Derivation rules

2,433 declarative match → where → emit rules (1,787 derived, 646 explicit). Filter by cloud, emitted edge, node type, or text.

91 rule(s) · page 2 of 2

Function app SCM/app surface reachable publicly (used with a held key or exploitable code).
azure ExposedToInternet derived
A Logic App with a public HTTP (Request) trigger and no IP allowlist is triggerable from the internet.
azure ExposedToInternet derived
A Standard Load Balancer with a public frontend IP is reachable from the internet on its listener ports.
azure ExposedToInternet derived
An NSG effective inbound Allow rule from Internet/0.0.0.0/0 on a service port, combined with a public IP (or internet-facing LB) on an attached resource, makes that resource internet-reachable: ExposedToInternet.
azure ExposedToInternet derived
PostgreSQL/MySQL Flexible Server with publicNetworkAccess Enabled and an internet-wide firewall rule exposes the DB endpoint to the public internet.
azure ExposedToInternet derived
Cache with authnotrequired=true and publicNetworkAccess=Enabled allows anonymous internet access to the Redis data-plane with full commands.
azure ExposedToInternet derived
Cache for Redis with publicNetworkAccess=Enabled and no IP firewall rules exposes the Redis data-plane port 6380 (SSL) to the public internet.
azure ExposedToInternet derived
A firewall rule allowing 0.0.0.0–255.255.255.255 explicitly exposes the Redis data-plane endpoint to the entire public internet.
azure ExposedToInternet derived
A Service Bus namespace with publicNetworkAccess=Enabled and no restrictive IP filter is reachable from the internet; any holder of a valid SAS key or Entra token can connect from any IP.
azure ExposedToInternet derived
SF cluster gateway (19000 FabricGateway / 19080 FabricHttpGateway+SFX) fronted by a public LB with a permissive NSG.
azure ExposedToInternet derived
SQL Managed Instance with publicDataEndpointEnabled=true and an NSG allowing inbound TCP 3342 from the internet is reachable by any internet host.
azure ExposedToInternet derived
SQL logical server with publicNetworkAccess=Enabled and a 0.0.0.0–255.255.255.255 firewall rule is reachable from the public internet on port 1433.
azure ExposedToInternet derived
Storage account with public blob access enabled and a public container exposes blob data to unauthenticated internet access.
azure ExposedToInternet derived
Synapse workspace development, SQL, and Spark endpoints are public-internet reachable when publicNetworkAccess is Enabled and no private-endpoint-only restriction is applied.
azure ExposedToInternet derived
VM with a public IP and an NSG rule allowing an inbound port.
azure ExposedToInternet derived
A CNAME or alias DNS record (in a public zone) pointing to a deprovisioned Azure resource enables subdomain takeover: an attacker can claim the target resource and inherit DNS resolution for the dangling name.
azure ExposedToInternet derived
A compute resource or load balancer with a public IP AND an NSG rule that allows inbound Internet/0.0.0.0/0 on a port is internet-exposed.
azure ExposedToInternet derived
A serving App Engine version is reachable at its appspot.com URL (modeled as a PublicEndpoint node) unless ingress-restricted.
gcp ExposedToInternet derived
A repository granting uploadArtifacts to allUsers allows any unauthenticated attacker on the public internet to push code - the most critical supply-chain injection vulnerability.
gcp CanModifyCode derived
A dataset ACL entry for allUsers makes it queryable by unauthenticated public principals - internet-accessible data.
gcp ExposedToInternet explicit
A CNAME (or ALIAS) resource record set in a public Cloud DNS zone whose target resolves to a GCP-managed FQDN suffix that no longer has a backing resource in collected GCP inventory enables subdomain takeover: an external attacker can claim that resource name and inherit DNS resolution for the dangling hostname.
gcp ExposedToInternet derived
cloudsql.instances.update can enable public IP (ipv4Enabled=true) and add 0.0.0.0/0 to authorizedNetworks, making the instance internet-reachable from any network.
gcp ExposedToInternet derived
A Cloud SQL instance with a public IP (ipv4Enabled=true) and an authorized network of 0.0.0.0/0 is TCP-reachable from the internet on the DB port, exposing it to unauthenticated network-level attack (brute-force, known CVEs).
gcp ExposedToInternet derived
Airflow web server in Composer 2 environment is internet-accessible when config.webServerNetworkAccessControl.allowedIpRanges includes 0.0.0.0/0.
gcp ExposedToInternet derived
Dataproc cluster master VM with a public IP and permissive dataproc-* firewall rules exposes the YARN UI / Spark History Server to the internet.
gcp ExposedToInternet derived
An IAM binding on a Firestore database naming 'allUsers' as a principal allows unauthenticated access to the database via the Cloud IAM / Admin SDK surface.
gcp ExposedToInternet explicit
Firebase Security Rules containing 'allow read, write: if true' (or equivalent unauthenticated-access rule) make the Firestore database readable/writable by any unauthenticated internet user via the Firebase client SDK.
gcp ExposedToInternet derived
VM with an ingress ALLOW from 0.0.0.0/0 AND an external IP is internet-exposed on that port - any unauthenticated actor can attempt to connect.
gcp ExposedToInternet derived
2nd-gen public invoke is governed by roles/run.invoker on the BACKING Cloud Run service's IAM policy, not the function resource.
gcp ExposedToInternet derived
artifacts bucket ACL grants allUsers storage.objects.get - GCR registry is publicly pullable without authentication, exposing embedded secrets and proprietary code.
gcp ExposedToInternet derived
A bucket IAM binding granting any read role to allUsers, or a publicRead/publicReadWrite predefined ACL (when UBLA is disabled), makes the bucket's objects accessible to unauthenticated internet principals.
gcp ExposedToInternet derived
A global or regional external forwarding rule with a public IP (loadBalancingScheme EXTERNAL or EXTERNAL_MANAGED) is reachable from the public internet on its configured port. IAP on backend services is an authentication layer but does not remove the internet-exposure fact.
gcp ExposedToInternet derived
allUsers or allAuthenticatedUsers granted pubsub.topics.publish on a topic makes it publicly writable; any internet caller can trigger bound push-subscription consumers via messaging-chains without project credentials.
gcp ExposedToInternet derived
allUsers/allAuthenticatedUsers bound to run.invoker on a service reachable from the internet.
gcp ExposedToInternet derived
A forwarding rule with loadBalancingScheme EXTERNAL and an assigned external IP exposes the backend service to the public internet.
gcp ExposedToInternet derived
An IAM binding granting roles/workflows.invoker to allUsers or allAuthenticatedUsers makes the workflow internet-invocable.
gcp ExposedToInternet derived
A resource exposed to the internet is reachable by any internet (anonymous) principal - the external network entry point that seeds internet-origin attack paths.
CanNetworkReach derived
move · open · esc close