E-CAR
Cartography
Python tool that builds a Neo4j graph of infrastructure across AWS, GCP, Azure, GitHub, Okta, and more for security analysis.
OVERVIEW
Cartography (originally lyft/cartography, now maintained as cartography-cncf/cartography under the CNCF Sandbox) is a Python tool that syncs infrastructure and identity data from AWS, GCP, Azure, Kubernetes, GitHub, Okta, Entra ID, CrowdStrike, and dozens of other providers into a single Neo4j graph database.
Unlike the Azure-only identity graph tools in this list, Cartography is intentionally broad — it is built for continuous asset inventory and attack-surface mapping across an organization's whole cloud and SaaS footprint, and it is commonly run as a scheduled job feeding dashboards and Cypher queries rather than as a one-off engagement tool.
USE CASES
Practical use cases
- 01
Building a continuously updated inventory of AWS, GCP, and Azure assets and their relationships in Neo4j.
- 02
Mapping cross-provider attack paths, e.g. from a GitHub repo secret to an AWS IAM role to an EC2 instance.
- 03
Auditing Okta or Entra ID identity assignments alongside the cloud resources those identities can reach.
- 04
Feeding attack-surface-management dashboards and Cypher-based detections from a single unified asset graph.
QUICK START
For cloud and SaaS asset-inventory work spanning multiple providers, once a Neo4j instance and provider credentials are available.
- Start a local Neo4j instance, e.g. with the official Docker image.
- Install Cartography with `pip install cartography` and configure credentials for the providers you want to sync (AWS profile, GCP service account, etc.).
- Run `cartography` with `--selected-modules` set to the providers in scope and `--neo4j-uri` pointing at your Neo4j instance.
- Open the Neo4j browser and explore the synced graph with Cypher, or point a BI tool at it.
cartography --neo4j-uri bolt://localhost:7687 --selected-modules aws,gcp,githubBEFORE YOU RUN IT
What to check before running it
A full multi-provider sync makes many read-only API calls against every configured provider — confirm scope and expected call volume with the client before running it against a live tenant.
The resulting graph is a complete map of the organization's cloud and SaaS footprint, including cross-provider privilege paths — treat the Neo4j instance and its backups as sensitive, engagement-scoped data.
Only use read-only, scoped credentials per provider; Cartography does not need write access to do its job.