From df4d9618efa9721077779a95d8add46f1ab57bda Mon Sep 17 00:00:00 2001 From: O M Date: Tue, 29 Sep 2026 15:59:01 -0400 Subject: [PATCH] Document the datastore sensitivity mark and the query that keeps only those paths. Co-authored-by: Cursor --- src/pages/docs/api.astro | 2 +- src/pages/docs/attack-paths.astro | 21 +++++++++++++++++---- src/pages/docs/collectors/aws.astro | 9 ++++++--- src/pages/docs/collectors/azure.astro | 9 +++++---- src/pages/docs/collectors/gcp.astro | 9 +++++---- src/pages/docs/collectors/plugins.astro | 6 +++++- src/pages/docs/index.astro | 2 +- src/pages/docs/schema.astro | 1 + src/pages/docs/the-graph.astro | 2 +- 9 files changed, 42 insertions(+), 19 deletions(-) diff --git a/src/pages/docs/api.astro b/src/pages/docs/api.astro index 4b91e16..ad50768 100644 --- a/src/pages/docs/api.astro +++ b/src/pages/docs/api.astro @@ -128,7 +128,7 @@ curl -s -H "Authorization: Bearer $OM_API_SECRET" \\

GET /v1/graph/query?name=internet-to-datastore returns query, summary, and paths. Each path is an array of nodes. Unknown names - are 400. The five names are listed by GET /v1/graph/queries as + are 400. The six names are listed by GET /v1/graph/queries as {`{"queries":[{"name":"...","description":"..."}]}`}. See Attack paths for depth and row limits.

diff --git a/src/pages/docs/attack-paths.astro b/src/pages/docs/attack-paths.astro index 8f1ba48..e0a181a 100644 --- a/src/pages/docs/attack-paths.astro +++ b/src/pages/docs/attack-paths.astro @@ -6,12 +6,12 @@ import DocsLayout from '@/layouts/DocsLayout.astro';

OpenSourceOM attack path queries

- Core ships five named queries. You run them from the CLI, the API, or the console’s query + Core ships six named queries. You run them from the CLI, the API, or the console’s query dropdown. There is no ad-hoc graph language in this version. What attack path analysis means, as a practice, is in Attack path analysis. @@ -78,7 +78,20 @@ import DocsLayout from '@/layouts/DocsLayout.astro';

Same walk, ending on a Datastore, and the path must include at least one Workload. Recursion stops before depth 8. At most 50 paths are returned. This is - the query the demo prints after om scan demo. + the query the demo prints after om scan demo. It does not look at + sensitivity. A log bucket and a customer database on the same shape of path both + appear. +

+ +

internet-to-sensitive-datastore

+

+ The same walk as internet-to-datastore, with the same depth and path caps, kept + only when the datastore’s sensitivity property is a non-empty string after + trimming. A missing property and a blank value stay in internet-to-datastore and + drop out of this one. The value itself is not ranked: customer and + restricted both count. Collectors copy it from a tag or label named + sensitivity or data-class. The demo marks prod-db and + leaves the log and asset buckets unmarked.

public-datastore

diff --git a/src/pages/docs/collectors/aws.astro b/src/pages/docs/collectors/aws.astro index b724c90..43396c8 100644 --- a/src/pages/docs/collectors/aws.astro +++ b/src/pages/docs/collectors/aws.astro @@ -49,7 +49,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro'; S3 bucket list, public access block, encryption, versioning - Datastore with service: s3, public_access, public_access_block (disabled or enabled), encryption, versioning. + Datastore with service: s3, public_access, public_access_block (disabled or enabled), encryption, versioning, and sensitivity when a bucket tag names it. @@ -80,6 +80,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
  • public_access_block is enabled only when Block Public ACLs, Block Public Policy, Ignore Public ACLs, and Restrict Public Buckets are all true. Any other configuration, including a missing public access block, is disabled.
  • encryption is true when default encryption has at least one rule. A missing encryption configuration is false.
  • versioning is true only when versioning status is Enabled. Suspended is false.
  • +
  • sensitivity is copied from a bucket tag named sensitivity or data-class. sensitivity wins when both are set. A blank value is omitted, and a failed tag read leaves the bucket unmarked. The same copy runs for an RDS TagList.
  • Node ids are {'aws:{account}:{scope}:{kind}:{resource}'}. EC2 instances and @@ -91,7 +92,9 @@ import DocsLayout from '@/layouts/DocsLayout.astro'; API reports no further page.

    - The collector does not inventory RDS, Lambda, EKS, VPCs, or IAM groups. Buckets are listed + The collector does not inventory Lambda, EKS, VPCs, or IAM groups. RDS and Aurora instances are + datastores, and their tags supply sensitivity the same way a bucket tag does. + Buckets are listed account-wide. EC2 and security groups are the one region in AWS_REGION.

    @@ -100,6 +103,6 @@ import DocsLayout from '@/layouts/DocsLayout.astro'; A least-privilege policy for this collector needs read access for the calls above, including iam:GetInstanceProfile, iam:ListAttachedRolePolicies, iam:ListRolePolicies, iam:GetRolePolicy, iam:GetPolicy, - and iam:GetPolicyVersion. The scan does not call mutating APIs. + iam:GetPolicyVersion, and s3:GetBucketTagging. The scan does not call mutating APIs.

    diff --git a/src/pages/docs/collectors/azure.astro b/src/pages/docs/collectors/azure.astro index 468ee5f..955f8a4 100644 --- a/src/pages/docs/collectors/azure.astro +++ b/src/pages/docs/collectors/azure.astro @@ -13,8 +13,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro'; om scan azure requires AZURE_SUBSCRIPTION_ID. Authentication is DefaultAzureCredential: Azure CLI (az login), environment variables (AZURE_TENANT_ID, AZURE_CLIENT_ID, AZURE_CLIENT_SECRET), - or a managed identity. The scan covers one subscription. Network security groups, Key Vault, - and SQL are not inventoried. + or a managed identity. The scan covers one subscription. Key Vault is not inventoried.

