From df4d9618efa9721077779a95d8add46f1ab57bda Mon Sep 17 00:00:00 2001
From: O M
- Core ships five named queries. You run them from the CLI, the API, or the console’s query
+ Core ships six named queries. You run them from the CLI, the API, or the console’s query
dropdown. There is no ad-hoc graph language in this version. What attack path analysis means,
as a practice, is in
Attack path analysis.
@@ -78,7 +78,20 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
Same walk, ending on a
+ The same walk as
Node ids are
- The collector does not inventory RDS, Lambda, EKS, VPCs, or IAM groups. Buckets are listed
+ The collector does not inventory Lambda, EKS, VPCs, or IAM groups. RDS and Aurora instances are
+ datastores, and their tags supply GET /v1/graph/query?name=internet-to-datastore returns query,
summary, and paths. Each path is an array of nodes. Unknown names
- are 400. The five names are listed by GET /v1/graph/queries as
+ are 400. The six names are listed by GET /v1/graph/queries as
{`{"queries":[{"name":"...","description":"..."}]}`}. See
Attack paths for depth and row limits.
OpenSourceOM attack path queries
Datastore, and the path must include at least one
Workload. Recursion stops before depth 8. At most 50 paths are returned. This is
- the query the demo prints after om scan demo.
+ the query the demo prints after om scan demo. It does not look at
+ sensitivity. A log bucket and a customer database on the same shape of path both
+ appear.
+ internet-to-sensitive-datastore
+ internet-to-datastore, with the same depth and path caps, kept
+ only when the datastore’s sensitivity property is a non-empty string after
+ trimming. A missing property and a blank value stay in internet-to-datastore and
+ drop out of this one. The value itself is not ranked: customer and
+ restricted both count. Collectors copy it from a tag or label named
+ sensitivity or data-class. The demo marks prod-db and
+ leaves the log and asset buckets unmarked.
public-datastore
diff --git a/src/pages/docs/collectors/aws.astro b/src/pages/docs/collectors/aws.astro
index b724c90..43396c8 100644
--- a/src/pages/docs/collectors/aws.astro
+++ b/src/pages/docs/collectors/aws.astro
@@ -49,7 +49,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
@@ -80,6 +80,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
S3 bucket list, public access block, encryption, versioning
-
+ Datastore with service: s3, public_access, public_access_block (disabled or enabled), encryption, versioning.Datastore with service: s3, public_access, public_access_block (disabled or enabled), encryption, versioning, and sensitivity when a bucket tag names it.public_access_block is enabled only when Block Public ACLs, Block Public Policy, Ignore Public ACLs, and Restrict Public Buckets are all true. Any other configuration, including a missing public access block, is disabled.encryption is true when default encryption has at least one rule. A missing encryption configuration is false.versioning is true only when versioning status is Enabled. Suspended is false.sensitivity is copied from a bucket tag named sensitivity or data-class. sensitivity wins when both are set. A blank value is omitted, and a failed tag read leaves the bucket unmarked. The same copy runs for an RDS TagList.{'aws:{account}:{scope}:{kind}:{resource}'}. EC2 instances and
@@ -91,7 +92,9 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
API reports no further page.
sensitivity the same way a bucket tag does.
+ Buckets are listed
account-wide. EC2 and security groups are the one region in AWS_REGION.
iam:GetInstanceProfile, iam:ListAttachedRolePolicies,
iam:ListRolePolicies, iam:GetRolePolicy, iam:GetPolicy,
- and iam:GetPolicyVersion. The scan does not call mutating APIs.
+ iam:GetPolicyVersion, and s3:GetBucketTagging. The scan does not call mutating APIs.
om scan azure requires AZURE_SUBSCRIPTION_ID. Authentication is
DefaultAzureCredential: Azure CLI (az login), environment variables
(AZURE_TENANT_ID, AZURE_CLIENT_ID, AZURE_CLIENT_SECRET),
- or a managed identity. The scan covers one subscription. Network security groups, Key Vault,
- and SQL are not inventoried.
+ or a managed identity. The scan covers one subscription. Key Vault is not inventoried.
{`export AZURE_SUBSCRIPTION_ID=00000000-0000-0000-0000-000000000000
az login
@@ -47,7 +46,7 @@ az login
Storage accounts and blob containers
- Datastore with resource_id and public_access.
+ Datastore with resource_id, public_access, and sensitivity when an account tag names it.
Role assignments at the subscription and on each storage account
@@ -76,7 +75,9 @@ az login
An account that allows public blobs but has no container set to blob or container access is
stored with public_access: false. A missing resource group on the storage account
- id fails the scan.
+ id fails the scan. A tag named sensitivity or data-class is stored
+ as sensitivity. sensitivity wins when both are set, and a blank
+ value is omitted. Logical SQL servers copy the same property from the server’s resource tags.
