGH
48
MEDIUM
131
RESOLVED 30D
1,204
CRITICALS3 bucket public-readAWS
HIGHSecurity group 0.0.0.0/0 :22AWS
HIGHCloud SQL no SSL enforcementGCP
MEDIUMStorage account allows HTTPAzure
MEDIUMKMS key rotation disabledAWS

See it on your own estate

Read-only connection, and your first scan complete in under ten minutes.

From connected to answering in under ten minutes

01
your cloudread-onlyEchelonGraphno agent

Connect

One read-only role per cloud. No agents, no network changes.

under 5 min
02
workloadsidentitiesimagesone inventory, all three clouds

Inventory

Every workload, identity, image and permission lands in one place.

first scan < 10 min
03
AWS→GCPedges observed, not inferred

Graph

Trust and reachability become edges. Cross-cloud hops included.

continuous
04
9.1reachable7.4blocked9.8unreachableordered by reach, not by CVSS

Act

A queue ordered by what an attacker can actually reach, not by CVSS.

re-scored in 30s

Ask the graph in plain English

The AI analyst answers from your graph and shows the path it walked. Grounded in your own inventory, never trained on your data.

See the AI analyst
AI Security Analystgrounded in your graphREPRESENTATIVE
Which internet-facing assets can reach customer data?
E
ec2/api-7f2iam/ci-deployergcp:sa/data-syncrds/prod
grounded in 41 graph nodes · no training on your data
Field report · July 2026

The State of Exposure

July 2026 in evidence: what the whole internet could already see, observed read-only across 114 countries. 209 facts, 187 sources, every one re-checked. 132 pages, free and no signup.

9,924
CVEs published
26
added to CISA KEV
7,640
open databases
114
countries observed
ECHELONGRAPHThe State ofExposureJuly 2026132 pages · 209 facts · 187 sources

Questions we get asked

The four that come up in almost every first call.

Something else?

We would rather answer it than have you guess.

Talk to us
What is EchelonGraph?+

EchelonGraph is a cloud security intelligence platform that provides real-time attack surface mapping, blast radius visualization, and automated compliance scoring across AWS, GCP, and Azure.

What compliance frameworks does EchelonGraph support?+

EchelonGraph automates compliance scoring across 330 frameworks including CIS AWS Foundations v3.0.0, CIS GCP Foundations v2.0.0, CIS Azure, CIS Kubernetes Benchmark v1.9, Pod Security Standards (Privileged/Baseline/Restricted), AI Workload Compliance (NIST AI-RMF + EU AI Act + ISO/IEC 42001 + MITRE ATLAS), SOC 2 Type II, ISO 27001:2022, HIPAA, PCI-DSS 4.0, GDPR, NIST 800-53, FedRAMP Moderate, CMMC 2.0 L2, CIS Controls v8, NIS2, DORA, SWIFT CSP, HITRUST CSF, Essential Eight, NIST 800-171, ISO 27017/27018/27701, NIST CSF, GLBA, and more. Posture-sweep cadence is plan-gated: Free, Starter and Team sweep each connected cloud account daily, while Pro and Enterprise sweep hourly (and can be set as often as every 15 minutes). On every plan a change watcher pulls the next sweep forward when it sees something move. Once a change lands, the compliance engine re-scores all 3,473 controls inside a 30-second SLA — measured at about 11 seconds on our own estate on 2026-08-07.

How does blast radius visualization work?+

EchelonGraph builds a real-time graph of every asset, connection, and permission in your cloud infrastructure using Neo4j. When a vulnerability is detected, the blast radius engine calculates exactly which downstream systems, data stores, and users could be impacted — visualized as an interactive 3D graph.

Does EchelonGraph require agents?+

EchelonGraph uses a 3-tier agent architecture: Tier 1 (EcheSky) is agentless via cloud APIs, Tier 2 (EcheNet) performs network crawling, and Tier 3 (EcheDeep) uses eBPF for zero-knowledge runtime protection — no kernel modules required.

Is there a free tier?+

Yes. EchelonGraph offers a Free tier with up to 3 cloud accounts, 500 assets, Tier 1 cloud scanning, CIS + SOC 2 frameworks, and 90-day data retention. No credit card required.

What is the Shadow AI Radar?+

The Shadow AI Radar monitors Certificate Transparency logs and Shodan in real-time to discover exposed AI infrastructure — vector databases, LLM proxies, RAG pipelines, model registries, and AI agents that are publicly accessible without authentication. It's a free, live feed of shadow AI endpoints that security teams can use to identify exposures before attackers do.

What is the Surface Scanner?+

The Surface Scanner is an external attack surface analysis engine with 35 parallel security modules (25 free, 10 Pro). It analyzes TLS/SSL, security headers, DNS + full email-security suite (SPF/DKIM/DMARC/MTA-STS/BIMI/TLS-RPT, DNSSEC, CAA), exposed secrets (55+ patterns), sensitive paths, cloud buckets (11 providers + name-guessing), open redirects, cookies, JWT audit, session-entropy, MFA detection, source-maps, GraphQL introspection, Swagger exposure, backup files, third-party JS / SRI audit, API versioning, AI-bot policy, typosquat + Spamhaus DBL, and more — delivering an A+ to F security score in 2–3 minutes.

Start with what an attacker sees first

Scan any domain you own. It is the same engine that feeds the graph.

No signupResults in 2-3 minutesRead-only
B
yourcompany.com
35 modules · 1 high · 1 medium
EXAMPLE
TLS & certificateTLS 1.3, valid 61 days
Security headersCSP and HSTS missing
Email authenticationDMARC p=none
Exposed paths & secretsnothing reachable