Get started

Cloud security collectors

A collector lists resources through a cloud or cluster API and returns a graph batch. The CLI upserts that batch into Postgres. Collectors do not open security groups, change IAM, or delete data. Give them read credentials.

./om scan aws
./om scan azure
./om scan gcp
./om scan k8s
./om scan plugin -- ./my-collector
./om scan demo

Cloud and Kubernetes scans print how many nodes and edges were ingested. They do not run CSPM rules. Follow a scan with om rules run when you want findings. om scan demo is the exception: it runs the catalog for you.

Built-in coverage

Command Inventory Credentials
om scan aws EC2, security groups, IAM roles and users, S3, instance-profile access to S3, recent CloudTrail management events AWS default chain, one region
om scan azure Virtual machines, storage accounts, subscription role assignments, recent Activity Log events DefaultAzureCredential and AZURE_SUBSCRIPTION_ID
om scan gcp Compute instances, GCS buckets, service accounts, recent Admin Activity audit logs Application Default Credentials and GCP_PROJECT_ID
om scan k8s Namespaces, pods, services, service accounts kubeconfig
om scan plugin Whatever the executable emits Inherited environment

How each collector marks the internet

Attack-path queries start at internet:global and follow edges. A resource with no REACHABLE edge is invisible to those queries even when a human would call it exposed. The collectors do not agree on what “exposed” means:

Collector REACHABLE when
AWS Instance has a public IPv4 address and an attached security group allows 0.0.0.0/0 or ::/0.
Azure The VM’s NIC resolves to a public IP address. Network security groups are not read.
GCP The instance has a NAT IP or sits behind a public load balancer, and a firewall allow is not covered by a higher-priority deny.
Kubernetes A LoadBalancer or NodePort Service selects the pod. Ingress and Gateway API are not read.

AWS CAN_ACCESS edges come from instance-profile allow statements. Azure edges come from role assignments whose scope covers the storage account. GCP edges come from project and bucket IAM on the service account the instance runs as. Details are on each collector page.

Upserts, not a full reconcile

A later scan updates rows with the same id. Resources that vanished from the account stay in the graph until you delete them. The demo command is the one scan that deletes first, and it only deletes the demo account ids.

Every built-in cloud batch includes the shared internet:global node so path queries have a start vertex. Plugins that want internet paths must include that node themselves. The id constant is internet:global in sdk/collector.

Questions

Which clouds can OpenSourceOM scan?

Built-in collectors cover AWS, Azure, GCP, and Kubernetes. om scan plugin ingests any other inventory that prints a graph batch to stdout.

Do OpenSourceOM collectors change my cloud account?

They call read APIs and upsert the result into Postgres. Give them a read-only role. A later scan updates the same node ids and does not delete resources that disappeared from the account.

Related reading