
cartography is a CNCF-hosted Python tool that consolidates assets and relationships from 30+ cloud, identity, and SaaS platforms into a Neo4j graph for authorized security analysis.
| Tool | cartography-cncf/cartography — Python tool that pulls infrastructure assets and relationships into a Neo4j graph database |
| Category | Attack surface management and graph-based security analytics |
| Primary Use | Correlating identities, compute, storage, and vulnerability data across clouds and SaaS into one queryable graph (Cypher queries, cartography-rules) |
| Safe Use | Intended for defenders and authorized security teams inventorying environments they own or are contracted to assess; it reads metadata via authenticated APIs and performs no exploitation |
| Telemetry Note | Uses read-only authenticated API calls against your own tenants (e.g., boto3, Okta, GitHub tokens); leaves API audit trail entries in cloud logs but touches no target systems |
cartography occupies a distinctive niche in the security tooling landscape: rather than scanning or attacking anything, it builds a unified, queryable model of infrastructure you already control. The project, now hosted under the cartography-cncf organization with roughly 4,100 stars, an Apache-2.0 license, and OpenSSF Scorecard and Best Practices badges, is a Python tool that synchronizes assets and their relationships from more than thirty platforms into a Neo4j graph database. The premise is simple and powerful: most security questions that matter — who can access what, what is exposed, what is vulnerable — are inherently relational, and relational databases handle those questions poorly. Graphs handle them natively.
The README frames the tool around the questions it answers, and they read like a defender's wish list. Which identities have access to which datastores, including across multiple tenants or providers? Am I affected by any critical vulnerabilities or compromised software packages? What are the network paths in and out of my environment? Which compute instances are exposed to the internet? Notably, the list also includes a newer concern: what AI agents are running in production, and what permissions do they have? That last item signals the project's trajectory — it is tracking the evolution of enterprise attack surfaces, not just the classic cloud triad.
The breadth of integrations is the headline feature. Beyond the expected AWS, GCP, Azure, Kubernetes, and GitHub, cartography ingests from Okta, Entra ID, CrowdStrike, Cloudflare, DigitalOcean, Duo, Keycloak, JumpCloud, Tailscale, Snowflake, Slack, Zoom, PagerDuty, Jira, LastPass, SentinelOne, Orca Security, Socket.dev, and more. Each module documents specific object types: the AWS module covers everything from EC2, EKS, and RDS through IAM, KMS, Secrets Manager, GuardDuty, Inspector, and Security Hub; the Snowflake module is remarkably deep, modeling role hierarchies, grants, programmatic access tokens, and network policies. The GitHub module pulls repos, branches, teams, and dependency graph manifests, which is where cross-platform correlation starts to shine — a vulnerable dependency in a repo can be linked to the workload that runs it.
Installation follows the standard pip install cartography path, with an optional extra worth knowing about: cartography[neo4j-rust] swaps in Neo4j's Rust Bolt codec, which the README says cuts sync time by roughly 20-30%. For shops syncing large multi-account AWS estates on a schedule, that optimization is not cosmetic. You then need a Neo4j instance; the quickstart suggests the community container via Docker with ports 7474 and 7687 published. The quickstart explicitly disables authentication with NEO4J_AUTH=none for simplicity, and the docs rightly steer production deployments toward authenticated setups — treat the graph itself as sensitive, since it is effectively a compiled map of your entire environment.
Running a sync is a single invocation: cartography --neo4j-uri bolt://localhost:7687 --selected-modules aws. Credentials come from the standard chains — for AWS, AWS_PROFILE, AWS_DEFAULT_REGION, or ~/.aws/config — so there is no credential handling bolted onto the tool itself. The --selected-modules flag is the key composability mechanism: you run the modules you have credentials for, and cartography stitches the results together, creating cross-platform relationship edges where identities federate between systems, such as the documented Okta and Entra ID federation into AWS roles and AWS Identity Center.
Once the graph is populated, analysis happens in Cypher. The README's examples are instructive because they show the shape of the payoff: one query matches AWSAccount nodes through RESOURCE edges to AWSRDSInstance nodes where storage_encrypted:false, giving you every unencrypted database by account in a single statement. Another matches AWSEC2Instance nodes flagged exposed_internet: true and returns instance IDs and public DNS names. These are checks you could approximate with native tooling per-platform, but the graph model collapses the multi-account, multi-provider version of the question into one query against one dataset.
Beyond ad-hoc queries, the project ships a rules engine exposed as the cartography-rules command. You can list available rules, inspect a specific one, and execute it — the README demonstrates cartography-rules list, cartography-rules list object_storage_public, and cartography-rules run object_storage_public. The naming of the example rule tells you the intent: continuously evaluated, declarative checks against the graph, in the spirit of infrastructure-as-code linting but applied to live security posture. Authenticated Neo4j deployments configure credentials via NEO4J_PASSWORD or the alternatives in the rules documentation.
Two enrichment modules deserve specific attention. The CVE Metadata module enriches vulnerability nodes with CVSS and EPSS scores plus CISA KEV data pulled from NVD and FIRST.org, which lets you prioritize findings using the same signals the broader industry triages on. The older NIST CVE module is explicitly deprecated in favor of it. Alongside that, the Trivy module ingests scanner output for AWS ECR images, the Socket.dev module imports CVE, malware, and supply-chain security alerts, and the AIBOM module links AI component detections to container images — a supply-chain angle that pairs naturally with the README's question about AI agents in production. There are even dedicated modules for OpenAI and Anthropic, modeling API keys, service accounts, and workspaces as first-class graph citizens.
The identity providers coverage is where cartography earns its keep for attack path analysis in authorized engagements. Okta and Entra ID modules model users, groups, applications, roles, factors, and federation relationships; Keycloak goes as far as authentication flows and executions; Google Workspace covers OAuth applications. Combined with cloud IAM data, this enables the questions auditors actually get asked: which dormant identity still has an admin path to production, which third-party OAuth app has overbroad scopes. It is reconnaissance-grade visibility, pointed inward at systems you are authorized to examine.
Operationally, the tool is read-only with respect to targets — it consumes metadata through authenticated provider APIs and writes only to your Neo4j instance. That makes it suitable for continuous scheduled syncs in a defensive pipeline, and its provenance supports that use: the README lists Lyft (where the project originated), Thought Machine, MessageBird, Cloudanix, Corelight, SubImage, and Superhuman among its users, and the community maintains a CNCF Slack channel, monthly meetings with published minutes, and recordings. Contributors follow the CNCF Code of Conduct with a DCO sign-off requirement.
For practitioners, the practical considerations are graph freshness and credential scope. The graph is only as current as your last sync, so exposure findings should be validated against live state before acting on them — a node flagged exposed_internet: true reflects conditions at ingestion time. Conversely, the service credentials you grant each module should be least-privilege read-only, since every module's API access will appear in your providers' audit logs. Handled that way, cartography is one of the strongest open-source foundations available for building a durable, queryable model of a complex multi-cloud estate.
cartography-cncf/cartography.Educational analysis for authorized security professionals. Use only in controlled, authorized environments.
Related coverage
0 comentários:
Post a Comment
Note: Only a member of this blog may post a comment.