diff --git a/src/pages/docs/api.astro b/src/pages/docs/api.astro index 4b91e16..ad50768 100644 --- a/src/pages/docs/api.astro +++ b/src/pages/docs/api.astro @@ -128,7 +128,7 @@ curl -s -H "Authorization: Bearer $OM_API_SECRET" \\
GET /v1/graph/query?name=internet-to-datastore returns query,
summary, and paths. Each path is an array of nodes. Unknown names
- are 400. The five names are listed by GET /v1/graph/queries as
+ are 400. The six names are listed by GET /v1/graph/queries as
{`{"queries":[{"name":"...","description":"..."}]}`}. See
Attack paths for depth and row limits.
- Core ships five named queries. You run them from the CLI, the API, or the console’s query + Core ships six named queries. You run them from the CLI, the API, or the console’s query dropdown. There is no ad-hoc graph language in this version. What attack path analysis means, as a practice, is in Attack path analysis. @@ -78,7 +78,20 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
Same walk, ending on a Datastore, and the path must include at least one
Workload. Recursion stops before depth 8. At most 50 paths are returned. This is
- the query the demo prints after om scan demo.
+ the query the demo prints after om scan demo. It does not look at
+ sensitivity. A log bucket and a customer database on the same shape of path both
+ appear.
+
+ The same walk as internet-to-datastore, with the same depth and path caps, kept
+ only when the datastore’s sensitivity property is a non-empty string after
+ trimming. A missing property and a blank value stay in internet-to-datastore and
+ drop out of this one. The value itself is not ranked: customer and
+ restricted both count. Collectors copy it from a tag or label named
+ sensitivity or data-class. The demo marks prod-db and
+ leaves the log and asset buckets unmarked.
Datastore with service: s3, public_access, public_access_block (disabled or enabled), encryption, versioning.Datastore with service: s3, public_access, public_access_block (disabled or enabled), encryption, versioning, and sensitivity when a bucket tag names it.public_access_block is enabled only when Block Public ACLs, Block Public Policy, Ignore Public ACLs, and Restrict Public Buckets are all true. Any other configuration, including a missing public access block, is disabled.encryption is true when default encryption has at least one rule. A missing encryption configuration is false.versioning is true only when versioning status is Enabled. Suspended is false.sensitivity is copied from a bucket tag named sensitivity or data-class. sensitivity wins when both are set. A blank value is omitted, and a failed tag read leaves the bucket unmarked. The same copy runs for an RDS TagList.
Node ids are {'aws:{account}:{scope}:{kind}:{resource}'}. EC2 instances and
@@ -91,7 +92,9 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
API reports no further page.
- The collector does not inventory RDS, Lambda, EKS, VPCs, or IAM groups. Buckets are listed
+ The collector does not inventory Lambda, EKS, VPCs, or IAM groups. RDS and Aurora instances are
+ datastores, and their tags supply sensitivity the same way a bucket tag does.
+ Buckets are listed
account-wide. EC2 and security groups are the one region in AWS_REGION.
iam:GetInstanceProfile, iam:ListAttachedRolePolicies,
iam:ListRolePolicies, iam:GetRolePolicy, iam:GetPolicy,
- and iam:GetPolicyVersion. The scan does not call mutating APIs.
+ iam:GetPolicyVersion, and s3:GetBucketTagging. The scan does not call mutating APIs.
om scan azure requires AZURE_SUBSCRIPTION_ID. Authentication is
DefaultAzureCredential: Azure CLI (az login), environment variables
(AZURE_TENANT_ID, AZURE_CLIENT_ID, AZURE_CLIENT_SECRET),
- or a managed identity. The scan covers one subscription. Network security groups, Key Vault,
- and SQL are not inventoried.
+ or a managed identity. The scan covers one subscription. Key Vault is not inventoried.
{`export AZURE_SUBSCRIPTION_ID=00000000-0000-0000-0000-000000000000
az login
@@ -47,7 +46,7 @@ az login
Storage accounts and blob containers
- Datastore with resource_id and public_access.
+ Datastore with resource_id, public_access, and sensitivity when an account tag names it.
Role assignments at the subscription and on each storage account
@@ -76,7 +75,9 @@ az login
An account that allows public blobs but has no container set to blob or container access is
stored with public_access: false. A missing resource group on the storage account
- id fails the scan.
+ id fails the scan. A tag named sensitivity or data-class is stored
+ as sensitivity. sensitivity wins when both are set, and a blank
+ value is omitted. Logical SQL servers copy the same property from the server’s resource tags.
