Get started

OpenSourceOM CLI

The om binary talks to Postgres directly. Scans, rules, queries, and exports do not go through the HTTP API, so they do not send OM_API_SECRET. Build it from the core repo with go build -o om ./cmd/om, or use a release archive.

om migrate walks upward from the working directory until it finds go.mod, then applies migrations/ beside that file. Set OM_REPO_ROOT if the binary is not running inside a checkout. The container image includes go.mod and migrations/ under /app.

Commands

Command What it does
om migrate Apply versioned SQL migrations.
om serve Listen on OM_API_PORT and serve the API plus the console.
om scan demo Replace the demo accounts, ingest the sample graph, run all rules, print a path and the top findings.
om scan aws EC2, security groups, IAM, and S3 in AWS_REGION, plus CloudTrail management events from the last 24 hours.
om scan azure VMs, storage accounts, subscription role assignments, and Activity Log events from the last 24 hours.
om scan gcp GCE, GCS, service accounts, and Admin Activity audit logs from the last 24 hours in GCP_PROJECT_ID.
om scan k8s Pods, services, and service accounts from kubeconfig.
om scan plugin -- <exe> [args...] Run an external collector. --timeout defaults to 10 minutes.
om rules list Print every built-in and pack rule id.
om rules run [rule-id] Evaluate one rule or the full catalog and upsert findings. A full run writes attack-path findings after the control rules.
om paths list Print named query names.
om paths run <name> Run one named query and print paths. A CloudTrail, Activity Log, or Admin Activity event whose resource is on a path is printed under that path.
om graph stats JSON counts of nodes, edges, and nodes by type.
om identity blast-radius --id or --name. Add --json for the API shape.
om enrich cve Match workload packages and images to CVEs. Repeat --cve to limit ids. --catalog replaces NVD. --internet-only defaults to true.
om export findings run --format siem|slack|jira. --out writes SIEM JSONL to a file.

Plugin arguments

Flags after -- belong to the plugin. Flags before -- belong to om.

./om scan plugin --timeout 5m -- ./my-collector --region us-east-1

Stdout must be one JSON object. Stderr is diagnostics and is capped. The process inherits your environment, including cloud credentials. See Plugins.

Demo scan is destructive to the demo account

om scan demo deletes nodes whose account id belongs to the sample (111122223333 and cluster-demo), then inserts a fresh batch and runs rules. Other accounts in the same database stay. Cloud scans upsert. They do not delete resources that disappeared from the account, and they do not run rules.

Lines you should see

A cloud scan prints one line and exits:

Ingested 42 nodes and 17 edges from AWS account 123456789012 (us-east-1).

om rules run prints a match count and does not print each finding. Read them with GET /v1/findings or the console. om rules run with an unknown id exits with unknown rule.

om enrich cve prints Enrichment complete: N findings created, M updated. om export findings run --format siem writes JSON Lines to stdout and the count to stderr. Slack and Jira print Posted N findings to Slack. or Created N Jira issues. on stdout.

om graph stats is a JSON object with nodes, edges, and by_type. om paths run prints each path as node names. The same queries are documented on Attack paths.