Admin identities
diff --git a/src/pages/docs/collectors/gcp.astro b/src/pages/docs/collectors/gcp.astro
index f9adfc7..c6705c9 100644
--- a/src/pages/docs/collectors/gcp.astro
+++ b/src/pages/docs/collectors/gcp.astro
@@ -13,8 +13,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
om scan gcp requires GCP_PROJECT_ID. Clients use Application Default
Credentials (gcloud auth application-default login,
GOOGLE_APPLICATION_CREDENTIALS, or the metadata server). The Compute client
- requests the cloud-platform scope. One scan covers one project. Firewall rules, VPC networks,
- and Cloud SQL are not inventoried.
+ requests the cloud-platform scope. One scan covers one project.
{`export GCP_PROJECT_ID=my-project
gcloud auth application-default login
@@ -43,7 +42,7 @@ gcloud auth application-default login
Storage bucket list, then each bucket’s IAM policy
- Datastore with resource_id (bucket name) and public_access. Bucket IAM members that can read objects get CAN_ACCESS to that bucket.
+ Datastore with resource_id (bucket name), public_access, and sensitivity when a bucket label names it. Bucket IAM members that can read objects get CAN_ACCESS to that bucket.
IAM service accounts, then the project IAM policy
@@ -72,7 +71,9 @@ gcloud auth application-default login
Public access prevention is not read. A bucket can have prevention unset and still be stored
as private when those members are absent. allUsers on a role that cannot read
objects, such as roles/storage.legacyBucketReader, does not set
- public_access.
+ public_access. A label named sensitivity or data-class
+ is stored as sensitivity. sensitivity wins when both are set, and a
+ blank value is omitted. Cloud SQL copies the same property from the instance’s user labels.
Service accounts and admin
diff --git a/src/pages/docs/collectors/plugins.astro b/src/pages/docs/collectors/plugins.astro
index a2659f6..06e6009 100644
--- a/src/pages/docs/collectors/plugins.astro
+++ b/src/pages/docs/collectors/plugins.astro
@@ -97,7 +97,11 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
for external collectors. Include internet:global when the batch should show up
in attack path queries. Set public_access,
admin_access, and the other keys on
- Schema when you want pack rules to match. On a workload,
+ Schema when you want pack rules to match. On a datastore, set
+ sensitivity to a non-empty string to mark a crown jewel.
+ internet-to-sensitive-datastore keeps only those paths. Built-in collectors copy
+ that value from a tag or label named sensitivity or data-class; a
+ plugin sets the property itself. On a workload,
packages, image, and images are what
om enrich cve matches. A package entry is a CPE 2.3 name or a versioned package
URL. See CVE enrichment.
diff --git a/src/pages/docs/index.astro b/src/pages/docs/index.astro
index 6ad9c29..066b47d 100644
--- a/src/pages/docs/index.astro
+++ b/src/pages/docs/index.astro
@@ -50,7 +50,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
- The graph — nodes, edges, and how findings attach
- Schema — node types, edge types, and ID format
- - Attack paths — the five named queries
+ - Attack paths — the six named queries
- Blast radius — what an identity can reach
- Prioritization — how graph context changes a score
diff --git a/src/pages/docs/schema.astro b/src/pages/docs/schema.astro
index 786063e..bbf14fe 100644
--- a/src/pages/docs/schema.astro
+++ b/src/pages/docs/schema.astro
@@ -152,6 +152,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
public_access (bool) — datastore is treated as public
+ sensitivity (string) — crown-jewel mark on a datastore. Any non-empty value is enough. internet-to-sensitive-datastore keeps those paths, and internet-to-datastore does not filter on it. Collectors copy a tag or label named sensitivity or data-class (sensitivity wins). A blank value is omitted. A plugin may set the property directly. Object contents are not read.
public_access_block — disabled matches the public-bucket query and a CIS-inspired rule
encryption, versioning, service — S3 pack rules
open_ingress — security group allows 0.0.0.0/0 or ::/0
diff --git a/src/pages/docs/the-graph.astro b/src/pages/docs/the-graph.astro
index dba0bc5..fd9ecad 100644
--- a/src/pages/docs/the-graph.astro
+++ b/src/pages/docs/the-graph.astro
@@ -16,7 +16,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
{
question: 'How do I query the OpenSourceOM graph?',
answer:
- 'Run one of five named queries, such as om paths run internet-to-datastore, or open the same query in the web console. Blast radius is a separate command.',
+ 'Run one of six named queries, such as om paths run internet-to-datastore, or open the same query in the web console. internet-to-sensitive-datastore keeps paths that end on a datastore whose sensitivity property is set. Blast radius is a separate command.',
},
]}
related={[