Welcome to GuardiaGraph

Not configured yet Skip to Dashboard โ†’
1
Welcome
2
Company
3
Admin User
4
Assets
5
Data Sources
6
Results & Guide

๐Ÿ‘‹ Welcome to GuardiaGraph

GuardiaGraph maps your attack surface โ€” assets, identities, and vulnerabilities โ€” into a live graph of the paths an adversary could take to reach your Crown Jewels. This guided setup takes ~5 minutes and configures everything we need to start scoring risk.

๐Ÿ› ๏ธ What we'll set up together

๐Ÿข
1 ยท Your Company (Tenant)
Creates your isolated tenant workspace. All your data is encrypted and kept separate from other companies.
๐Ÿ‘ค
2 ยท Your Admin Account
Creates your login and signs you in. You'll manage everything from your dashboard.
๐Ÿ–ฅ๏ธ
3 ยท Your Assets
Register servers, workstations, cloud VMs and network devices โ€” then choose which ones we accept into the risk graph.
๐Ÿ”Œ
4 ยท Data Sources (Accept / Unaccept)
Decide which scanners (Qualys, CrowdStrike, etc.) we accept to pull data from and which we reject.

๐Ÿ” How the engine turns your data into answers

๐Ÿ“ฅ
1 ยท Ingest
Accepted data sources feed assets, CVEs, identities & flows
๐Ÿ•ธ๏ธ
2 ยท Graph Build
We construct a probabilistic attack graph in Neo4j
๐ŸŽฏ
3 ยท Score
Every endpoint gets a risk score 0โ€“100 + attack paths
โšก
4 ยท Act
Alerts, choke points & SOAR containment recommendations
๐Ÿ’ก

Where will I see results? After onboarding you'll get a live Dashboard (Crown Jewel exposure, top-risk endpoints, trends), a Risk Scores page, an interactive Attack Graph with the highest-probability adversary paths, and Alerts ranked by impact. Every page explains why something is risky โ€” you'll never see a number without an explanation.

๐Ÿข Tell us about your company

This creates your tenant โ€” a fully isolated workspace. Your company's data, scores, and configuration can never be seen by other GuardiaGraph customers.

๐Ÿ”

Why it matters: Multi-tenancy means row-level isolation in PostgreSQL, separate Neo4j graph namespaces, prefixed Kafka topics, and AES-256-GCM field encryption with a per-tenant key. You get the whole platform, but only your slice of it.

Company details

๐Ÿ‘ค Create your admin account

This is the account you'll use to sign in. As Admin you'll have full control of your tenant's configuration, assets, and integrations.

๐Ÿ›ก๏ธ

Why it matters: GuardiaGraph uses role-based access control (RBAC). Admin is the highest role โ€” it can configure integrations, run simulations, trigger containment, and invite teammates later from the dashboard.

Account details

๐Ÿ–ฅ๏ธ Register your assets

Add the endpoints that matter: servers, workstations, cloud VMs, containers, network devices. For each asset you choose to Accept โœ“ (include in the risk graph) or Exclude โœ— (keep it out โ€” e.g. lab / test systems).

๐Ÿ’ก

What "accept" means: Accepted assets become nodes in your attack graph and receive risk scores. Excluded assets are stored but never scored โ€” perfect for test environments, shadow IT you don't want analyzed yet, or assets you plan to decommission. Mark anything critical as a Crown Jewel (๐Ÿ”ฎ) so the engine focuses on protecting it.

โž• Add an asset

You can add more assets later from the dashboard.

๐Ÿ”Œ Data sources โ€” what do we accept?

GuardiaGraph can connect to your existing security tools. For each source you choose to Accept โœ“ (we pull data from it) or Unaccept โœ— (we ignore it). Unaccepted sources are not contacted and no data is stored from them.

๐ŸŽ›๏ธ

What this controls: Every scanner category feeds a different part of the model โ€” vulnerability scanners feed CVEs & CVSS/EPSS, EDR feeds endpoint telemetry, IAM / Identity feeds user accounts & MFA posture, CSPM feeds cloud misconfigurations, Threat Intel feeds CISA KEV & exploit probability. If you don't use a vendor, simply unaccept it โ€” you can change any decision later from Settings โ†’ Integrations.

Loading supported data sourcesโ€ฆ

๐Ÿ“ก Ingest options

How often we pull new data from accepted sources.
The format your SIEM/sensors push via POST /api/v1/ingest/*

๐ŸŽ‰ Your workspace is ready!

