ExposedToInternet

Target is reachable/abusable from the public internet - common attack entry point (incl. a queue/topic/API with a public/wildcard resource policy).

network NETWORK nature: derived walkable weight 1 high value
Compute, Data, PublicEndpoint, LoadBalancer, Storage, Messaging, DNS  ── ExposedToInternet ──▸  AnonymousIdentity

Source types

ComputeDataPublicEndpointLoadBalancerStorageMessagingDNS

Target types

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

naturederived

Rules that emit ExposedToInternet 87

A REST API resource policy with Principal '*' and no VPC/IP restriction makes the API internet-callable.
awsderived
WebServer-tier environments front instances with an internet-facing ELB by default.
awsderived
A Deployed CloudFront distribution is publicly reachable from the internet on its *.cloudfront.net domain (and any custom CNAME aliases).
awsderived
A DocumentDB cluster with PubliclyAccessible=true and a VPC security group permitting inbound TCP 27017 from 0.0.0.0/0 or ::/0 is network-reachable from the public internet. Valid MongoDB credentials (obtained via credential-grab paths) enable connection without VPC foothold.
awsderived
A principal with ec2:ModifySnapshotAttribute can make a snapshot world-readable (any AWS account can CreateVolume from it).
awsderived
A public ECR repository is pull-accessible to any user on the internet without authentication, enabling supply-chain poisoning by external/anonymous attackers.
awsderived
An EventBridge custom bus policy granting events:PutEvents to Principal '*' is publicly writable; any internet actor can inject events and potentially trigger compute consumers.
awsderived
A DEPLOYED Global Accelerator with anycast IPs enabled is internet-reachable. This rule derives the exposure fact from the normalizer's structural Accelerator node.
awsderived
Function URL with AuthType NONE + public resource policy is internet-invocable.
awsderived
An Amazon MQ broker with PubliclyAccessible=true is reachable from the internet over wire-protocol ports; obtaining broker credentials is sufficient to publish messages and trigger bound Lambda consumers.
awsderived
An MSK cluster with publiclyAccessible enabled and an open broker security group (port 9198 from 0.0.0.0/0) is internet-reachable; IAM or SASL/SCRAM authentication still required.
awsderived
Neptune cluster snapshot with public restore attribute (restore=all) is exposed to the internet via CrossAccountTrust to external Account.
awsderived
Neptune DB instance with a public endpoint, permissive security group (port 8182/8183/8184 from 0.0.0.0/0), and IAM database authentication disabled is accessible from the internet without any credential.
awsderived
OpenSearch domain with a public endpoint and Principal:* access policy is reachable from the internet; unauthenticated if FGAC is also disabled.
awsderived
A Redshift cluster or Serverless workgroup with PubliclyAccessible=true and a permissive VPC security group is reachable from the public internet on port 5439.
awsderived
A dangling alias or CNAME record pointing to a deprovisioned AWS resource enables subdomain takeover - an attacker (unauthenticated, from the internet) claims the deprovisioned resource and serves content on the hijacked name without any AWS IAM permission required.
awsderived
S3 bucket with a Principal:* bucket policy allowing s3:GetObject and Block Public Access disabled (RestrictPublicBuckets=false) is readable by any internet client.
awsderived
s3:PutBucketAcl on a bucket with ObjectOwnership != BucketOwnerEnforced and Block Public Access IgnorePublicAcls=false enables ACL-based public exposure.
awsderived
S3 static website hosting publishes a public HTTP endpoint serving bucket objects, independent of the bucket policy's API access controls.
awsderived
s3:PutBucketPublicAccessBlock + s3:PutBucketPolicy enables a two-step escalation to expose the bucket - attacker CAN expose the bucket but it is NOT currently exposed.
awsderived
An SNS topic access policy granting sns:Publish to Principal '*' is internet-accessible - anyone can publish and trigger all subscribers.
awsderived
An SQS queue with Principal:* granting sqs:SendMessage (no condition) is publicly writable; any unauthenticated sender can trigger bound Lambda consumers via messaging-chains.
awsderived
A compute resource is internet-exposed when its security group has an inbound rule allowing 0.0.0.0/0 (or ::/0) on a port, the resource has a public IP, and the subnet has a route to an Internet Gateway. All three conditions must be observed facts.
