The value is not a colored map. It is being able to explain every path.
EudorIA Path is the evidence engine of the network risk assessment: it separates reachability, technical exposure and impact. No synthetic index replaces the network evidence.
When a path is confirmed
A path is confirmed only when an active permit rule, interpretable network objects and a route consistent with the egress zone all exist. Rules are evaluated in the exported order: an earlier block can therefore prevent a later authorization.
What a sensitive service means
SSH, RDP, SMB, WinRM, LDAP, databases and similar protocols raise the attention required. Their presence does not prove that the service is vulnerable or exploitable.
Incomplete data
FQDNs unresolved offline, missing dynamic routes, non-interpretable groups and vendor features not yet supported remain visible as uncertainty. These links do not contribute to the blast radius or to the confirmed paths.
Processing security
The service accepts read-only exports only. The original content is checked in memory and is not retained. Passwords, tokens, shared keys, community strings and private keys are excluded before technical interpretation. At the end only the technical model and the result remain, encrypted with a key external to the database. The file content is never executed.
Assisted assessment Coming soon
We are designing an optional feature to help read the evidence. It is not active and does not affect the calculations, the reports or the uploaded data.
Supported formats
The service interprets FortiGate CLI configurations, Cisco ASA running-config and standalone PAN-OS XML: interfaces, zones, network objects and groups, services, static and connected routes, rules and the main NAT transformations. For ASA you can separately attach the output of
show route. Complex Panorama and unmodeled features require manual verification.