Here's everything that was configured, and a plain-English guide to how GuardiaGraph will show you results.

๐Ÿข
โ€”
Company
๐Ÿ‘ค
โ€”
Admin Account
๐Ÿ–ฅ๏ธ
0
Assets
๐Ÿ”Œ
0
Data Sources Accepted

๐Ÿ†” Your identifiers

Tenant ID
โ€”
Signed in as
โ€”

๐Ÿ–ฅ๏ธ Assets registered (0)

Loadingโ€ฆ

๐Ÿ”Œ Data source decisions

Loadingโ€ฆ

โšก Make your dashboard live right now

Skip the wait for your first sync โ€” load a realistic sample environment (12 endpoints, 16 CVEs, 18 network pivots, crown jewels, alerts) and run the full scoring engine immediately. Your Risk Scores, Heatmap, Attack Graph, Alerts and Executive Dashboard will be fully populated the moment you click Open.

Works alongside your own assets โ€” additive, never destructive.

๐Ÿ“– Understand your results โ€” explained

The engine connects every accepted asset, identity, and vulnerability into a graph. It then computes the most probable adversary paths toward your Crown Jewels using probabilistic scoring (identity surface ร— vulnerability surface ร— network adjacency ร— crown-jewel proximity).

  • Nodes = assets, identities, vulnerabilities.
  • Edges = reachable pivots, each with a probability of being used.
  • Highlighted paths = the highest-probability routes โ€” see them in the Attack Graph page.
๐Ÿ“Š Where to see it: Menu โ†’ Attack Graph. Select a Crown Jewel to see its top attack paths ranked by probability.

Every node gets a composite risk score combining node risk (CVEs, exploitability), choke score (how many paths converge here), local exposure, and proximity to Crown Jewels.

  • 85โ€“100 Critical โ€” likely on an active attack path; act now.
  • 70โ€“84 High โ€” high exposure, prioritize this week.
  • 40โ€“69 Medium โ€” monitor and schedule remediation.
  • 0โ€“39 Low โ€” healthy posture.
๐Ÿ“Š Where to see it: Menu โ†’ Risk Scores (card grid + ranked list) and Dashboard. Click any card to see the factor breakdown โ€” each score line shows why.

Crown Jewels are your most critical assets (finance DBs, domain controllers, IP vaults). We compute a Crown Jewel Exposure Score โ€” the probability-weighted likelihood that an attacker reaches a Crown Jewel from any starting point.

  • Mark assets as Crown Jewels by setting sensitivity to Critical (or the ๐Ÿ”ฎ toggle while adding).
  • The exposure score trend appears on the Executive Dashboard โ€” dropping it is the goal of every remediation.
๐Ÿ“Š Where to see it: Dashboard โ†’ Crown Jewel Exposure Score (current + 30-day trend).

Raw events are rationalized: each is scored by computed criticality ร— crown-jewel impact. Incomplete data is never silently suppressed โ€” it's flagged Needs Review. Expect ~85% noise reduction versus raw SIEM alerts.

๐Ÿ“Š Where to see it: Menu โ†’ Alerts. Each alert shows its impact score and recommended action.

SOAR Playbooks auto-generate ranked containment runbooks (patch, isolate, revoke, segment) for compromised assets, exportable to XSOAR, Splunk SOAR, or Sentinel. Simulation lets you test "what if we patch X and revoke Y?" and see the risk reduction before deploying.

๐Ÿ“Š Where to see it: Menu โ†’ SOAR Playbooks and Simulation.

If you use your own pipelines, push normalized events directly:

  • POST /api/v1/ingest/logs โ€” JSON events
  • POST /api/v1/ingest/cef โ€” CEF syslog
  • POST /api/v1/ingest/syslog โ€” raw syslog with CVE tokens
  • GET /api/v1/discovery/setup-script/linux|windows โ€” agent scripts for remote discovery
๐Ÿ” All ingest calls are authenticated with your Bearer token and scoped to your tenant.
  • Now: accepted data sources sync on the schedule you chose (default hourly).
  • +1 sync: assets, CVEs, identities flow in โ†’ the engine builds your first attack graph.
  • After build: risk scores, heatmap, choke points, and dashboard metrics appear.
  • Ongoing: daily scoring, real-time updates via WebSocket, and Kafka-streamed change events keep everything current.
๐Ÿ’ก Tip: import vulnerabilities from Inventory โ†’ Vulnerabilities and identities from Inventory โ†’ Identities to make scores meaningful immediately โ€” you can also run a demo seed from the admin panel.