awsderived
Container group with a public IP and exposed ports.
azurederived
anonymousPullEnabled == true on a registry makes image pull accessible to any unauthenticated client from the internet.
azurederived
ADLS Gen2 account with public blob access enabled and a public container exposes blob data to unauthenticated internet access.
azurederived
App Service site reachable from the public internet on its default/custom hostname or scm endpoint.
azurederived
An enabled Automation Account webhook with a public URI is internet-triggerable; any holder of the URI can start a runbook job.
azurederived
Container App with external ingress and no denying IP restrictions.
azurederived
Cosmos DB account with no IP firewall and public network access enabled exposes its data-plane endpoint to the internet - any caller with a valid token can reach it.
azurederived
Databricks workspace REST API endpoint is publicly reachable; any token/PAT holder can authenticate from the internet.
azurederived
An ADF factory with publicNetworkAccess=Enabled exposes its REST data-plane endpoint (adfstudio.azure.com + management.azure.com) to the internet.
azurederived
A CNAME or A/AAAA alias DNS record in a public Azure DNS zone pointing to a deprovisioned Azure resource enables subdomain takeover: an external attacker can claim that resource name and inherit DNS resolution for the dangling hostname.
azurederived
An Event Grid custom topic with publicNetworkAccess=Enabled is internet-accessible for event publishing (any holder of the topic key can publish from the internet).
azurederived
An Event Hubs namespace with no IP/VNet network restrictions and publicNetworkAccess not Disabled is internet-reachable; any holder of SAS or Entra data-plane credentials can access it from the internet.
azurederived
When an Azure Firewall has active DNAT rules and a public IP allocated, resources translated by those rules are exposed to the internet via the firewall's public endpoint. This is emitted as internet exposure on the firewall node itself (as a Network class that has public reachability).
azurederived
An enabled Azure Front Door endpoint (*.azurefd.net or a custom domain) is reachable from the public internet by design - AFD uses Microsoft's global anycast infrastructure; no explicit public IP is required on the profile. This is derived from the explicit normalization rule azure-frontdoor-endpoint-record.
azurederived
A Function app with a public hostname and an anonymous-auth HTTP trigger.
azurederived
Function app SCM/app surface reachable publicly (used with a held key or exploitable code).
azurederived
A Standard Load Balancer with a public frontend IP is reachable from the internet on its listener ports.
azurederived
An Application Gateway with a public frontend IP accepts HTTP/HTTPS traffic from the internet on its listener ports.
azurederived
A Logic App with a public HTTP (Request) trigger and no IP allowlist is triggerable from the internet.
azurederived
AML workspace with publicNetworkAccess=Enabled exposes its management REST API to the internet - any token holder can reach it.
azurederived
AML online endpoint with a public HTTPS URL and key-based auth is reachable from the internet; the scoring key is retrievable via listkeys.
azurederived
An NSG effective inbound Allow rule from Internet/0.0.0.0/0 on a service port, combined with a public IP (or internet-facing LB) on an attached resource, makes that resource internet-reachable: ExposedToInternet.
azurederived
PostgreSQL/MySQL Flexible Server with publicNetworkAccess Enabled and an internet-wide firewall rule exposes the DB endpoint to the public internet.
azurederived
Cache for Redis with publicNetworkAccess=Enabled and no IP firewall rules exposes the Redis data-plane port 6380 (SSL) to the public internet.
azurederived
A firewall rule allowing 0.0.0.0–255.255.255.255 explicitly exposes the Redis data-plane endpoint to the entire public internet.
azurederived
Cache with authnotrequired=true and publicNetworkAccess=Enabled allows anonymous internet access to the Redis data-plane with full commands.
azurederived
A Service Bus namespace with publicNetworkAccess=Enabled and no restrictive IP filter is reachable from the internet; any holder of a valid SAS key or Entra token can connect from any IP.
azurederived
SF cluster gateway (19000 FabricGateway / 19080 FabricHttpGateway+SFX) fronted by a public LB with a permissive NSG.
azurederived