Admin identities
diff --git a/src/pages/docs/collectors/gcp.astro b/src/pages/docs/collectors/gcp.astro
index f9adfc7..c6705c9 100644
--- a/src/pages/docs/collectors/gcp.astro
+++ b/src/pages/docs/collectors/gcp.astro
@@ -13,8 +13,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
om scan gcp requires GCP_PROJECT_ID. Clients use Application Default
Credentials (gcloud auth application-default login,
GOOGLE_APPLICATION_CREDENTIALS, or the metadata server). The Compute client
- requests the cloud-platform scope. One scan covers one project. Firewall rules, VPC networks,
- and Cloud SQL are not inventoried.
+ requests the cloud-platform scope. One scan covers one project.
{`export GCP_PROJECT_ID=my-project
gcloud auth application-default login
@@ -43,7 +42,7 @@ gcloud auth application-default login
Storage bucket list, then each bucket’s IAM policy
- Datastore with resource_id (bucket name) and public_access. Bucket IAM members that can read objects get CAN_ACCESS to that bucket.
+ Datastore with resource_id (bucket name), public_access, and sensitivity when a bucket label names it. Bucket IAM members that can read objects get CAN_ACCESS to that bucket.
IAM service accounts, then the project IAM policy
@@ -72,7 +71,9 @@ gcloud auth application-default login
Public access prevention is not read. A bucket can have prevention unset and still be stored
as private when those members are absent. allUsers on a role that cannot read
objects, such as roles/storage.legacyBucketReader, does not set
- public_access.
+ public_access. A label named sensitivity or data-class
+ is stored as sensitivity. sensitivity wins when both are set, and a
+ blank value is omitted. Cloud SQL copies the same property from the instance’s user labels.
Service accounts and admin
diff --git a/src/pages/docs/collectors/plugins.astro b/src/pages/docs/collectors/plugins.astro
index a2659f6..06e6009 100644
--- a/src/pages/docs/collectors/plugins.astro
+++ b/src/pages/docs/collectors/plugins.astro
@@ -97,7 +97,11 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
for external collectors. Include internet:global when the batch should show up
in attack path queries. Set public_access,
admin_access, and the other keys on
- Schema when you want pack rules to match. On a workload,
+ Schema when you want pack rules to match. On a datastore, set
+ sensitivity to a non-empty string to mark a crown jewel.
+ internet-to-sensitive-datastore keeps only those paths. Built-in collectors copy
+ that value from a tag or label named sensitivity or data-class; a
+ plugin sets the property itself. On a workload,
packages, image, and images are what
om enrich cve matches. A package entry is a CPE 2.3 name or a versioned package
URL. See CVE enrichment.
diff --git a/src/pages/docs/index.astro b/src/pages/docs/index.astro
index 6ad9c29..066b47d 100644
--- a/src/pages/docs/index.astro
+++ b/src/pages/docs/index.astro
@@ -50,7 +50,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
- The graph — nodes, edges, and how findings attach
- Schema — node types, edge types, and ID format
- - Attack paths — the five named queries
+ - Attack paths — the six named queries
- Blast radius — what an identity can reach
- Prioritization — how graph context changes a score
diff --git a/src/pages/docs/schema.astro b/src/pages/docs/schema.astro
index 786063e..bbf14fe 100644
--- a/src/pages/docs/schema.astro
+++ b/src/pages/docs/schema.astro
@@ -152,6 +152,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
public_access (bool) — datastore is treated as public
+ sensitivity (string) — crown-jewel mark on a datastore. Any non-empty value is enough. internet-to-sensitive-datastore keeps those paths, and internet-to-datastore does not filter on it. Collectors copy a tag or label named sensitivity or data-class (sensitivity wins). A blank value is omitted. A plugin may set the property directly. Object contents are not read.
public_access_block — disabled matches the public-bucket query and a CIS-inspired rule
encryption, versioning, service — S3 pack rules
open_ingress — security group allows 0.0.0.0/0 or ::/0
diff --git a/src/pages/docs/the-graph.astro b/src/pages/docs/the-graph.astro
index dba0bc5..fd9ecad 100644
--- a/src/pages/docs/the-graph.astro
+++ b/src/pages/docs/the-graph.astro
@@ -16,7 +16,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
{
question: 'How do I query the OpenSourceOM graph?',
answer:
- 'Run one of five named queries, such as om paths run internet-to-datastore, or open the same query in the web console. Blast radius is a separate command.',
+ 'Run one of six named queries, such as om paths run internet-to-datastore, or open the same query in the web console. internet-to-sensitive-datastore keeps paths that end on a datastore whose sensitivity property is set. Blast radius is a separate command.',
},
]}
related={[