LOZULA RDS Risk

Attack Path & Blast Radius Analysis

Model how a compromise can move across identity, social accounts, GitHub, cloud infrastructure, admin systems, domains, wallets and smart contracts — then identify the controls that break the chain.

Example attack chain
Identity → Infrastructure → Treasury
1
Email / SSO compromise
2
GitHub token exposure
3
Cloud role escalation
4
Admin control access
5
Wallet / contract privilege
Interactive RDS Risk v1

Model a connected digital environment

This simulator is an assessment model, not a live penetration test. Select the systems that exist in your environment, choose a likely compromise entry point, and compare how security controls change the modeled blast radius.

1. Select Assets

5 selected

2. Choose Compromise Entry Point

3. Security Controls

RDS Risk Coverage

One graph across Web2, cloud and Web3

RDS Risk is designed to connect security dependencies that are normally reviewed in separate tools.

Identity & Recovery

Email, SSO, MFA and recovery path exposure.

Cloud & Admin

IAM, privileged dashboards and infrastructure access.

Developer & Web3

GitHub, wallets, smart contracts and governance privilege.

AI & API Access

Agent, OAuth, API key and delegated action paths.

Frequently asked questions

What is attack path analysis?+

Attack path analysis models how an attacker could move from one compromised identity, account or system to other connected assets through permissions, recovery relationships, trust links or privileged access.

What does blast radius mean in cybersecurity?+

Blast radius describes how much of an environment could be affected after one asset is compromised. RDS Risk uses the connected systems you select to model that possible spread.

Does RDS Risk perform a live penetration test?+

No. The current public RDS Risk simulator is a risk-modeling experience. A real security assessment requires verified scope, authorized access and evidence from the client environment.

Can RDS Risk cover Web3 systems?+

Yes. The model is designed to include wallets, multisig roles, smart-contract administration, upgrade privileges and governance relationships alongside traditional identity and cloud systems.

Why connect email, cloud, GitHub and wallets in one model?+

Because real compromise chains can cross those boundaries. A weak recovery account can become a route into developer infrastructure, privileged systems or digital assets even when each component looks secure in isolation.

LOZULA Cybersecurity

See the breach path before it becomes a breach.

Use the simulator for an initial model, then request an authorized assessment when you need evidence-backed analysis of your real environment.

Request Assessment