Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/pages/docs/api.astro
Original file line number Diff line number Diff line change
Expand Up @@ -128,7 +128,7 @@ curl -s -H "Authorization: Bearer $OM_API_SECRET" \\
<p>
<code>GET /v1/graph/query?name=internet-to-datastore</code> returns <code>query</code>,
<code>summary</code>, and <code>paths</code>. Each path is an array of nodes. Unknown names
are 400. The five names are listed by <code>GET /v1/graph/queries</code> as
are 400. The six names are listed by <code>GET /v1/graph/queries</code> as
<code>{`{"queries":[{"name":"...","description":"..."}]}`}</code>. See
<a href="/docs/attack-paths/">Attack paths</a> for depth and row limits.
</p>
Expand Down
21 changes: 17 additions & 4 deletions src/pages/docs/attack-paths.astro
Original file line number Diff line number Diff line change
Expand Up @@ -6,12 +6,12 @@ import DocsLayout from '@/layouts/DocsLayout.astro';

<DocsLayout
title="OpenSourceOM attack path queries"
description="The five named queries om paths run executes, from the internet through workloads to datastores, plus public buckets and admin identities."
description="The six named queries om paths run executes, from the internet through workloads to datastores, including datastores marked with sensitivity."
faq={[
{
question: 'Which attack path queries does OpenSourceOM run?',
answer:
'om paths list prints five names. internet-to-datastore walks from the internet node and keeps paths that include a workload and end on a datastore. The other four are internet-to-workload, public-datastore, admin-identities, and admin-to-public-datastore. public-s3-buckets and toxic-s3-public-with-admin-role still run as aliases.',
'om paths list prints six names. internet-to-datastore walks from the internet node and keeps paths that include a workload and end on a datastore. internet-to-sensitive-datastore is that walk limited to datastores whose sensitivity property is set. The other four are internet-to-workload, public-datastore, admin-identities, and admin-to-public-datastore. public-s3-buckets and toxic-s3-public-with-admin-role still run as aliases.',
},
{
question: 'How do I run an attack path query?',
Expand All @@ -27,7 +27,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
>
<h1>OpenSourceOM attack path queries</h1>
<p>
Core ships five named queries. You run them from the CLI, the API, or the console’s query
Core ships six named queries. You run them from the CLI, the API, or the console’s query
dropdown. There is no ad-hoc graph language in this version. What attack path analysis means,
as a practice, is in
<a href="/blog/attack-path-analysis-cloud-security/">Attack path analysis</a>.
Expand Down Expand Up @@ -78,7 +78,20 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
<p>
Same walk, ending on a <code>Datastore</code>, and the path must include at least one
<code>Workload</code>. Recursion stops before depth 8. At most 50 paths are returned. This is
the query the demo prints after <code>om scan demo</code>.
the query the demo prints after <code>om scan demo</code>. It does not look at
<code>sensitivity</code>. A log bucket and a customer database on the same shape of path both
appear.
</p>

<h2>internet-to-sensitive-datastore</h2>
<p>
The same walk as <code>internet-to-datastore</code>, with the same depth and path caps, kept
only when the datastore’s <code>sensitivity</code> property is a non-empty string after
trimming. A missing property and a blank value stay in <code>internet-to-datastore</code> and
drop out of this one. The value itself is not ranked: <code>customer</code> and
<code>restricted</code> both count. Collectors copy it from a tag or label named
<code>sensitivity</code> or <code>data-class</code>. The demo marks <code>prod-db</code> and
leaves the log and asset buckets unmarked.
</p>

