Skip to content
OPS // KITitspentest.sh

E-CAR

Cartography

Python tool that builds a Neo4j graph of infrastructure across AWS, GCP, Azure, GitHub, Okta, and more for security analysis.

Official siteBack to catalog

OVERVIEW

Cartography (originally lyft/cartography, now maintained as cartography-cncf/cartography under the CNCF Sandbox) is a Python tool that syncs infrastructure and identity data from AWS, GCP, Azure, Kubernetes, GitHub, Okta, Entra ID, CrowdStrike, and dozens of other providers into a single Neo4j graph database.

Unlike the Azure-only identity graph tools in this list, Cartography is intentionally broad — it is built for continuous asset inventory and attack-surface mapping across an organization's whole cloud and SaaS footprint, and it is commonly run as a scheduled job feeding dashboards and Cypher queries rather than as a one-off engagement tool.

USE CASES

Practical use cases

  • 01

    Building a continuously updated inventory of AWS, GCP, and Azure assets and their relationships in Neo4j.

  • 02

    Mapping cross-provider attack paths, e.g. from a GitHub repo secret to an AWS IAM role to an EC2 instance.

  • 03

    Auditing Okta or Entra ID identity assignments alongside the cloud resources those identities can reach.

  • 04

    Feeding attack-surface-management dashboards and Cypher-based detections from a single unified asset graph.

QUICK START

For cloud and SaaS asset-inventory work spanning multiple providers, once a Neo4j instance and provider credentials are available.

  1. Start a local Neo4j instance, e.g. with the official Docker image.
  2. Install Cartography with `pip install cartography` and configure credentials for the providers you want to sync (AWS profile, GCP service account, etc.).
  3. Run `cartography` with `--selected-modules` set to the providers in scope and `--neo4j-uri` pointing at your Neo4j instance.
  4. Open the Neo4j browser and explore the synced graph with Cypher, or point a BI tool at it.
cartography — bash
cartography --neo4j-uri bolt://localhost:7687 --selected-modules aws,gcp,github

BEFORE YOU RUN IT

What to check before running it

A full multi-provider sync makes many read-only API calls against every configured provider — confirm scope and expected call volume with the client before running it against a live tenant.

The resulting graph is a complete map of the organization's cloud and SaaS footprint, including cross-provider privilege paths — treat the Neo4j instance and its backups as sensitive, engagement-scoped data.

Only use read-only, scoped credentials per provider; Cartography does not need write access to do its job.

KEEP EXPLORING

View the whole phase →