GEIGER 2.0 · Available August 1, 2026

    Stop Counting Vulnerabilities. Start Cutting Attack Paths.

    GEIGER — unified attack path management across AD, Azure, AWS, GCP, Okta, and Kubernetes.

    Most organizations carry more open vulnerabilities than they could patch in a decade. Attackers don't work from a list — they chain one weak password, one misconfiguration, and one forgotten trust relationship into a straight line to the crown jewels.

    GEIGER maps the paths, not the pile. It unifies your identities into a single living graph of how an attacker could move, then finds the choke points that break the most attack paths at once.

    Request Attack Path Assessment
    GEIGER 2.0 attack path view: four hops from a foothold to Domain Admin, with risk scoring and CISA KEV flags

    New in GEIGER 2.0

    The attack-path platform now pairs live exploit intelligence with sensors that reach any network, so teams fix the few things that actually stop a breach.

    Live exploit intelligence

    Every finding is scored against CISA's Known Exploited Vulnerabilities catalog and EPSS, so what attackers are using right now rises to the top.

    Choke points

    See the handful of fixes that close the most attack paths at once — the one wire to cut instead of a to-do list.

    Sensors that reach anywhere

    Deploy inside any network in minutes, connect outbound only, and keep collecting through an internet outage without ever losing data.

    Isolated for each customer

    Every customer's data lives in its own database and graph, so a provider can run a whole book of business from one console.

    Your Tools Don't Talk to Each Other

    A compromised service account in Azure with lateral movement paths to on-prem Domain Admins? That requires correlating data from at least three different tools.

    By the time you've exported, normalized, and cross-referenced the data, an attacker has already completed the attack chain.

    GEIGER sees the complete picture.

    Find Every Path to Your Crown Jewels

    GEIGER identifies all attack paths to your most critical assets. 50+ pre-built queries. One click to see every user, group, or service account with a path to Domain Admins, Azure Global Admin, or your custom high-value targets.

    Kerberoasting & ASREPRoasting paths
    ADCS ESC1-13 vulnerabilities
    Delegation abuse chains (unconstrained, constrained, RBCD)
    DCSync exposure
    Cross-domain trust abuse
    Azure privilege escalation (Global Admin, KeyVault, VM contributor)
    Shadow credentials (msDS-KeyCredentialLink)
    Session-based attacks
    Live Exploit Intelligence

    The paths attackers can actually use, first

    Every finding along a path is scored against CISA's Known Exploited Vulnerabilities catalog and EPSS. GEIGER flags the hosts and CVEs that attackers are exploiting right now, so a path that traverses an exploitable host outranks one that only looks bad on paper.

    • CISA KEV catalog matching on every finding
    • EPSS exploit-probability scoring
    • Paths through exploitable hosts scored highest

    Why this path scores 91

    Traverses an exploitable host (KEV / CVSS ≥ 9)

    CVE-2020-1472KEVT1558T1078.002

    Blast Radius Analysis

    What happens if this account is compromised? GEIGER calculates the blast radius instantly. See every asset reachable from any starting point, the maximum depth of the attack chain, and which high-value targets are at risk.

    • Impact score calculation
    • Total assets in blast radius
    • Critical assets at risk
    • Maximum attack depth
    • High-value target identification
    GEIGER 2.0 blast radius: everything a single compromised account can reach, with impact score and crown jewels
    Choke Points

    Cut the One Wire

    Not every fix matters equally. GEIGER ranks the choke points — the changes that eliminate the most attack paths at once — so a handful of fixes can remove the majority of your exposure. Apply them top-down and watch the cumulative percentage of paths removed climb.

    The old way asked how much you could find. GEIGER asks how little you have to fix.

    GEIGER 2.0 choke points: prioritized fixes ranked by how many attack paths each one removes

    Complete Identity Visibility

    Identity data from across your entire environment, unified in a single graph database.

