AttackLens
Private beta · AWSOn-demand, IAM-validated attack-path assessments for AWS — mapping how an attacker would actually reach your crown jewels, including your AI systems.
AttackLens is an AI-augmented security assessment platform. It connects to your AWS environment read-only, discovers the real paths an attacker could take to your most sensitive resources — data stores, identities, and AI systems — and validates each hop against live AWS IAM authorization instead of guessing from static rules. You get a client-ready report with a prioritized action plan and a grounded AI chat that answers questions about the specific findings. It runs alongside your CNAPP for deep, point-in-time validation — it doesn't replace continuous posture monitoring.
What it does
- Validated attack paths
- AI assets as first-class citizens
- Lightweight AI asset inventory
- Cross-model verification
- Priority Action Plan
- + 4 more below
What it does
Validated attack paths
Discovers forward and reverse paths to your crown jewels and validates each hop with simulated AWS IAM authorization (IAM Policy Simulation), complemented by service-control-policy gap analysis — so findings reflect what identities are actually permitted to do, not a static rule match.
AI assets as first-class citizens
Treats Bedrock, SageMaker, vector stores, and agents as crown jewels in their own right — surfacing paths to model weights and paths from agentic AI, not just classic cloud resources.
Lightweight AI asset inventory
Produces an inventory and risk classification of the AI systems in the account, mapped to the OWASP LLM Top 10 and MITRE ATLAS — useful input for AI governance and EU AI Act pre-scoping. It's assistive context, not legal advice.
Cross-model verification
Every AI-written narrative is checked by a separate model plus deterministic mechanical checks before it ships — catching hallucinations, broken citations, and invalid IAM syntax — with an audit trail of each verdict.
Priority Action Plan
Distills findings into a focused, ordered set of fixes with copy-ready IAM policy JSON, so teams act on what matters first instead of triaging a raw findings dump.
Grounded AI chat
A per-assessment assistant grounded in that assessment's validated findings, citing the specific path or fix inline — retained so teams can revisit the results by asking questions.
Cost-of-Risk modelling
Presents a modeled financial blast-radius range per path and in aggregate — clearly labelled as a model, not a quote — to help translate technical risk into business terms a board can act on.
Exec-ready deliverables
Generates a technical report, an executive brief, and the AI asset inventory as PDF, DOCX, and PPTX — built for consultants and internal teams to hand to clients or leadership.
Read-only by design
A pre-flight check rejects any access role that carries write permissions before a scan starts, so an assessment can never change your environment. Credentials live only in memory during the run.
How it works
From connect to result
Connect (read-only)
You create a single read-only role with a unique external ID. A pre-flight check confirms it has no write access before anything runs.
Discover & recon
AttackLens inventories the environment using AWS-native signals (Security Hub, Config, GuardDuty, Inspector) and identifies candidate crown jewels — including AI systems.
Validate attack paths
It builds a graph of resources, identities, and network reachability, finds forward and reverse paths to the crown jewels, and validates each hop against simulated IAM authorization while scoring exploitability.
Narrate & verify
AI writes the attack-path narratives, priority actions, and executive summary; a separate model plus mechanical checks verify every claim before it's included.
Report & chat
You get a prioritized, client-ready report and a grounded AI chat to explore the findings — with technical, architect, DevOps, and CISO views of the same assessment.
Who it's for
Best fit
- Security consultancies and independent consultants delivering AWS assessments to clients
- MSSPs offering managed assessment tiers
- Internal enterprise security teams running periodic, deep AWS reviews
- Teams securing AI and LLM workloads on AWS
How it fits
What it is — and what it isn't
We'd rather be clear up front than have you find the edges later.
- Runs alongside a CNAPP, not instead of one — point-in-time deep validation, not continuous posture monitoring.
- It confirms each hop is IAM-authorized; it does not execute live exploits, and it doesn't replace penetration testing or GRC tooling.
- AWS-first today — Azure and GCP coverage is on the roadmap.
AttackLens — FAQs
Is AttackLens a CNAPP or a Wiz replacement?
No. It's an on-demand, point-in-time assessment that validates attack paths and produces a client-ready deliverable. It complements a continuous posture platform (CNAPP) rather than replacing it.
Does it change anything in my account?
No. You grant a single read-only role, and a pre-flight check rejects it if it carries any write permissions before the scan starts. Credentials live only in memory during the run and are never persisted.
What do you mean by 'validated' attack paths?
Each hop in a path is checked against simulated AWS IAM authorization (IAM Policy Simulation), complemented by service-control-policy gap analysis — so a reported path reflects what the identities are actually permitted to do. It confirms authorization; it does not fire an exploit.
How is the AI chat different from a generic assistant?
It's grounded in that specific assessment's validated findings and cites them inline. Environment-specific answers are strictly tied to the evidence; general best-practice answers are labelled as such, so the two never blur.
Which clouds does it cover?
AWS today, including AWS-hosted AI services. Azure and GCP are on the roadmap.
See AttackLens for yourself
Book a call and we'll walk you through it against a sample environment, and talk through access for your team.