    {`export AZURE_SUBSCRIPTION_ID=00000000-0000-0000-0000-000000000000
     az login
    @@ -47,7 +46,7 @@ az login
             
             
               Storage accounts and blob containers
    -          Datastore with resource_id and public_access.
    +          Datastore with resource_id, public_access, and sensitivity when an account tag names it.
             
             
               Role assignments at the subscription and on each storage account
    @@ -76,7 +75,9 @@ az login
       

    An account that allows public blobs but has no container set to blob or container access is stored with public_access: false. A missing resource group on the storage account - id fails the scan. + id fails the scan. A tag named sensitivity or data-class is stored + as sensitivity. sensitivity wins when both are set, and a blank + value is omitted. Logical SQL servers copy the same property from the server’s resource tags.

    Admin identities

    diff --git a/src/pages/docs/collectors/gcp.astro b/src/pages/docs/collectors/gcp.astro index f9adfc7..c6705c9 100644 --- a/src/pages/docs/collectors/gcp.astro +++ b/src/pages/docs/collectors/gcp.astro @@ -13,8 +13,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro'; om scan gcp requires GCP_PROJECT_ID. Clients use Application Default Credentials (gcloud auth application-default login, GOOGLE_APPLICATION_CREDENTIALS, or the metadata server). The Compute client - requests the cloud-platform scope. One scan covers one project. Firewall rules, VPC networks, - and Cloud SQL are not inventoried. + requests the cloud-platform scope. One scan covers one project.

    {`export GCP_PROJECT_ID=my-project
     gcloud auth application-default login
    @@ -43,7 +42,7 @@ gcloud auth application-default login
             
             
               Storage bucket list, then each bucket’s IAM policy
    -          Datastore with resource_id (bucket name) and public_access. Bucket IAM members that can read objects get CAN_ACCESS to that bucket.
    +          Datastore with resource_id (bucket name), public_access, and sensitivity when a bucket label names it. Bucket IAM members that can read objects get CAN_ACCESS to that bucket.
             
             
               IAM service accounts, then the project IAM policy
    @@ -72,7 +71,9 @@ gcloud auth application-default login
         Public access prevention is not read. A bucket can have prevention unset and still be stored
         as private when those members are absent. allUsers on a role that cannot read
         objects, such as roles/storage.legacyBucketReader, does not set
    -    public_access.
    +    public_access. A label named sensitivity or data-class
    +    is stored as sensitivity. sensitivity wins when both are set, and a
    +    blank value is omitted. Cloud SQL copies the same property from the instance’s user labels.
       

    Service accounts and admin

    diff --git a/src/pages/docs/collectors/plugins.astro b/src/pages/docs/collectors/plugins.astro index a2659f6..06e6009 100644 --- a/src/pages/docs/collectors/plugins.astro +++ b/src/pages/docs/collectors/plugins.astro @@ -97,7 +97,11 @@ import DocsLayout from '@/layouts/DocsLayout.astro'; for external collectors. Include internet:global when the batch should show up in attack path queries. Set public_access, admin_access, and the other keys on - Schema when you want pack rules to match. On a workload, + Schema when you want pack rules to match. On a datastore, set + sensitivity to a non-empty string to mark a crown jewel. + internet-to-sensitive-datastore keeps only those paths. Built-in collectors copy + that value from a tag or label named sensitivity or data-class; a + plugin sets the property itself. On a workload, packages, image, and images are what om enrich cve matches. A package entry is a CPE 2.3 name or a versioned package URL. See CVE enrichment. diff --git a/src/pages/docs/index.astro b/src/pages/docs/index.astro index 6ad9c29..066b47d 100644 --- a/src/pages/docs/index.astro +++ b/src/pages/docs/index.astro @@ -50,7 +50,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro'; diff --git a/src/pages/docs/schema.astro b/src/pages/docs/schema.astro index 786063e..bbf14fe 100644 --- a/src/pages/docs/schema.astro +++ b/src/pages/docs/schema.astro @@ -152,6 +152,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';

    • public_access (bool) — datastore is treated as public
    • +
    • sensitivity (string) — crown-jewel mark on a datastore. Any non-empty value is enough. internet-to-sensitive-datastore keeps those paths, and internet-to-datastore does not filter on it. Collectors copy a tag or label named sensitivity or data-class (sensitivity wins). A blank value is omitted. A plugin may set the property directly. Object contents are not read.
    • public_access_block — disabled matches the public-bucket query and a CIS-inspired rule
    • encryption, versioning, service — S3 pack rules
    • open_ingress — security group allows 0.0.0.0/0 or ::/0
    • diff --git a/src/pages/docs/the-graph.astro b/src/pages/docs/the-graph.astro index dba0bc5..fd9ecad 100644 --- a/src/pages/docs/the-graph.astro +++ b/src/pages/docs/the-graph.astro @@ -16,7 +16,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro'; { question: 'How do I query the OpenSourceOM graph?', answer: - 'Run one of five named queries, such as om paths run internet-to-datastore, or open the same query in the web console. Blast radius is a separate command.', + 'Run one of six named queries, such as om paths run internet-to-datastore, or open the same query in the web console. internet-to-sensitive-datastore keeps paths that end on a datastore whose sensitivity property is set. Blast radius is a separate command.', }, ]} related={[