Exposure Analysis

Last Updated: September 28, 2026
Estimated Reading Time: 4 minutes

Overview

Exposure Analysis shows what else a CI can reach through CMDB relationships. Use it when a CI is compromised, misconfigured, or under a security or tabletop review.

Exposure Analysis and the Blast Radius Simulator answer different questions:

Blast Radius (outage)Exposure Analysis
QuestionIf this CI fails, what depends on it?If this CI is compromised, what is connected to it?
DirectionFrom the CI to its dependentsBoth directions
RelationshipsOnly outage-propagating relationshipsAll normalized relationships, including relationships that do not carry outage impact

The two modes use separate, versioned relationship rules. The same CI usually gives different counts in each mode.

Exposure Analysis shows CMDB relationship reachability. It does not verify network paths, identity permissions, or an exploit path. Use it to scope a review, not to prove that an attack is possible.

How to Run Exposure Analysis

  1. Go to Dependency Map.
  2. Find the CI. Use search or the map.
  3. Right-click the CI.
  4. Select Exposure Analysis.
  5. Review the results in the Exposure Analysis side panel.

Exposure Analysis runs against the current CMDB mirror. If Time Machine shows historical topology, return to live topology first.

Results

  • Direct exposure is one relationship level from the selected CI.
  • Indirect exposure is reached through more levels.
  • The map shows only the CIs that connect to the selected CI through the returned relationships.
  • Exposure Analysis Evidence shows the paths, the included relationships, the excluded relationships, and the limits of the analysis.

Like the Blast Radius Simulator, Exposure Analysis reports evidence confidence and completeness. Stale topology or an early stop lowers confidence.

How to Export Results

  1. Run Exposure Analysis.
  2. Select Export PDF or Export CSV.

CMDBx creates the export from the saved result. The export does not run the analysis again.

How to Use Exposure Analysis

Security Incident Scoping

  1. Run Exposure Analysis on the affected CI.
  2. Review the direct exposure first.
  3. Share the CSV with the security team to scope the investigation.

Tabletop Exercises

  1. Select a critical CI, for example an identity provider or a shared database.
  2. Run Exposure Analysis.
  3. Review which services connect to the CI.
  4. Record gaps where the CMDB does not model a relationship that you expect.

Related Articles