A landscape map drawn by the RedRays Security Platform claims one thing per line and nothing at all about the space between the lines: an absence on the map means no qualifying RFC destination was found in what was successfully read, which is a different statement from a landscape with no lateral movement in it.
Every capability in this platform is held to one rule: a number nobody measured must never be shown as if it were measured. A zero and "we were not told" are different answers. This page is that rule applied to a picture, and it is the page to read before a map is put in front of anybody who will act on it.
It means one of several situations that the drawing renders identically, and only the first is good news.
| Situation | What the map shows |
|---|---|
| Every system was read and no qualifying destination exists | Nothing between those systems |
| Some systems could not be logged on to | Nothing between those systems |
| A client that holds the destinations was not in scope | Nothing between those systems |
| A system exists in the landscape but was never scanned | The system is not on the map at all |
The remedy is not in the picture. It is in knowing which systems were read and when, and recording it beside the map. A map presented without its scope invites the reader to treat silence as safety, and silence here is not evidence.
A band is an ordering to work through. It is not a measurement of exploitability, it does not account for compensating controls, and the arrow colour combines the environment boundary crossed with the security posture of the system at the tail. Open a connection to see which half contributed. A conclusion drawn from colour alone will be wrong on some paths and there is no way to tell which from the picture.
With the source systems' own findings taken out of the colour, what remains is the boundary grading, and the arrows that lose their colour are the ones no boundary rule can grade.
Only what it draws. It carries no record of the date of the read, the systems covered or the account used, so an exported image is a diagram rather than evidence. Write the scope beside it when it goes into a report, and treat two images of the same landscape as comparable only if you know both scopes.
Because the alternative is worse for the person relying on it. A picture is the most persuasive artefact in security work and the easiest to over-read. The failure this analysis is built to prevent is a landscape where one lost system quietly means five, and a reader who mistakes an unread system for a safe one has reproduced exactly that failure with better graphics.
By comparing the systems on it against the inventory of SAP systems you expect, and by checking which of them were successfully read. Completeness is a property of the scope, not of the drawing.
Not necessarily. It has not been found in the most recent read. Confirm that the source system was read successfully in that run before recording the path as remediated.
It can draw a path whose far end is recorded under a string that does not resolve to the machine you expect, because the far end is taken from configuration rather than confirmed by a connection. Read the destination on the source system before acting.
It should not, and that principle is described for the whole product in what a finding does and does not claim. Where a system's environment type is inferred rather than set, set it yourself for the systems that matter, as described in system types and environment boundaries.
SAP threat modelling and attack paths, and reading the SAP landscape map for the picture itself.