    Active Directory

    • Users, Groups, Computers, OUs, GPOs
    • Trusts, ACLs, Kerberos delegation
    • ADCS certificates

    Azure / Entra ID

    • Users, Groups, Service Principals
    • Applications, Roles, Devices
    • Subscriptions

    AWS IAM

    • Users, Roles, Policies
    • Trust relationships
    • EC2 instances, KMS keys

    GCP IAM

    • Service Accounts, Roles
    • IAM Bindings, Projects
    • Compute resources

    Okta

    • Users, Groups, Applications
    • MFA status, API tokens

    Kubernetes

    • Service Accounts, Roles
    • RoleBindings, ClusterRoles
    • Namespaces

    Risk-Based Prioritization

    Not all attack paths are equal. GEIGER's risk scoring considers:

    • Exploit intelligence - CISA KEV and EPSS on every finding
    • Path length - Shorter paths are more exploitable
    • Edge types - DCSync is worse than CanRDP
    • Target criticality - Domain Controllers vs workstations
    • Source context - Paths from compromised accounts are urgent
    • Business impact - Test server vs payment systems

    The result: A prioritized list of what to fix first, not 10,000 equally-weighted findings.

    Privilege Zone Enforcement

    Define your security boundaries:

    • Admin Zones - who should have elevated access
    • Production Zones - which identities can touch production
    • Staging/Dev Zones - environment separation
    • Custom Zones - your own boundaries

    When an identity violates zone boundaries, GEIGER alerts immediately.

    Sensors that reach anywhere

    GEIGER sensors deploy inside any network in minutes and connect outbound only — no inbound firewall changes. They keep collecting through an internet outage and forward everything once connectivity returns, so you never lose data from air-gapped or unreliable segments.

    Isolated for each customer

    Every customer's data lives in its own database and graph. Providers and MSSPs can run a whole book of business from a single console, with strict tenant isolation at the data layer — no commingling, no cross-tenant leakage.

    More Than 50 Integrations

    Connect GEIGER to your existing tools across cloud, endpoint, identity, and vulnerability management — with prioritized findings pushed back to SIEM, ticketing, and chat.

    CloudEndpointIdentityVulnerabilitySIEMSOARTicketingAlerting

    Remediation That Drives Action

    Findings don't sit in a dashboard. GEIGER drives action.

    Step-by-Step Guidance

    Remediation instructions for every finding type

    Jira & ServiceNow

    Automatic ticket creation and tracking

    Verification

    Track from open to verified-fixed

    Risk Acceptance

    Workflows with automatic expiry

    Posture Trending

    Prove security improves over time

    Full API Access

    200+ REST API endpoints

    Technical Architecture

    Graph database
    Outbound-only sensors
    CISA KEV + EPSS scoring
    Multi-tenant isolation
    Async job processing
    RBAC (Admin, Analyst, Viewer)
    Full audit logging
    200+ REST API endpoints
    BloodHound import/export
    MITRE ATT&CK mapping

    Frequently Asked Questions

    What's new in GEIGER 2.0?

    GEIGER 2.0 adds live exploit intelligence (findings scored against CISA KEV and EPSS), choke-point analysis that shows the fewest fixes needed to close the most attack paths, sensors that deploy inside any network in minutes and keep collecting through an internet outage, and full per-customer data isolation for multi-tenant providers.

    What are choke points?

    Choke points are the fixes that break the largest number of attack paths at once. Instead of a list of 10,000 equally-weighted findings, GEIGER shows you the handful of changes that remove most of your exposure — the one wire to cut.

    How does GEIGER use CISA KEV and EPSS?

    Every finding is scored against CISA’s Known Exploited Vulnerabilities catalog and the EPSS exploit-probability model, so vulnerabilities that attackers are actively using rise to the top of your prioritized list.

    What is attack path management?

    Attack path management maps the routes an attacker could take from initial access to your most critical assets. GEIGER visualizes these paths across AD, Azure, AWS, GCP, Okta, and Kubernetes in a single graph.

    How is GEIGER different from BloodHound?

    GEIGER unifies identity data from six platforms in one graph database with 50+ pre-built queries, live exploit intelligence, risk-based prioritization, choke-point analysis, and remediation workflows including Jira and ServiceNow integration.

    Does GEIGER require endpoint agents?

    No. GEIGER uses distributed sensors that connect to your identity providers and cloud platforms via API. Sensors deploy in minutes, connect outbound only, and require no endpoint agents.

    See Your Attack Paths

    Schedule a demo to see how GEIGER maps your identity infrastructure, scores it with live exploit intelligence, and shows you the choke points that close the most attack paths.

    Request Attack Path Assessment