SQL logical server with publicNetworkAccess=Enabled and a 0.0.0.0–255.255.255.255 firewall rule is reachable from the public internet on port 1433.
azurederived
SQL Managed Instance with publicDataEndpointEnabled=true and an NSG allowing inbound TCP 3342 from the internet is reachable by any internet host.
azurederived
Storage account with public blob access enabled and a public container exposes blob data to unauthenticated internet access.
azurederived
Synapse workspace development, SQL, and Spark endpoints are public-internet reachable when publicNetworkAccess is Enabled and no private-endpoint-only restriction is applied.
azurederived
VM with a public IP and an NSG rule allowing an inbound port.
azurederived
A compute resource or load balancer with a public IP AND an NSG rule that allows inbound Internet/0.0.0.0/0 on a port is internet-exposed.
azurederived
A CNAME or alias DNS record (in a public zone) pointing to a deprovisioned Azure resource enables subdomain takeover: an attacker can claim the target resource and inherit DNS resolution for the dangling name.
azurederived
A serving App Engine version is reachable at its appspot.com URL (modeled as a PublicEndpoint node) unless ingress-restricted.
gcpderived
A CNAME (or ALIAS) resource record set in a public Cloud DNS zone whose target resolves to a GCP-managed FQDN suffix that no longer has a backing resource in collected GCP inventory enables subdomain takeover: an external attacker can claim that resource name and inherit DNS resolution for the dangling hostname.
gcpderived
allUsers/allAuthenticatedUsers bound to run.invoker on a service reachable from the internet.
gcpderived
cloudsql.instances.update can enable public IP (ipv4Enabled=true) and add 0.0.0.0/0 to authorizedNetworks, making the instance internet-reachable from any network.
gcpderived
A Cloud SQL instance with a public IP (ipv4Enabled=true) and an authorized network of 0.0.0.0/0 is TCP-reachable from the internet on the DB port, exposing it to unauthenticated network-level attack (brute-force, known CVEs).
gcpderived
Airflow web server in Composer 2 environment is internet-accessible when config.webServerNetworkAccessControl.allowedIpRanges includes 0.0.0.0/0.
gcpderived
Dataproc cluster master VM with a public IP and permissive dataproc-* firewall rules exposes the YARN UI / Spark History Server to the internet.
gcpderived
Firebase Security Rules containing 'allow read, write: if true' (or equivalent unauthenticated-access rule) make the Firestore database readable/writable by any unauthenticated internet user via the Firebase client SDK.
gcpderived
VM with an ingress ALLOW from 0.0.0.0/0 AND an external IP is internet-exposed on that port - any unauthenticated actor can attempt to connect.
gcpderived
2nd-gen public invoke is governed by roles/run.invoker on the BACKING Cloud Run service's IAM policy, not the function resource.
gcpderived
artifacts bucket ACL grants allUsers storage.objects.get - GCR registry is publicly pullable without authentication, exposing embedded secrets and proprietary code.
gcpderived
A bucket IAM binding granting any read role to allUsers, or a publicRead/publicReadWrite predefined ACL (when UBLA is disabled), makes the bucket's objects accessible to unauthenticated internet principals.
gcpderived
A global or regional external forwarding rule with a public IP (loadBalancingScheme EXTERNAL or EXTERNAL_MANAGED) is reachable from the public internet on its configured port. IAP on backend services is an authentication layer but does not remove the internet-exposure fact.
gcpderived
allUsers or allAuthenticatedUsers granted pubsub.topics.publish on a topic makes it publicly writable; any internet caller can trigger bound push-subscription consumers via messaging-chains without project credentials.
gcpderived
A forwarding rule with loadBalancingScheme EXTERNAL and an assigned external IP exposes the backend service to the public internet.
gcpderived
An IAM binding granting roles/workflows.invoker to allUsers or allAuthenticatedUsers makes the workflow internet-invocable.
gcpderived
DocumentDB cluster snapshot is publicly restorable (restore attribute contains 'all') via rds:DescribeDBClusterSnapshotAttributes.
awsexplicit
gcpexplicit
An IAM binding on a Firestore database naming 'allUsers' as a principal allows unauthenticated access to the database via the Cloud IAM / Admin SDK surface.
gcpexplicit
A dataset ACL entry for allUsers makes it queryable by unauthenticated public principals - internet-accessible data.
gcpexplicit
move · open · esc close