Self-hosted, graph-native cloud security — prioritize what attackers can actually reach.
The screenshot is the web console after docker compose up and om scan demo — internet-exposed web-1 on a path to prod-db, plus public S3 and an over-privileged admin role.
OpenSourceOM Core is the platform behind opensourceom.org: collectors that ingest cloud inventory and security signals, a graph engine that models attack paths, and APIs/UI to explore risk in context.
Traditional scanners flood you with CVEs and misconfigurations. OpenSourceOM connects the dots — showing which findings sit on paths from the internet to your sensitive data and privileged identities.
Status: Early development (Phase 3). CSPM rules, identity blast radius, Kubernetes ingest, exports, a collector plugin SDK, and a Helm chart are available. CVE findings follow package and image inventory. Datastores can carry a sensitivity mark from a tag or label. Current work is graph accuracy: attack-path findings, rule packs, and cloud audit ingest. See the roadmap.
CNAPP platforms demonstrated that context beats volume: a critical CVE on an isolated dev box is not the same as a high-severity issue on an internet-exposed path to production.
OpenSourceOM brings that graph-first model to teams that want:
- Transparency — inspect scoring, rules, and enrichment in code
- Control — run entirely in your VPC
- Community — extend collectors and policies without vendor lock-in
| Capability | Description |
|---|---|
| Security graph | Model workloads, identities, network paths, data stores, and findings as nodes and edges |
| Attack path analysis | Query reachable paths — e.g. internet → CVE → prod database |
| Risk prioritization | Rank findings by exposure, blast radius, and path length — not CVSS alone |
| CSPM | Graph-context policy rules with prioritized findings |
| Multi-cloud | AWS, Azure, GCP, and Kubernetes collectors |
Cloud APIs → Collectors → Normalizer → Graph Store → API / UI
↘ Rules Engine → Findings (with path context)
Graph schema (v0): nodes like Workload, Identity, Datastore, Finding; edges like REACHABLE, ASSUMES, AFFECTS.
Full design: docs/ARCHITECTURE.md
cmd/om/ `om` CLI (migrate, serve, scan, enrich, rules, identity, export)
sdk/collector/ Public SDK for external collector plugins
examples/collector/ Sample plugin (`om scan plugin`)
internal/collectors/ AWS, Azure, GCP, Kubernetes, demo graph
packs/ Embedded YAML CSPM rule packs
internal/rules/ CSPM rules engine with graph-context scoring
internal/graph/ Graph schema, Postgres store, path + blast-radius queries
internal/enrichment/ CVE lookup (NVD) and severity normalization
internal/export/ Slack, SIEM, Jira exporters
internal/api/ REST API + embedded web console
migrations/ Postgres schema migrations
docs/ Architecture, roadmap, ADRs
docker-compose.yml Local dev stack (Postgres + API)
deploy/helm/ Production Kubernetes chart
Phase 2 stack — Postgres, multi-cloud + Kubernetes collectors, CSPM rules, CVE enrichment, blast-radius analysis, exports, and a web console.
git clone https://github.com/OpenSourceOM/core.git
cd core
cp .env.example .env
# Start Postgres + API (http://localhost:8080)
docker compose up -d
# Build the CLI
go build -o om ./cmd/om
# Apply graph schema migrations
./om migrate
# Load the sample graph (no cloud credentials)
./om scan demo
# Or scan cloud / cluster inventory
export AWS_REGION=us-east-1
./om scan aws
./om scan k8s # requires kubeconfig
# Or ingest a custom collector (stdout is a graph batch)
go build -o example-collector ./examples/collector
./om scan plugin -- ./example-collector
# Run CSPM rules (builtin graph-context + embedded packs)
./om rules list
./om rules run
# Identity blast radius
./om identity blast-radius --name AdminRole
# Enrich with CVE data that matches workload inventory.
# The demo graph lists log4j 2.14.1 on web-1 and 2.17.1 on worker-1.
# NVD matches the CPE. This catalog is the offline equivalent.
./om enrich cve --catalog examples/cve-catalog.json
# Export findings
./om export findings run --format siem --out findings.jsonl
# Open the web console (click identities for blast radius)
open http://localhost:8080Compose sets OM_API_SECRET. The console sends that value as X-API-Key from localStorage.om_api_key on every /v1 call except health. Leave the secret empty to keep local API calls open.
API endpoints: GET /v1/health, POST /v1/ingest, GET /v1/findings, GET /v1/graph/snapshot, POST /v1/rules/run, GET /v1/identity/blast-radius
Multi-cloud scan:
./om scan demo # sample environment, no credentials
./om scan aws
./om scan azure # requires AZURE_SUBSCRIPTION_ID + az login
./om scan gcp # requires GCP_PROJECT_ID + ADC
./om scan k8s # requires kubeconfig or in-cluster credentials
./om scan plugin -- ./my-collectorFor local CLI-only use without Docker API, run docker compose up -d postgres and set POSTGRES_HOST=localhost.
Kubernetes:
docker build -t ghcr.io/opensourceom/core:0.2.1 .
helm install om deploy/helm/opensourceom \
--set api.secret='change-me' \
--set postgres.password='change-me' \
--set image.tag=0.2.1Collectors stay off until you enable one and supply credentials, an existing Secret, or serviceAccountAuth. The CronJob runs om scan against the same Postgres the API reads. om scan demo stays a one-shot command. See scan in deploy/helm/opensourceom/values.yaml.
Full documentation: opensourceom.org (docs at opensourceom.org/docs)
| Phase | Focus |
|---|---|
| 0 | Graph schema v0, AWS collector, ingest API, om CLI |
| 1 | Attack path queries, CVE enrichment, web UI, Azure/GCP collectors |
| 2 | CSPM rules, blast radius, K8s connector, exports |
| 3 (now) | Graph accuracy, crown-jewel datastores, attack-path findings, rule packs, cloud audit ingest |
Details: docs/ROADMAP.md
We welcome issues, discussions, and PRs.
- Read the roadmap and architecture
- Comment on an open issue, or open a discussion with the
roadmaplabel before a large change that is not tracked yet - Keep collectors read-only toward cloud accounts by default
- See CONTRIBUTING.md — PRs get an automatic CodeRabbit review once the GitHub App is installed on this repo
| Repo | Purpose |
|---|---|
| website | Marketing site and user docs |
| core | This repository |
Report vulnerabilities to security@opensourceom.org. Do not open public issues for security bugs. See SECURITY.md.
Apache-2.0 — see LICENSE.
