awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
lyft avatar

lyft/cartography

0
View on GitHub↗
3,926 stars·522 forks·Python·Apache-2.0·16 viewscartography.dev↗

Cartography

Cartography is a graph-based infrastructure visualization and security analysis framework. It ingests data from diverse cloud, identity, and software-as-a-service providers to model complex relationships between resources, users, and security findings within a centralized graph database. By mapping these interdependencies, the platform enables organizations to gain visibility into their environment and identify potential security risks through graph traversal queries.

The platform distinguishes itself through its ontology-based normalization and cross-platform entity correlation, which map heterogeneous data from multiple sources into a unified, consistent model. It employs modular ingestion pipelines and schema-based filtering to maintain this graph, ensuring that infrastructure data remains accurate through automated state-based pruning of stale nodes. This approach allows for the discovery of complex attack paths and security misconfigurations that span across disparate cloud, device, and identity management systems.

Beyond core modeling, the system provides extensive capabilities for asset inventory, identity governance, and software supply chain analysis. It supports a wide range of integrations, including cloud-native compute and networking resources, endpoint management telemetry, and development lifecycle metadata. Users can extend the platform’s functionality by defining custom security rules, adding specialized data analysis jobs, or integrating new intelligence sources through its modular framework.

The project is implemented in Python and provides documentation for configuring ingestion modules and defining custom graph queries.

Features

  • Infrastructure Knowledge Graphs - Models complex relationships between cloud resources, identity providers, and security findings within a centralized graph database.
  • Cross-Platform Links - Links identical assets across different platforms by matching shared attributes to maintain a unified entity view.
  • Data Normalization - Maps fields from heterogeneous source data into a unified semantic model for consistent entity representation.
  • Graph-Based Node Models - Stores infrastructure resources and their interdependencies as nodes and edges to enable complex relationship traversal and analysis.
  • Security Analysis Queries - Identifies infrastructure risks and attack paths by executing graph traversal queries against the aggregated environment model.
  • Semantic Normalization - Applies semantic labels and standardized properties to diverse resource types to enable consistent cross-platform queries.
  • Infrastructure Dependency Visualizations - Visualizes complex relationships between cloud resources, network components, and data stores to understand environment dependencies and risks.
  • Asset Inventory Aggregators - Consolidates hardware, software, and cloud resources into a unified asset ontology for visibility.
  • Attack Path Analysis - Identifies risky infrastructure patterns and potential attack vectors using graph-based queries.
  • Cloud Security Posture Management - Identifies attack paths and security misconfigurations by analyzing infrastructure relationships in a graph database.
  • Identity and Access Management - Maps users, groups, and permissions across identity providers to analyze effective access and identify over-privileged accounts.
  • Software Supply Chain Security - Traces container provenance and software dependencies from source repositories through CI/CD pipelines to production.
  • Graph Pruning - Automatically removes stale nodes and relationships from the graph to ensure infrastructure data remains accurate.
  • Internet Exposure Detection - Analyzes security group rules and load balancer schemes to flag assets reachable from the public internet.
  • Infrastructure Mappers - Ingests cloud assets and relationships into a graph database to enable dependency analysis.
  • Azure Data Factory Inventory - Models data factories, pipelines, datasets, and linked services to visualize data integration workflows.
  • Data Catalogs - Indexes tables, instances, and clusters to map the data layer across cloud environments for centralized visibility.
  • Pipeline Dependency Inventories - Ingests configuration and relationship data from data integration pipelines to analyze dependencies between data movement components.
  • Entity Mapping - Provides mechanisms to restrict canonical entity creation to trusted modules, ensuring data consistency across the graph.
  • Source Definitions - Restricts the creation of canonical user and device nodes to specific modules to ensure trusted data integrity.
  • Synchronization Pruning - Maintains data accuracy by automatically removing nodes and relationships that were not updated during the latest synchronization cycle.
  • Code Ownership Tools - Parses owner files to link repository paths to the users and teams responsible for them.
  • Software Dependency Catalogs - Extracts manifests and lockfiles to identify and inventory software packages and versions across repositories.
  • AWS Infrastructure Inventory - Transforms resource configurations and their relationships into a graph database to visualize dependencies across AWS environments.
  • Azure Compute Inventory - Catalogs virtual machines, clusters, and serverless functions, including operational state and network exposure.
  • Container Registry Inventory - Indexes container packages, images, tags, and layers from a registry to provide visibility into software supply chains.
  • Infrastructure Inventory - Discovers and catalogs DigitalOcean cloud assets to populate a graph database for dependency analysis.
  • AI Infrastructure Inventories - Ingests users, workspaces, and API keys to visualize relationships between AI infrastructure and organizational access points.
  • Cloudflare - Ingests account roles and network records into a graph database to visualize the relationships between edge security assets and web infrastructure.
  • Endpoint Fleet Inventories - Imports device objects and relationships to visualize managed endpoint fleets and security status.
  • Endpoint Management Inventories - Ingests configuration and device data to visualize the security posture of managed endpoint infrastructure.
  • Cloud Resource Inventory - Ingests Kubernetes cluster resources and their relationships into a graph database for infrastructure visualization.
  • Compute Resource Inventory - Maps virtual machines, serverless functions, and clusters into a graph database to create a comprehensive view of distributed compute assets and dependencies.
  • Infrastructure Security Audits - Executes pre-defined queries against graph-stored infrastructure data to identify potential attack surfaces, security gaps, and compliance violations.
  • Infrastructure Topology Mapping - Visualizes virtual networks, subnets, and gateways to map traffic flow and infrastructure dependencies.
  • Ingestion Filters - Limits the ingestion process to specific resource types to optimize synchronization performance and reduce data overhead.
  • Access Pattern Analysis - Queries the relationships between users, groups, and applications to identify software access patterns.
  • Authentication Flow Analysis - Models the sequence of authentication steps and execution requirements to visualize how users are authenticated.
  • Compliance Security Audits - Evaluates the current environment against sets of predefined security rules to identify framework violations.
  • Identity Correlation Tools - Links user accounts across multiple identity providers and platforms to create a unified view of identities.
  • Identity Data Ingestion - Ingests identity and access management data to visualize relationships between users, devices, and security policies.
  • Identity Provider Role Mapping - Infers effective user permissions by propagating group memberships and role assignments across a graph.
  • Security Asset Inventories - Ingests security telemetry and asset data to visualize infrastructure relationships within a graph database.
  • Security Finding Management - Aggregates vulnerabilities and security issues from multiple scanners into a unified graph to identify risks.
  • Security Monitoring - Aggregates vulnerability and threat detection data from cloud-native security services into a searchable graph for risk assessment.
  • Container Image Vulnerability Scanners - Parses security scan reports from container images to identify vulnerable base images and associated risks.
  • Custom Security Rule Definitions - Defines new security checks by writing queries to gather evidence and specifying a data model for findings.
  • Ontologies - Maps heterogeneous resource types from multiple providers into a standardized set of semantic labels and properties.
  • External API Ingestion Pipelines - Uses independent, pluggable modules to fetch data from diverse APIs and transform them into a unified graph structure.
  • AWS Security - Graph-based visualization of AWS infrastructure assets.
  • Identity and Access Management - Maps dependencies and relationships between services and cloud resources.
  • Security Assessment Tools - Consolidates infrastructure assets into a graph-based view.

