//

//

Introducing Saporo v5 - From Identity Exposure Visibility to Preemptive Control

Saporo v5 is a major release that expands Saporo from identity exposure visibility into end-to-end Preemptive Identity Exposure Management (PIEM). It brings identity discovery, attack-path analysis, prioritization, dashboards, scope management, remediation workflows, and integrations together in one product experience.

This release reflects Saporo’s evolution from APM and ISPM toward a complete PIEM approach, helping teams continuously scope, discover, prioritize, validate, mobilize and measure against identity exposure before it becomes an attack. Saporo v5 is among the first platforms to apply the CTEM model deeply to identity security, spanning Active Directory, Entra ID, Azure, Microsoft 365, Google Workspace, GCP, ADCS, SMB, Windows local security, service accounts, certificates, and cross-environment attack paths. With v5, Saporo advances its chokepoint engine, building on an in-memory capability that already operated at a scale few platforms reach. Its new exact computation model accounts for every shortest attack path within the analysis budget and completes the work faster, giving even the largest enterprise environments complete chokepoint rankings in minutes.

  • Automation & Remediation Center with a catalog of 140+ prebuilt workflows, a visual workflow builder, finding association, and execution history.

  • Close to 1,900 integrations plus custom connector support, connecting remediation to the tools teams already use.

  • New dashboards (Overview, Compliance, Tiering, Custom, and Manage) that make posture, compliance, tiering, and remediation easier to track.

  • Google Workspace and GCP support, extending coverage beyond Microsoft-centric environments.

  • Expanded collector and coverage improvements across AD, Azure, Entra ID, ADCS, SMB, and WinLocal.

  • Exact chokepoint analysis at enterprise scale, powered by a new engine that accounts for every shortest attack path within the analysis budget and produces complete rankings in minutes.

  • New licensing tiers (Core, Core+, and Enterprise) aligned to observe, investigate, and remediate.


From finding exposure to reducing it, at scale

Discovering risk is only half the problem. Lasting security comes from continuously reducing identity exposure as environments change. v5 makes remediation a first-class part of the workflow: teams can associate a workflow with a finding right where they triage, run and monitor it, track execution history, and measure automation coverage, from applicable and remediated findings to estimated time saved, success rate, and recommended automations.



The result is a continuous loop from finding exposure to reducing it, without leaving Saporo.

Saporo v5 ships with close to 140 prebuilt workflows, addressing common identity remediation patterns across Active Directory, Entra ID, Azure, ADCS, and related infrastructure.



Workflows are highly flexible: built on n8n behind the scenes, they can include human-in-the-loop approval steps, conditional logic, detailed execution logs, and connections to the tools teams already use, so automation moves as fast or as cautiously as each change demands.

Many remediation tasks require specialist knowledge of directory internals, cloud permissions, GPOs, certificates, and scripting. v5 packages those actions into reusable workflows so teams act faster and more consistently, even when specialist resources are limited.


Integrations as a first-class capability

Automation introduces integrations as a first-class capability. Using n8n behind the scenes, Saporo gives customers access to close to 1,900 integrations, connecting remediation workflows with ticketing systems, notification tools, ITSM platforms, SOAR processes, identity providers, cloud services, and internal APIs. Customers can also build custom connectors for proprietary or specialized tools.



Integrations work in both directions. Saporo can push out to the tools teams already use, for example opening a Jira ticket when a critical finding appears, and it can pull context in to sharpen its own analysis. When an XDR tool flags a detection, an integration can tag the affected node as high risk in Saporo, so that live signal feeds directly into attack-path prioritization. The result is a richer, more current picture of exposure, informed by the rest of the security stack rather than analyzed in isolation.


The only engine that ranks chokepoints exactly, at enterprise scale

At the heart of Saporo sits the chokepoint engine. It identifies the permissions that give an adversary the greatest control over critical assets, so that severing one can collapse millions of attack paths with a single fix. Ranking these chokepoints correctly turns a wall of findings into a short list of high-leverage actions.

