K8s Attack Path Visualizer
A graph-based security analysis platform modeling Kubernetes clusters to discover hidden attack paths, blast radii, permission cycles, and critical chokepoints.
The Narrative
Developed a Python-based analysis engine that ingests Kubernetes manifests and builds a directed graph of trust and permissions using NetworkX.
Implemented core graph algorithms (Dijkstra, BFS, DFS) to identify shortest attack paths, calculate blast radius, and detect circular RBAC permission chains.
Built a FastAPI backend exposing a REST API and a TanStack Start/React frontend for interactive graph visualization and temporal snapshot management.
Integrated real-time CVE scoring from the National Vulnerability Database (NVD) to automatically enrich nodes with known vulnerabilities and penalize misconfigurations.
Tags
Links
System Highlights
Graph Analysis
Uses Dijkstra, BFS, and DFS to analyze trust boundaries, attack vectors, and permission cycles.
FastAPI Core
Python REST API powers analysis execution, risk scoring, and snapshot history management.
React UI
TanStack Start and ReactFlow deliver an interactive, visually rich security dashboard.
NVD Scoring
Dynamic integration with the National Vulnerability Database to assess real-world CVE risks.