Prioritize cloud risk by attack path
A rule starts with a base score from 0 to 100. Graph context adds points, then the total is
capped at 100 and mapped to a severity label. CVE enrichment uses CVSS from NVD and stores a
normalized severity on the finding. The two paths share the Finding node type.
Graph context
For each matched resource the engine computes:
internet_reachable— a walk frominternet:globalcan reach the nodepath_to_datastore— the node sits on an internet → workload → datastore pathadmin_can_access— set by the built-in admin-datastore rule when an admin identity hasCAN_ACCESS
| Signal | Added to base score |
|---|---|
| Internet reachable | +10 |
| On a path to a datastore | +25 |
| Admin can access | +5 |
A public datastore rule with base 70 that also sits on an internet-to-datastore path scores 70 + 25 = 95 and is labeled critical. If that node is also internet-reachable, the same rule scores 70 + 10 + 25 = 105, then the cap brings it back to 100. The same rule on an isolated bucket stays at 70 (high). The admin-datastore rule adds its +5 on top of whatever the walk already found.
The finding description appends a short reason when a path or internet signal is present.
A path to a datastore replaces the internet-only sentence. admin_can_access
changes the score and does not add its own sentence.
CVE enrichment does not use this table. It stores the NVD-normalized score unchanged, so a critical CVE on a private workload ranks the same as the same CVE on an exposed one. Use CSPM rules, or the path queries, when the question is whether an outsider can reach the resource. See CVE enrichment.
Severity bands
| Score | Severity |
|---|---|
| 90–100 | critical |
| 70–89 | high |
| 50–69 | medium |
| 30–49 | low |
| 0–29 | info |
What gets stored
Each match upserts a finding node finding:{rule-id}:{resource-id} and a
VIOLATES edge to the resource. Properties include finding_type
(cspm), rule_id, title, description,
severity, normalized_score, graph_context, and
affected_resource. Re-running a rule updates that row. It does not append a
second finding for the same rule and resource.
The console and GET /v1/findings list findings with the affected resource’s name
and type. The API orders them by normalized_score, highest first, and the console
shows that order.
The attack-path rule does not use this table. It copies
normalized_score from the finding already on the workload and maps that score
through the bands above. A source with no score is stored as 75 (high). See
Attack paths.
Questions
How does OpenSourceOM prioritize findings?
Each CSPM rule starts with a base score. Internet reachability adds 10, a path from the internet to a datastore adds 25, and admin access adds 5. The total is capped at 100.
Does a critical CVE always rank first?
CVE findings store an NVD-normalized score and do not add attack-path points. CSPM findings do. A public datastore on a path to data can outrank a critical CVE that was attached without graph context.
Related reading
Copyright © 2026 OpenSourceOM. Licensed under Apache-2.0.