Saporo was already ahead here. Our previous engine used an in-memory graph to compute chokepoints across hundreds of thousands of identities and millions of relationships, a capability few platforms offer. Like every path-enumerating architecture, it operated within a deliberate path limit to keep the analysis practical on environments containing close to a billion shortest attack paths.

With v5, we removed the need for that limit.

Instead of retaining every path in memory, the new engine accumulates the required statistics directly on the relationships those paths cross. This allows v5 to account for every shortest attack path within the analysis budget, giving customers chokepoint rankings that reflect the complete environment.



We have verified those results against an independent reference implementation and directly against the raw graph. On smaller environments, the previous engine and v5 produce exactly the same results. On the largest environments, v5 extends the analysis to the complete set of paths within budget.

The new computational model also makes the analysis faster. The first complete version of the exact engine took 84 minutes. After successive optimization rounds, the Saporo v5 engine completes the same analysis in 7.4 minutes, even as the benchmark graph grew from 10.4 million to 13.5 million relationships.



Chokepoint analysis at this scale was already rare. With v5, Saporo takes that capability further: exact rankings, independently verified results, and faster analysis across the most complex enterprise identity environments.


Posture, compliance, and tiering in one place

Saporo v5 introduces a broader dashboard experience organized around the main ways customers manage identity exposure, with updated navigation to reach these views from the main product menu.



  • Overview: high-level posture, Resistance Score, trends, and operational movement.

  • Compliance: misconfiguration posture, framework alignment, and control pass/fail status.

  • Tiering: tiering score, cross-tier violations, access to higher tiers, and Tier 0 exposure.

  • Custom Dashboard: user-defined dashboards built from reusable widgets.

  • Manage Dashboards: dashboard creation, sharing, defaults, and widget management.

Custom Dashboards replace the previous Kibana-based Analytics experience. Instead of a complex analytics interface, v5 provides a dashboard canvas built from reusable widgets: resistance score, score trends, attack paths removed, ticket activity, findings triage, compliance and tiering widgets, prewritten and saved query widgets, and custom markdown text. Advanced users can monitor specific exposure patterns without forcing every user into Explore or raw query workflows.


Compliance connected to identity exposure

The Compliance Dashboard gives a dedicated view of misconfiguration posture and framework alignment: global misconfiguration score, control pass/fail posture by severity, operational risk by impact, attack paths from misconfigured nodes, and reachable high-value targets. Supported framework views include ANSSI, CIS Azure, CIS GCP, CIS Microsoft 365, ENS RD2022, ISO 27001, MITRE ATT&CK, NIS2, PCI, Prowler ThreatScore, and SOC 2. Saporo now delivers close to 1,000 controls across our supported data sources and security frameworks.



As always in Saporo, compliance is connected to identity exposure. Customers see not only which controls fail, but whether those failures contribute to attack paths or expose high-value targets.


Tiering as a measurable program

The Tiering Dashboard is one of the most important additions in v5, and it works across Microsoft and non-Microsoft environments. Tiering is often treated as an Active Directory project, but modern identity exposure crosses directories, cloud platforms, service accounts, local systems, groups, and applications.



Because Saporo maps access relationships and attack paths across the identity estate, it can track tiering programs over time, showing who can access what, where lower-tier identities can reach higher-tier systems, and which paths create risk to Tier 0.



This turns tiering from a static spreadsheet exercise into a measurable exposure management program.


Google is now a first-class data source in Saporo

Google support is new in v5. Saporo has always analyzed Microsoft and other enterprise identity systems, and now it brings the Google estate into the same model for the first time. A modern Google organization lives in two places at once: Workspace and Google Cloud. They are governed separately, but attackers don’t respect the boundary. A Workspace identity can quietly hold cloud privileges, up to and including ownership of the entire GCP organization, and neither console shows the full picture. The risk lives in the gap between them.

With v5, Saporo brings Google Workspace and Google Cloud Platform into a single security graph. From Workspace, Saporo collects users, groups, memberships, role assignments, Drive ownership, and managed devices; from GCP, it maps the organization, folder, and project hierarchy, IAM bindings, service accounts, compute instances, Cloud SQL, and storage buckets. A bridge resolves user access across both planes, creating the cross-domain edges that make unified attack-path analysis possible. No single Google API returns this; Saporo computes it at ingest.