Star history

Star history chart for lyft/cartographyStar history chart for lyft/cartography

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Cartography

Similar open-source projects, ranked by how many features they share with Cartography.
  • hashicorp/ottohashicorp avatar

    hashicorp/otto

    4,241View on GitHub↗

    Otto is a hybrid cloud orchestration platform designed to provision infrastructure and deploy application workloads across diverse cloud environments using infrastructure as code. It functions as an infrastructure as code provisioner that automates the deployment of consistent resources through policy-driven workflows. The project includes a hybrid cloud service mesh for managing service discovery and secure communication between applications, as well as an identity-based access controller for managing secrets and enforcing granular access controls. It also features an infrastructure knowledg

    HTML
    View on GitHub↗4,241
  • snyk/snyksnyk avatar

    snyk/snyk

    5,586View on GitHub↗

    Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source code, open-source dependencies, container images, and infrastructure-as-code configurations. It functions as a comprehensive security workflow automation tool, utilizing a static analysis engine and dependency graph mapping to detect security flaws and license compliance issues throughout the software development lifecycle. The platform distinguishes itself through agentic workflow orchestration and an automated remediation pipeline that generates and submits pull requests to patc

    TypeScript
    View on GitHub↗5,586
  • scanopy/scanopyscanopy avatar

    scanopy/scanopy

    4,092View on GitHub↗

    Scanopy is a self-hosted infrastructure inventory and network discovery tool. It identifies hosts, services, and workloads across subnets to build a live model of network infrastructure, maintaining a searchable catalog of assets. The system features an interactive network topology visualizer that generates physical, logical, and application dependency diagrams. It maps the nesting chain from physical hardware and hypervisors down to virtual machines and containers, utilizing SNMP for hardware metadata and container APIs for workload discovery. The platform supports distributed network scann

    Rustdocumentationdocumentation-generatordocumentation-tools
    View on GitHub↗4,092
  • infobyte/faradayinfobyte avatar

    infobyte/faraday

    6,523View on GitHub↗

    Faraday is a vulnerability management platform and security tool aggregator designed to centralize security findings from multiple scanners into a single dashboard. It utilizes a relational security database to catalog hosts, services, and security flaws, enabling users to track remediation and analyze organizational risk. The platform distinguishes itself through a plugin-based system that normalizes diverse security tool outputs into a unified data model. It supports deep integration with a wide array of scanners and CLI tools, intercepting shell command output or parsing report files to ag

    Python
    View on GitHub↗6,523
See all 30 alternatives to Cartography→

Frequently asked questions

What does lyft/cartography do?

Cartography is a graph-based infrastructure visualization and security analysis framework. It ingests data from diverse cloud, identity, and software-as-a-service providers to model complex relationships between resources, users, and security findings within a centralized graph database. By mapping these interdependencies, the platform enables organizations to gain visibility into their environment and identify potential security risks through graph traversal queries.

What are the main features of lyft/cartography?

The main features of lyft/cartography are: Infrastructure Knowledge Graphs, Cross-Platform Links, Data Normalization, Graph-Based Node Models, Security Analysis Queries, Semantic Normalization, Infrastructure Dependency Visualizations, Asset Inventory Aggregators.

What are some open-source alternatives to lyft/cartography?

Open-source alternatives to lyft/cartography include: hashicorp/otto — Otto is a hybrid cloud orchestration platform designed to provision infrastructure and deploy application workloads… snyk/snyk — Snyk is an application security testing platform designed to identify and remediate vulnerabilities across source… scanopy/scanopy — Scanopy is a self-hosted infrastructure inventory and network discovery tool. It identifies hosts, services, and… infobyte/faraday — Faraday is a vulnerability management platform and security tool aggregator designed to centralize security findings… owasp/top10 — This project is a web application security standard and vulnerability framework. It provides a comprehensive list of… veeral-patel/how-to-secure-anything — This project is a comprehensive security suite and knowledge base focused on the engineering and construction of…