<h2>public-datastore</h2>
Expand Down
9 changes: 6 additions & 3 deletions src/pages/docs/collectors/aws.astro
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
</tr>
<tr>
<td>S3 bucket list, public access block, encryption, versioning</td>
<td><code>Datastore</code> with <code>service: s3</code>, <code>public_access</code>, <code>public_access_block</code> (<code>disabled</code> or enabled), <code>encryption</code>, <code>versioning</code>.</td>
<td><code>Datastore</code> with <code>service: s3</code>, <code>public_access</code>, <code>public_access_block</code> (<code>disabled</code> or enabled), <code>encryption</code>, <code>versioning</code>, and <code>sensitivity</code> when a bucket tag names it.</td>
</tr>
</tbody>
</table>
Expand Down Expand Up @@ -80,6 +80,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
<li><code>public_access_block</code> is <code>enabled</code> only when Block Public ACLs, Block Public Policy, Ignore Public ACLs, and Restrict Public Buckets are all true. Any other configuration, including a missing public access block, is <code>disabled</code>.</li>
<li><code>encryption</code> is true when default encryption has at least one rule. A missing encryption configuration is false.</li>
<li><code>versioning</code> is true only when versioning status is <code>Enabled</code>. Suspended is false.</li>
<li><code>sensitivity</code> is copied from a bucket tag named <code>sensitivity</code> or <code>data-class</code>. <code>sensitivity</code> wins when both are set. A blank value is omitted, and a failed tag read leaves the bucket unmarked. The same copy runs for an RDS <code>TagList</code>.</li>
</ul>
<p>
Node ids are <code>{'aws:{account}:{scope}:{kind}:{resource}'}</code>. EC2 instances and
Expand All @@ -91,7 +92,9 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
API reports no further page.
</p>
<p>
The collector does not inventory RDS, Lambda, EKS, VPCs, or IAM groups. Buckets are listed
The collector does not inventory Lambda, EKS, VPCs, or IAM groups. RDS and Aurora instances are
datastores, and their tags supply <code>sensitivity</code> the same way a bucket tag does.
Buckets are listed
account-wide. EC2 and security groups are the one region in <code>AWS_REGION</code>.
</p>

Expand All @@ -100,6 +103,6 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
A least-privilege policy for this collector needs read access for the calls above, including
<code>iam:GetInstanceProfile</code>, <code>iam:ListAttachedRolePolicies</code>,
<code>iam:ListRolePolicies</code>, <code>iam:GetRolePolicy</code>, <code>iam:GetPolicy</code>,
and <code>iam:GetPolicyVersion</code>. The scan does not call mutating APIs.
<code>iam:GetPolicyVersion</code>, and <code>s3:GetBucketTagging</code>. The scan does not call mutating APIs.
</p>
</DocsLayout>
9 changes: 5 additions & 4 deletions src/pages/docs/collectors/azure.astro
Original file line number Diff line number Diff line change
Expand Up @@ -13,8 +13,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
<code>om scan azure</code> requires <code>AZURE_SUBSCRIPTION_ID</code>. Authentication is
<code>DefaultAzureCredential</code>: Azure CLI (<code>az login</code>), environment variables
(<code>AZURE_TENANT_ID</code>, <code>AZURE_CLIENT_ID</code>, <code>AZURE_CLIENT_SECRET</code>),
or a managed identity. The scan covers one subscription. Network security groups, Key Vault,
and SQL are not inventoried.
or a managed identity. The scan covers one subscription. Key Vault is not inventoried.
</p>
<pre><code>{`export AZURE_SUBSCRIPTION_ID=00000000-0000-0000-0000-000000000000
az login
Expand Down Expand Up @@ -47,7 +46,7 @@ az login
</tr>
<tr>
<td>Storage accounts and blob containers</td>
<td><code>Datastore</code> with <code>resource_id</code> and <code>public_access</code>.</td>
<td><code>Datastore</code> with <code>resource_id</code>, <code>public_access</code>, and <code>sensitivity</code> when an account tag names it.</td>
</tr>
<tr>
<td>Role assignments at the subscription and on each storage account</td>
Expand Down Expand Up @@ -76,7 +75,9 @@ az login
<p>
An account that allows public blobs but has no container set to blob or container access is
stored with <code>public_access: false</code>. A missing resource group on the storage account
id fails the scan.
id fails the scan. A tag named <code>sensitivity</code> or <code>data-class</code> is stored
as <code>sensitivity</code>. <code>sensitivity</code> wins when both are set, and a blank
value is omitted. Logical SQL servers copy the same property from the server’s resource tags.
</p>

