The Security Graph
Model relationships between workloads, identities, network paths, and data stores to expose reachable attack paths — not just isolated findings.
Open source · Cloud-native · Graph-first
OpenSourceOM connects assets, identities, and exposures into a living security graph — surfacing attack paths and the vulnerabilities that actually put your data at risk.
Traditional scanners flood you with alerts. OpenSourceOM connects the dots — showing which vulnerabilities sit on paths to sensitive data and privileged access.
Model relationships between workloads, identities, network paths, and data stores to expose reachable attack paths — not just isolated findings.
Prioritize CVEs and misconfigurations by reachability, path to data, and admin access — so your team fixes what attackers can actually reach first.
Normalize assets across AWS, Azure, GCP, and Kubernetes with a unified graph schema. Add collectors of your own with the plugin SDK.
Check configurations against CIS, PCI, and custom guardrails. Map failed controls to graph nodes so remediation has context, not just ticket IDs.
Run OpenSourceOM in your VPC. No black-box scoring — inspect the graph, rules, and enrichment pipelines in plain code.
Push prioritized findings to Jira, Slack, or SIEM. Tie CVE data to workload inventory and extend ingest with collector plugins.
Inspired by graph-native CNAPP platforms, OpenSourceOM builds a queryable model of your environment. Ask questions like “Which critical CVEs are internet-exposed and can reach production databases?” — and get an answer in seconds.
reachable(critical_cve) → datastore(prod) CVE-2024-1234 · OpenSSL
S3 bucket policy · Public list
IAM user · Unused access key
CNAPP platforms proved that context beats volume. OpenSourceOM brings graph-native security to teams that want transparency, control, and community-driven innovation.
Early stage · Community-driven
OpenSourceOM is just getting started. Community momentum — stars, feedback, and word of mouth — directly influences how fast we ship and what we prioritize. Here is how you can help today.
A GitHub star is a small action with real impact — it helps others discover the project and signals that open cloud security deserves more attention.
Star on GitHubOpen issues for feature requests, bugs, or ideas. Upvote discussions that matter to you so we know what the community needs most.
Browse issuesVisibility is the biggest lever right now. Write about OpenSourceOM on Reddit, Hacker News, X/Twitter, LinkedIn, or wherever your cloud security peers hang out.
We plan to launch Slack and Discord spaces for contributors and early adopters. Watch this site and the GitHub repo for announcements.
Coming soonThe more support we get, the harder we push this project forward. Thank you for being here this early.