Cartography is a Python tool that pulls infrastructure assets and their relationships into a Neo4j graph database.
What it connects: AWS, GCP, Azure, Kubernetes, GitHub, Okta, Entra ID, CrowdStrike, and 30+ more platforms.
Questions it answers:
- Which identities have access to which datastores? How about across multiple tenants, or providers?
- Am I affected by any critical vulnerabilities or compromised software packages?
- What are the network paths in and out of my environment?
- Which compute instances are exposed to the internet?
- What AI agents are running in production, and what permissions do they have?

Quick Start
Install Cartography
pip install cartography
Install cartography[neo4j-rust] instead to swap in Neo4j's Rust Bolt codec, which cuts sync time by roughly 20-30%. See Faster Neo4j driver.
Start Neo4j database
docker run -d --publish=7474:7474 --publish=7687:7687 -v data:/data --env=NEO4J_AUTH=none neo4j:5-community
Confirm that http://localhost:7474 is up.
Sync your first data source (AWS example)
Ensure your AWS credentials and default region are configured (e.g. via AWS_PROFILE, AWS_DEFAULT_REGION, or ~/.aws/config). See AWS credentials docs for reference.
Run Cartography:
cartography --neo4j-uri bolt://localhost:7687 --selected-modules aws
See the full install guide for other platforms.
Query the graph
Open http://localhost:7474 and try:
// Find unencrypted RDS instances by account
MATCH (a:AWSAccount)-[:RESOURCE]->(rds:AWSRDSInstance{storage_encrypted:false})
RETURN a.name, rds.id
// Find EC2 instances exposed to the internet
MATCH (instance:AWSEC2Instance{exposed_internet: true})
RETURN instance.instanceid, instance.publicdnsname
See the querying tutorial and data schema for more use-cases.
Run security rules
Once Cartography has populated the reachable Neo4j graph, list, inspect, and run security rules. This quickstart uses the no-auth Neo4j container started above, so no password is required:
cartography-rules list
cartography-rules list object_storage_public
cartography-rules run object_storage_public
For authenticated Neo4j, set NEO4J_PASSWORD or use one of the other secure
password options in the rules docs.
Supported platforms
Click to expand full list of 30+ supported platforms
- Airbyte - Organization, Workspace, User, Source, Destination, Connection, Tag, Stream
- Amazon Web Services - ACM, API Gateway, Bedrock, CloudWatch, CodeBuild, Config, Cognito, EC2, ECS, ECR (including