<h2>Admin identities</h2>
Expand Down
9 changes: 5 additions & 4 deletions src/pages/docs/collectors/gcp.astro
Original file line number Diff line number Diff line change
Expand Up @@ -13,8 +13,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
<code>om scan gcp</code> requires <code>GCP_PROJECT_ID</code>. Clients use Application Default
Credentials (<code>gcloud auth application-default login</code>,
<code>GOOGLE_APPLICATION_CREDENTIALS</code>, or the metadata server). The Compute client
requests the cloud-platform scope. One scan covers one project. Firewall rules, VPC networks,
and Cloud SQL are not inventoried.
requests the cloud-platform scope. One scan covers one project.
</p>
<pre><code>{`export GCP_PROJECT_ID=my-project
gcloud auth application-default login
Expand Down Expand Up @@ -43,7 +42,7 @@ gcloud auth application-default login
</tr>
<tr>
<td>Storage bucket list, then each bucket’s IAM policy</td>
<td><code>Datastore</code> with <code>resource_id</code> (bucket name) and <code>public_access</code>. Bucket IAM members that can read objects get <code>CAN_ACCESS</code> to that bucket.</td>
<td><code>Datastore</code> with <code>resource_id</code> (bucket name), <code>public_access</code>, and <code>sensitivity</code> when a bucket label names it. Bucket IAM members that can read objects get <code>CAN_ACCESS</code> to that bucket.</td>
</tr>
<tr>
<td>IAM service accounts, then the project IAM policy</td>
Expand Down Expand Up @@ -72,7 +71,9 @@ gcloud auth application-default login
Public access prevention is not read. A bucket can have prevention unset and still be stored
as private when those members are absent. <code>allUsers</code> on a role that cannot read
objects, such as <code>roles/storage.legacyBucketReader</code>, does not set
<code>public_access</code>.
<code>public_access</code>. A label named <code>sensitivity</code> or <code>data-class</code>
is stored as <code>sensitivity</code>. <code>sensitivity</code> wins when both are set, and a
blank value is omitted. Cloud SQL copies the same property from the instance’s user labels.
</p>

<h2>Service accounts and admin</h2>
Expand Down
6 changes: 5 additions & 1 deletion src/pages/docs/collectors/plugins.astro
Original file line number Diff line number Diff line change
Expand Up @@ -97,7 +97,11 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
for external collectors. Include <code>internet:global</code> when the batch should show up
in <a href="/docs/attack-paths/">attack path</a> queries. Set <code>public_access</code>,
<code>admin_access</code>, and the other keys on
<a href="/docs/schema/">Schema</a> when you want pack rules to match. On a workload,
<a href="/docs/schema/">Schema</a> when you want pack rules to match. On a datastore, set
<code>sensitivity</code> to a non-empty string to mark a crown jewel.
<code>internet-to-sensitive-datastore</code> keeps only those paths. Built-in collectors copy
that value from a tag or label named <code>sensitivity</code> or <code>data-class</code>; a
plugin sets the property itself. On a workload,
<code>packages</code>, <code>image</code>, and <code>images</code> are what
<code>om enrich cve</code> matches. A package entry is a CPE 2.3 name or a versioned package
URL. See <a href="/docs/enrichment/">CVE enrichment</a>.
Expand Down
2 changes: 1 addition & 1 deletion src/pages/docs/index.astro
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
<ul>
<li><a href="/docs/the-graph/">The graph</a> — nodes, edges, and how findings attach</li>
<li><a href="/docs/schema/">Schema</a> — node types, edge types, and ID format</li>
<li><a href="/docs/attack-paths/">Attack paths</a> — the five named queries</li>
<li><a href="/docs/attack-paths/">Attack paths</a> — the six named queries</li>
<li><a href="/docs/blast-radius/">Blast radius</a> — what an identity can reach</li>
<li><a href="/docs/prioritization/">Prioritization</a> — how graph context changes a score</li>
</ul>
Expand Down
1 change: 1 addition & 0 deletions src/pages/docs/schema.astro
Original file line number Diff line number Diff line change
Expand Up @@ -152,6 +152,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
</p>
<ul>
<li><code>public_access</code> (bool) — datastore is treated as public</li>
<li><code>sensitivity</code> (string) — crown-jewel mark on a datastore. Any non-empty value is enough. <code>internet-to-sensitive-datastore</code> keeps those paths, and <code>internet-to-datastore</code> does not filter on it. Collectors copy a tag or label named <code>sensitivity</code> or <code>data-class</code> (<code>sensitivity</code> wins). A blank value is omitted. A plugin may set the property directly. Object contents are not read.</li>
<li><code>public_access_block</code> — <code>disabled</code> matches the public-bucket query and a CIS-inspired rule</li>
<li><code>encryption</code>, <code>versioning</code>, <code>service</code> — S3 pack rules</li>
<li><code>open_ingress</code> — security group allows <code>0.0.0.0/0</code> or <code>::/0</code></li>
Expand Down
2 changes: 1 addition & 1 deletion src/pages/docs/the-graph.astro
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ import DocsLayout from '@/layouts/DocsLayout.astro';
{
question: 'How do I query the OpenSourceOM graph?',
answer:
'Run one of five named queries, such as om paths run internet-to-datastore, or open the same query in the web console. Blast radius is a separate command.',
'Run one of six named queries, such as om paths run internet-to-datastore, or open the same query in the web console. internet-to-sensitive-datastore keeps paths that end on a datastore whose sensitivity property is set. Blast radius is a separate command.',
},
]}
related={[
Expand Down
Loading