LimaCharlie Cloud Security: CNAPP Walkthrough

A walkthrough of Cloud Security in LimaCharlie — CNAPP capability built into the SecOps Cloud Platform.

Connect your cloud and SaaS providers (AWS, GCP, Azure, Okta, Google Workspace, GitHub, Cloudflare, Anthropic, and even other LimaCharlie orgs) and everything is normalized into a single security graph: identities, permissions, workloads, and data. The engine reasons over that graph to surface attack paths — evidence-backed chains an attacker could actually walk — instead of isolated checkbox findings.

In this walkthrough:

  • Findings prioritized by real reachability and impact, not raw CVSS
  • A stale-key non-human identity that can reach sensitive customer data — one fix closes 25 attack paths
  • Attack path visualization from internet exposure to crown-jewel data
  • Identity and data security posture, built-in CAASM (cyber asset attack surface management), and compliance generated from the same graph
  • Findings feeding directly into detections, automation, and response — no data moving between products

Chapters:

0:00 Overview

0:44 Risks

0:58 Risk detail: stale-key NHI

1:21 Attack Surface

1:42 Identity & Access

2:03 Data Security

2:17 Inventory & CAASM

2:46 Compliance

2:59 Policies

3:12 Settings: Providers & Cases

Learn more: https://limacharlie.io