ETM Identity Release 1.5.0

September 28, 2026

This release adds Blast Radius and AI-generated attack path remediation summary, helping you improve identity misconfiguration detection and remediation guidance. 

Evaluate Identity Exposure with Blast Radius 

Understand the potential impact of a compromised identity with the new Blast Radius capability. Unlike Attack Path Analysis, which shows how an attacker can reach a target, Blast Radius reveals what an attacker can access after compromising a specific user. 

Identity Exposure Analysis

Blast Radius capability evaluates users, groups, and privileged assets reachable from a selected identity. This helps you understand the extent of access that may be exposed if an account is compromised.

 Using identity exposure analysis, you get answers to questions such as:

  • What can this user access?
  • Which privileged groups can this identity reach?
  • How far can an attacker move if this account is compromised?

To analyze identity exposure, navigate to ETM Identity > Risk Management > Attack Path Analysis > Blast Radius.

blast radius

Suspicious Paths Analysis

Use the Suspicious Paths option to focus on high-risk relationships and attack paths.

When suspicious paths are available, Blast Radius displays only those paths to help you prioritize investigation and remediation.

Fallback Behavior

If the source (currently a user object) is unable to reach the Tier 0 object anywhere in the path, then only the source object will be displayed in the Blast Radius attack path.

Privileged Access Visibility

Blast Radius helps you identify:

  • Reachable privileged groups
  • Tier-0 assets
  • High-risk permission chains
  • Potential lateral movement opportunities

By visualizing identity relationships, you can quickly assess the security impact of compromised identities and reduce identity-driven attack exposure.


- Blast Radius currently focuses only on Tier 0 objects in attack paths. 
- Currently, we support Blast radius up to 5 hops limit in the current release. 

Accelerate Attack Path Remediation with AI Summary  

Quickly understand how to remediate attack paths with AI-generated remediation summaries. Building on the AI Overview capability introduced in ETM Identity 1.4.0, this enhancement provides a more efficient and actionable investigation experience. 

ai overview

Key benefits are:

  • Receive AI-generated remediation recommendations for attack paths.
  • Accelerate investigation and response activities.
  • Reduce analyst effort through automated analysis and remediation guidance.
  • Improve readability through enhanced formatting and highlighted recommendations.

Improved Remediation Presentation

The enhancements include:

  • Highlighted remediation recommendations.
  • Support for emphasized and bold text.
  • Visual highlighting of critical permissions and remediation actions.
  • Improved color formatting for important recommendations.

Remediation guidance is dynamically generated based on the selected attack path and identified privilege escalation opportunities.

Performance and Workflow

Workflow Overview

The following is the workflow of the AI-generated remediation summary:

  1. Attack path details are submitted to Amazon Bedrock for analysis.
  2. Bedrock generates the risk explanation, attack path summary, and remediation recommendations.
  3. Responses are cached in Redis to improve performance.
  4. If the attack path has not changed, ETM Identity retrieves the cached response instead of generating a new one.

Additional Notes

  • All AI-generated sections are returned through a single API request.
  • Existing cache keys remain compatible with the updated response format.
  • No workflow changes are required for existing deployments.