Applications
Group infrastructure into logical applications for business context.
Overview
Real-world infrastructure serves business applications. The Applications feature lets you group related infrastructure resources into logical applications, enabling you to:
- Understand the blast radius of security issues
- Track application-to-application connections
- Roll up findings by business service
- Prioritize remediation by business impact
Creating Applications
Auto-Discovery
Infracast can automatically discover applications from resource tags:
AWS Tags:
ApplicationorappProjectorprojectServiceorservice
Azure Tags:
applicationworkloadservice
Resources with matching tags are automatically grouped into applications.
Manual Creation
- Navigate to Assets → Applications
- Click Create Application
- Enter a name and description
- Add resources manually or by filter
Filter-Based Grouping
Create dynamic applications using filters:
name contains "web" AND type = "aws.ec2.instance"
tags.environment = "production"
vpc_id = "vpc-abc123"
Application View
Overview Tab
- Total resources in the application
- Security findings count by severity
- Health status (based on findings)
- Last discovery time
Resources Tab
- List of all resources in the application
- Resource types and counts
- Direct links to asset details
Findings Tab
- Security findings affecting the application
- Grouped by severity
- Filter by compliance framework
Connections Tab
- Application-to-application connections
- Inbound and outbound traffic flows
- Dependency mapping
Business Services
A business service groups multiple applications into a higher-level business function, so you can reason about risk in terms the business recognises rather than per-application.
Payment Processing (business service — CRITICAL)
├── Customer Portal (frontend)
├── API Gateway (middleware)
├── Backend API (backend)
├── User Database (database)
└── Redis Cache (cache)
| Field | Description |
|---|---|
| Name | Service name |
| Description | What business function it fulfils |
| Criticality | critical, high, medium, low |
| SLA Tier | Your recovery-time commitment for the service |
| Owner | Responsible team or person |
| Member Applications | The applications that make up the service |
Findings roll up from resources, to applications, to the business service — so a single critical
finding on a database is visible as risk to "Payment Processing", not just to user-db-prod.
Managing business services
# List and read
GET /api/v1/tenants/{tenantID}/services
GET /api/v1/tenants/{tenantID}/services/{svcID}
# Create, update, delete
POST /api/v1/tenants/{tenantID}/services
PUT /api/v1/tenants/{tenantID}/services/{svcID}
DELETE /api/v1/tenants/{tenantID}/services/{svcID}
# Add or remove member applications
POST /api/v1/tenants/{tenantID}/services/{svcID}/applications
DELETE /api/v1/tenants/{tenantID}/services/{svcID}/applications/{appID}
# Ask Infracast to propose services from discovered applications
POST /api/v1/tenants/{tenantID}/applications/suggest-services
Security posture for a whole service is also available directly:
GET /api/v1/tenants/{tenantID}/services/{serviceID}/sbom
GET /api/v1/tenants/{tenantID}/services/{serviceID}/cve-exposure
Blast Radius Analysis
Understanding the impact of a compromised resource:
- Select an application
- View the Blast Radius panel
- See what other applications could be affected
- Identify critical dependencies
Blast radius considers:
- Network connectivity
- IAM permissions
- Shared resources
- Trust relationships
Connection Tracking
How It Works
Infracast maps connections between applications by analyzing:
- Security group rules
- Network ACLs
- Route tables
- Load balancer configurations
Viewing Connections
- Go to Assets → Applications
- Select an application
- Click the Connections tab
- View inbound and outbound connections
Connection Graph
The topology view shows application-level connections:
- Click Application View toggle in Topology
- See applications as grouped nodes
- Connection lines show traffic flow
Health Rollup
Application health is calculated from its resources:
| Status | Criteria |
|---|---|
| 🟢 Healthy | No critical or high findings |
| 🟡 Warning | High findings present, no critical |
| 🔴 Critical | Critical findings present |
Best Practices
- Consistent Tagging — Use standard tags across your infrastructure
- Meaningful Names — Name applications after business services
- Include All Components — Add databases, queues, and supporting resources
- Review Regularly — Update applications as infrastructure changes
- Prioritize by Business Value — Focus on applications with highest business impact
API Access
Manage applications programmatically:
# List applications
GET /api/v1/tenants/{id}/applications
# Create application
POST /api/v1/tenants/{id}/applications
{
"name": "Customer Portal",
"description": "Public-facing customer web application",
"filter": "tags.app = 'customer-portal'"
}
# Get application details
GET /api/v1/tenants/{id}/applications/{app_id}
See the API Reference for full details.