CIEM
Cloud Identity & Access
Privilege is a path. Treat unused keys like open doors.
10ETLabs identity coverage is AWS-first: IAM users and roles are inventoried next to the data and compute they can reach. Findings flag root access keys, missing MFA, and admin wildcards — then 10ET Score raises anything that is also internet-facing. On Azure, Entra ID users, groups, service principals, managed identities and app registrations are inventoried through read-only Microsoft Graph permissions, and every Azure role assignment is resolved into effective permissions: inherited from management groups and subscriptions, expanded through groups, custom roles evaluated with their notActions, minus deny assignments. Findings flag guest and service-principal admins, admins with no MFA policy, too many permanent Global Administrators, stale privileged accounts, long-lived or expiring app secrets, and service principals that can change or grant access to whole subscriptions. GCP service accounts are inventoried and flagged when they hold project Owner or Editor or have user-managed keys older than 90 days.

CIEM
AWS identities next to the data they can reach. Standing admin scores higher when it is also public.
See it work
Every cloud’s findings, one ranked queue
Findings from each provider share one shape, then 10ET Score orders them by exposure and blast radius.
Many clouds · one ranked queue
01Scan each cloud
Posture jobs list each connected provider’s control plane with its reader role or token — AWS deepest, then Azure, GCP, and Kubernetes.
Sample findings using real rule titles. Scores follow the 10ET Score formula.
What you get
Human and machine in one list
AWS IAM users and roles, Entra ID users, groups, service principals and managed identities, and GCP service accounts are assets in the same inventory, not a sidecar identity product.
Privilege that matters
Wildcard administrators and keys without MFA are scored higher when they sit on a path to public data or AI endpoints.
Effective Azure permissions
For every Azure principal the Identity tab shows why it can do something: group → role → scope, with what the role allows (manage resources, assign roles, write blob data, read Key Vault secrets). Managed identities link to the VM or AI service they run on, so attack paths follow them.
Same RBAC as the rest of the console
VIEWER can read. ANALYST can update finding status. OWNER and ADMIN connect accounts. No silent “everyone is admin.”
In this module
Step 1
List human and machine
AWS IAM users and roles, Entra ID principals and GCP service accounts become inventory assets.
Step 2
Flag standing admin
Root keys, missing MFA, and * on * land as identity findings — not a sidecar IdP product.
Step 3
Open Identity
Trace the finding to the linked asset and path, and expand an Azure principal to see the assignment chain behind its access.
In this release
- Identity inventory and high-signal posture rules
- Azure Entra ID principals, directory roles with PIM and Conditional Access MFA checks
- Effective Azure RBAC permissions per principal
- Scoring with exposure and admin flags
On the roadmap
- Unused-key detection
- Effective permissions for AWS and GCP
- Just-in-time access recommendations
Labeled roadmap for this module only. Site-wide scope is on Trust and FAQ.
More of the platform
Other modules — not a reprint of this page.
AI security
AI workload security
Trace attack paths to models and agents on SageMaker, Bedrock, Azure AI Foundry and Vertex AI — exposed notebooks, public training data, model weights anyone can swap, retrieval sources fed from public buckets, and workload identities with admin rights.
Code security
Agentless code-to-cloud security
Check Terraform, CloudFormation, ARM, and Kubernetes YAML against built-in pattern rules — in the console or on every pull request — then see the same risk classes on live AWS, Azure, GCP, Kubernetes, and other VPS.
CSPM
Cloud Security Posture Management
Misconfiguration and identity-risk checks across AWS, Azure, GCP, Kubernetes, and other VPS — AWS-first, re-checked on every scan you run or schedule.
CWPP
Cloud Workload Protection
Inventory VMs, Lambda functions, and hosts from the control plane, and look inside VM disks with opt-in, agentless DeepScan.
Containers
Container & Kubernetes Security
EKS, AKS, and any Kubernetes API you connect, ECR scan-on-push, and public services in one queue — agentless by default, with an optional sensor for runtime evidence and deploy-time blocking.
Compliance
Cloud Compliance Monitoring
CIS, SOC 2, PCI DSS, HIPAA, ISO 27001, NIST CSF, FedRAMP, GDPR, DPDP, an AI workload baseline, and your own frameworks — mapped to live findings, with signed evidence packs for auditors.
Vulnerabilities
Cloud Vulnerability Management
ECR scan-on-push gaps from the control plane, plus package CVEs from opt-in DeepScan or the optional host sensor, prioritized by blast radius.