Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ OpenSourceOM Core is the platform behind [opensourceom.org](https://opensourceom

Traditional scanners flood you with CVEs and misconfigurations. OpenSourceOM connects the dots — showing which findings sit on paths from the internet to your sensitive data and privileged identities.

> **Status:** Early development (Phase 3). CSPM rules, identity blast radius, Kubernetes ingest, exports, a collector plugin SDK, and a Helm chart are available. CVE findings follow package and image inventory. Datastores can carry a sensitivity mark from a tag or label. A rules run writes an attack-path finding when a workload finding sits on a path to a datastore. `om scan aws` attaches recent CloudTrail management events, `om scan azure` attaches recent Activity Log events, and `om scan gcp` attaches recent Admin Activity audit logs, to the identity and resource on that path. That slice is [#74](https://github.com/OpenSourceOM/core/issues/74); Phase 3 closes when the issue is closed. Further rule packs stay open for contributors and do not gate the phase. See the [roadmap](./docs/ROADMAP.md).
> **Status:** Phase 3 has shipped. CSPM rules, identity blast radius, Kubernetes ingest, exports, a collector plugin SDK, and a Helm chart are available. CVE findings follow package and image inventory. Datastores can carry a sensitivity mark from a tag or label. A rules run writes an attack-path finding when a workload finding sits on a path to a datastore. `om scan aws` attaches recent CloudTrail management events, `om scan azure` attaches recent Activity Log events, and `om scan gcp` attaches recent Admin Activity audit logs, to the identity and resource on that path. Further rule packs stay open for contributors ([#10](https://github.com/OpenSourceOM/core/issues/10)). See the [roadmap](./docs/ROADMAP.md).

## Why this exists

Expand Down Expand Up @@ -160,7 +160,7 @@ Full documentation: [opensourceom.org](https://opensourceom.org) (docs at [opens
| **0** | Graph schema v0, AWS collector, ingest API, `om` CLI |
| **1** | Attack path queries, CVE enrichment, web UI, Azure/GCP collectors |
| **2** | CSPM rules, blast radius, K8s connector, exports |
| **3** *(now)* | Graph accuracy, crown-jewel datastores, attack-path findings, CloudTrail and Activity Log context. GCP Admin Activity logs ([#74](https://github.com/OpenSourceOM/core/issues/74)) close the phase. |
| **3** | Plugin SDK, Helm, embedded rule pack, demo graph, inventory-backed CVEs, crown-jewel datastores, attack-path findings, and cloud audit context (CloudTrail, Activity Log, Admin Activity). Shipped. |

Details: [docs/ROADMAP.md](./docs/ROADMAP.md)

Expand Down
8 changes: 4 additions & 4 deletions docs/ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ SPDX-License-Identifier: Apache-2.0

# Architecture

> **Status:** Phase 3. The ordered path is complete: the collector plugin SDK, Helm, the embedded rule pack, and cloud audit context from CloudTrail, Activity Log, and Admin Activity logs, alongside Phase 2 CSPM rules, blast radius, Kubernetes ingest, and exports. Further rule packs stay open for contributors.
> **Status:** Phase 3 has shipped. The collector plugin SDK, Helm, the embedded rule pack, and cloud audit context from CloudTrail, Activity Log, and Admin Activity logs are in the tree, alongside Phase 2 CSPM rules, blast radius, Kubernetes ingest, and exports. Further rule packs stay open for contributors.

## Overview

Expand Down Expand Up @@ -70,17 +70,17 @@ See [ADR 001](./adr/001-graph-schema-v0.md), [ADR 002](./adr/002-phase1-findings
- **Dev:** Docker Compose — Postgres + API (`docker compose up -d`); CLI can also target Postgres directly
- **Prod:** Helm chart in `deploy/helm/opensourceom/` (API, optional Postgres, optional scheduled collectors)

## What's next (Phase 3)
## Phase 3

Making the skeleton true, in order:
Shipped, in this order:

- Self-hosted operability (console). Read routes honor the API secret, and the Helm chart schedules collectors when credentials are set.
- CVE enrichment tied to workload inventory. `om enrich cve` writes a finding only when a workload package or image matches.
- Crown-jewel mark on datastores. A tag or label named `sensitivity` or `data-class` is stored on the datastore, and `internet-to-sensitive-datastore` keeps only those paths.
- Attack path as the finding. A rules run writes one `attack_path` finding per existing finding on an internet-reachable workload that can reach a datastore, and stores the path as ordered node ids.
- Cloud audit logs as graph context. `om scan aws` stores CloudTrail management events from the last 24 hours, `om scan azure` stores administrative Activity Log events from the same window, and `om scan gcp` stores Admin Activity audit logs from the same window, on the identity and resource they name when that resource is on an exposed path. `GET /v1/graph/query` returns those events in `audits` for each path that contains the resource. Entra ID sign-in logs, S3 data events such as `GetObject`, and GCP Data Access logs are not collected.

Further community rule packs (PCI and additional CIS mappings) stay open for contributors ([#10](https://github.com/OpenSourceOM/core/issues/10)). That issue does not close the phase.
Further community rule packs (PCI and additional CIS mappings) stay open for contributors ([#10](https://github.com/OpenSourceOM/core/issues/10)).

Issue links: [ROADMAP.md](./ROADMAP.md)

Expand Down
Loading