Once access is a graph, questions a defender could never answer from lists become single queries:

  • Transitive privilege escalation: grants that look harmless alone but chain together to reach Owner, invisible in any single console.

  • Cross-domain lateral movement: a Workspace identity crossing the bridge into GCP along one continuous path.

  • Blast radius of an identity: if this account is phished, what becomes reachable? The graph answers as a traversal, not a guess.

  • Shadow admins and toxic combinations: effective ownership without an Owner title, such as reset-password rights plus a privileged target.



This directly addresses Google’s own top cloud threats. In its Threat Horizons H1 2025 report, Google found that 46.4% of observed security alerts stemmed from overprivileged service accounts that actors exploit to move laterally, the number-one cloud risk. Saporo turns that class of risk into a measurable question: what is the shortest path from any identity to organization Owner?

Alongside attack-path analysis, v5 checks Google posture against a broad set of controls and misconfigurations, powered by Prowler. Coverage spans both planes:

  • Google Cloud Platform: Identity & Access Management (12 checks), Logging & Monitoring (14), Networking (8), Virtual Machines (10), Cloud SQL Databases (21), BigQuery (3), Storage (2), and Dataproc (1).

  • Google Workspace: Apps (43 checks), Security (13), Rules (8), Directory (3), and Reporting (2).

Each control maps back to the same identity graph, so customers see not only which controls fail, but whether those failures open real attack paths or expose high-value targets.


More accurate analysis across the identity estate

v5 includes significant improvements across Saporo’s existing collectors and analysis logic, increasing coverage and reducing noise, especially where attack paths depend on precise relationships rather than broad posture signals.

  • Active Directory: expanded GPO analysis, dangerous privilege rights, SIDHistory improvements, Kerberos weak-encryption readiness, password-in-description detection, group loop detection, PAM and temporary membership, and Windows LAPS support.

  • Azure / Entra ID / M365: PIM-aware tiering, Enterprise Application visibility, delegated OAuth permission grants, Azure role usage, database firewall rules, and managed identity inventory.

  • ADCS: Certipy 5 support, ESC13 and ESC16 coverage, more accurate ESC predicate logic, and better certificate enrollment modeling.

  • SMB: redesigned collector, Linux-based collection support, share relationships, SMBv1 controls, and file-share HVT tagging.

  • WinLocal: local administrators, groups, sessions, remote execution paths, lateral movement, and local-to-domain relationships.

This release also brings WinLocal, Scope Filtering, and Themes (Dark Mode) into the main product line. First delivered in the intermediary v4.2 release, they are now part of the standard v5 experience for every customer.


Findings, Explore, and everyday workflow improvements

v5 includes many improvements across daily investigation and remediation: saved finding searches, shareable Explore queries, one-click loading of graph queries into Explore, improved node and path visualization, custom path views, copyable code blocks in finding descriptions, better filtering, improved inventory drilldowns, and ticket export improvements.

v5 also includes many additional fixes and refinements, such as MFA re-enrollment fixes, domain controller log and node filtering, HadSession improvements, ANSSI score fixes, child domain collection fixes, and dangerous node visualization fixes. Together, these changes make Saporo easier to operate during active investigation, remediation planning, and reporting.


Packaging aligned to the customer journey

Saporo v5 introduces a new tier structure: Core, Core+, and Enterprise. Existing customers will be grandfathered into Core+.

  • Core: broad visibility across the identity estate, including supported collectors, Overview / Tiering / Compliance dashboards, findings triage, inventory, prebuilt graph queries, logs, API access, SSO, MFA, RBAC, and audit reporting.

  • Core+: everything in Core, plus the custom graph query builder, advanced and saved graph queries, Custom Dashboards, and Scope Views.

  • Enterprise: everything in Core+, plus workflow-linked findings, the Remediation Center, automation engine, integrations, and prebuilt remediation workflows.

This packaging aligns Saporo’s capabilities with the customer journey: from observing exposure, to investigating it deeply, to operationalizing remediation.

10 minutes