Skip to main content

Analyzer Groups

Analyzer groups organize related analyzers into security domains. Each group represents a distinct area of security posture — cloud infrastructure, data stores, application pipelines, or AI systems — and provides its own dashboard, risk score, and insight feed.


Groups

GroupDomainWhat it covers
CSPMCloud Security Posture ManagementCloud infrastructure misconfigurations, IAM risks, network exposure, compliance across AWS, Azure, and GCP
DSPMData Security Posture ManagementDatabase access, storage encryption, sensitive data exposure across cloud storage and database services
ASPMApplication Security Posture ManagementCode vulnerabilities, SBOMs, secrets, IaC misconfigurations, CI/CD pipeline security
AISPMAI Security Posture ManagementAI model security, agent permissions, prompt vulnerabilities, training data integrity

Each group has its own:

  • Security Risk Score (0-100 gauge) calculated from active analyzers within the group
  • Insight Map showing findings across its analyzers
  • Overview dashboard with group-specific KPI metrics

Analyzers Within Groups

Analyzers are assigned to groups based on their security domain. A single group can span multiple cloud providers — for example, CSPM includes AWS IAM, Azure IAM, and GCP IAM.

CSPM Analyzers

AnalyzerCloudFocus
AWS IAMAWSIAM users, roles, policies, MFA
Azure IAMAzureAzure AD roles and access
GCP IAMGCPService accounts, IAM bindings
AWS ComputeAWSEC2, ECS, Lambda security
GCP ComputeGCPCompute Engine instances
AWS NetworkAWSVPCs, security groups, NACLs
Azure NetworkAzureVNets, NSGs, DNS
GCP NetworkGCPVPCs, firewall rules
KubernetesMultiCluster state, RBAC, pod security
AWS StreamingAWSKinesis, streaming infrastructure
Azure StreamingAzureEvent Hubs, streaming security

DSPM Analyzers

AnalyzerCloudFocus
AWS StorageAWSS3 buckets, EBS volumes
Azure StorageAzureStorage accounts, containers
GCP StorageGCPCloud Storage buckets
DatabaseMultiDirect database environments
AWS RDSAWSRDS instances, encryption
Azure DatabaseAzureSQL Database, Cosmos DB
GCP DatabaseGCPCloud SQL, Spanner

ASPM Analyzers

AnalyzerFocus
Code SecuritySAST findings, code vulnerabilities
ApplicationApplication-level security posture
SCADependency vulnerabilities, SBOM
ArtifactContainer image and build artifact security
IaCTerraform, CloudFormation misconfigurations
RepositoryBranch protection, unsigned commits
Secrets & PIIHardcoded secrets, sensitive data in code
GCP DevOpsGCP-specific DevOps security

AISPM Analyzers

AnalyzerFocus
AI IAMOverprivileged tokens, agent permissions
AI SASTInsecure AI code patterns, exposed prompts
AI DASTPrompt injection, jailbreak testing
Azure AIAzure Cognitive Services, OpenAI security
GCP AIVertex AI, Model Garden security

Active Analyzers

An analyzer is active within a group only if a blueprint account is configured for it. For example:

  • If you only have an AWS blueprint configured, the CSPM group score is based solely on AWS IAM, AWS Compute, and AWS Network
  • Adding an Azure blueprint automatically activates Azure IAM, Azure Network, and Azure Streaming within CSPM

This means analyzer groups adapt to your environment — you only see scores and insights for the platforms you actually use.


Group Risk Scores

Each group has a 0-100 security risk score calculated from its active analyzers. The weight of each analyzer is determined dynamically by the number and severity of its enabled insight rules. See each domain page for details: