[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"readme:cartography":3},"\u003Cpicture>\n  \u003Csource media=\"(prefers-color-scheme: dark)\" srcset=\"docs\u002Froot\u002Fimages\u002Flogo-horizontal-dark.svg\">\u003C\u002Fsource>\n  \u003Csource media=\"(prefers-color-scheme: light)\" srcset=\"docs\u002Froot\u002Fimages\u002Flogo-horizontal.svg\">\u003C\u002Fsource>\n  \u003Cimg alt=\"Cartography\" src=\"https:\u002F\u002Fraw.githubusercontent.com\u002Fcartography-cncf\u002Fcartography\u002FHEAD\u002Fdocs\u002Froot\u002Fimages\u002Flogo-horizontal.svg\" \u002F>\n\u003C\u002Fpicture>\u003Cdiv align=\"center\">\u003Cp>\u003Ca href=\"https:\u002F\u002Fscorecard.dev\u002Fviewer\u002F?uri=github.com\u002Fcartography-cncf\u002Fcartography\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fapi.scorecard.dev\u002Fprojects\u002Fgithub.com\u002Fcartography-cncf\u002Fcartography\u002Fbadge\" alt=\"OpenSSF Scorecard\" \u002F>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.bestpractices.dev\u002Fprojects\u002F9637\" rel=\"nofollow ugc noopener\">\u003Cimg src=\"https:\u002F\u002Fwww.bestpractices.dev\u002Fprojects\u002F9637\u002Fbadge\" alt=\"OpenSSF Best Practices\" \u002F>\u003C\u002Fa>\n\u003Cimg src=\"https:\u002F\u002Fgithub.com\u002Fcartography-cncf\u002Fcartography\u002Factions\u002Fworkflows\u002Fpublish-to-ghcr-and-pypi.yml\u002Fbadge.svg\" alt=\"build\" \u002F>\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fdocs.cartography.dev\u002F\" rel=\"nofollow ugc noopener\">Documentation\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fdiv>\u003Cp>Cartography is a Python tool that pulls infrastructure assets and their relationships into a \u003Ca href=\"https:\u002F\u002Fwww.neo4j.com\" rel=\"nofollow ugc noopener\">Neo4j\u003C\u002Fa> graph database.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What it connects:\u003C\u002Fstrong> AWS, GCP, Azure, Kubernetes, GitHub, Okta, Entra ID, CrowdStrike, and \u003Ca href=\"#supported-platforms\" rel=\"nofollow ugc noopener\">30+ more platforms\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Questions it answers:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Which identities have access to which datastores? How about across multiple tenants, or providers?\u003C\u002Fli>\n\u003Cli>Am I affected by any critical vulnerabilities or compromised software packages?\u003C\u002Fli>\n\u003Cli>What are the network paths in and out of my environment?\u003C\u002Fli>\n\u003Cli>Which compute instances are exposed to the internet?\u003C\u002Fli>\n\u003Cli>What AI agents are running in production, and what permissions do they have?\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cimg src=\"https:\u002F\u002Fraw.githubusercontent.com\u002Fcartography-cncf\u002Fcartography\u002FHEAD\u002Fdocs\u002Froot\u002Fimages\u002Faccountsandrds.png\" alt=\"Visualization of RDS nodes and AWS nodes\" \u002F>\u003C\u002Fp>\n\u003Ch2>Quick Start\u003C\u002Fh2>\n\u003Ch3>Install Cartography\u003C\u002Fh3>\n\u003Cpre>\u003Ccode class=\"language-bash\">pip install cartography\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Install \u003Ccode>cartography[neo4j-rust]\u003C\u002Fcode> instead to swap in Neo4j's Rust Bolt codec, which cuts sync time by roughly 20-30%. See \u003Ca href=\"https:\u002F\u002Fdocs.cartography.dev\u002Fops.html#faster-neo4j-driver\" rel=\"nofollow ugc noopener\">Faster Neo4j driver\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Start Neo4j database\u003C\u002Fh3>\n\u003Cpre>\u003Ccode class=\"language-bash\">docker run -d --publish=7474:7474 --publish=7687:7687 -v data:\u002Fdata --env=NEO4J_AUTH=none neo4j:5-community\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Confirm that \u003Ca href=\"http:\u002F\u002Flocalhost:7474\" rel=\"nofollow ugc noopener\">http:\u002F\u002Flocalhost:7474\u003C\u002Fa> is up.\u003C\u002Fp>\n\u003Ch3>Sync your first data source (AWS example)\u003C\u002Fh3>\n\u003Cp>Ensure your AWS credentials and default region are configured (e.g. via \u003Ccode>AWS_PROFILE\u003C\u002Fcode>, \u003Ccode>AWS_DEFAULT_REGION\u003C\u002Fcode>, or \u003Ccode>~\u002F.aws\u002Fconfig\u003C\u002Fcode>). See \u003Ca href=\"https:\u002F\u002Fdocs.aws.amazon.com\u002Fboto3\u002Flatest\u002Fguide\u002Fcredentials.html#configuring-credentials\" rel=\"nofollow ugc noopener\">AWS credentials docs\u003C\u002Fa> for reference.\u003C\u002Fp>\n\u003Cp>Run Cartography:\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">cartography --neo4j-uri bolt:\u002F\u002Flocalhost:7687 --selected-modules aws\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>See the \u003Ca href=\"https:\u002F\u002Fdocs.cartography.dev\u002Finstall.html\" rel=\"nofollow ugc noopener\">full install guide\u003C\u002Fa> for other platforms.\u003C\u002Fp>\n\u003Ch3>Query the graph\u003C\u002Fh3>\n\u003Cp>Open \u003Ca href=\"http:\u002F\u002Flocalhost:7474\" rel=\"nofollow ugc noopener\">http:\u002F\u002Flocalhost:7474\u003C\u002Fa> and try:\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-cypher\">\u002F\u002F Find unencrypted RDS instances by account\nMATCH (a:AWSAccount)-[:RESOURCE]-&gt;(rds:AWSRDSInstance{storage_encrypted:false})\nRETURN a.name, rds.id\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cpre>\u003Ccode class=\"language-cypher\">\u002F\u002F Find EC2 instances exposed to the internet\nMATCH (instance:AWSEC2Instance{exposed_internet: true})\nRETURN instance.instanceid, instance.publicdnsname\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>See the \u003Ca href=\"https:\u002F\u002Fdocs.cartography.dev\u002Fusage\u002Ftutorial.html\" rel=\"nofollow ugc noopener\">querying tutorial\u003C\u002Fa> and \u003Ca href=\"https:\u002F\u002Fdocs.cartography.dev\u002Fusage\u002Fschema.html\" rel=\"nofollow ugc noopener\">data schema\u003C\u002Fa> for more use-cases.\u003C\u002Fp>\n\u003Ch3>Run security rules\u003C\u002Fh3>\n\u003Cp>Once Cartography has populated the reachable Neo4j graph, list, inspect, and run\nsecurity rules. This quickstart uses the no-auth Neo4j container started above,\nso no password is required:\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">cartography-rules list\ncartography-rules list object_storage_public\ncartography-rules run object_storage_public\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>For authenticated Neo4j, set \u003Ccode>NEO4J_PASSWORD\u003C\u002Fcode> or use one of the other secure\npassword options in \u003Ca href=\"https:\u002F\u002Fdocs.cartography.dev\u002Fusage\u002Frules.html\" rel=\"nofollow ugc noopener\">the rules docs\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>Supported platforms\u003C\u002Fh2>\n\u003Cdetails>\n\u003Csummary>Click to expand full list of 30+ supported platforms\u003C\u002Fsummary>\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.cartography.dev\u002Fmodules\u002Fairbyte\u002Findex.html\" rel=\"nofollow ugc noopener\">Airbyte\u003C\u002Fa> - Organization, Workspace, User, Source, Destination, Connection, Tag, Stream\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.cartography.dev\u002Fmodules\u002Faws\u002Findex.html\" rel=\"nofollow ugc noopener\">Amazon Web Services\u003C\u002Fa> - ACM, API Gateway, Bedrock, CloudWatch, CodeBuild, Config, Cognito, EC2, ECS, ECR (including\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fdetails>",1790633825896]