CIOPages
DirectoryCybersecurityCloud Security & CSPMCloudmapper

Cloudmapper

Open Source

About Cloudmapper

CloudMapper is an open source cybersecurity tool designed to help enterprises analyze and audit their Amazon Web Services (AWS) environments. Originally developed to generate network diagrams, it has evolved to provide comprehensive security auditing capabilities, including identifying misconfigurations, unused resources, and privileged IAM roles. The tool is intended for security teams and cloud architects responsible for maintaining secure cloud infrastructure. CloudMapper enables continuous auditing and visibility into AWS accounts, helping organizations detect potential security risks and optimize resource usage.

The primary value proposition of CloudMapper lies in its ability to automate the collection and analysis of AWS metadata, offering actionable insights without the need for proprietary software. It supports various commands such as auditing for misconfigurations, finding administrative users, spotting unused resources, and generating detailed reports. Being open source, it allows enterprises to customize and extend its functionality to fit specific security policies and compliance requirements. CloudMapper is best suited for organizations with mature cloud security practices seeking a transparent and flexible tool to enhance their Cloud Security Posture Management (CSPM).

How to evaluate Cloud Security & CSPM

This is how the CIOPages Research Team evaluates this category. It is not an assessment of Cloudmapper. It comes from our Cloud Security Posture Management (CSPM) buyer guide.

25%
Risk Prioritization & Attack-Path Analysis
Context graph that correlates misconfiguration, internet reachability, identity/permissions, vulnerabilities, secrets, and data sensitivity into ranked attack paths to crown-jewel assets; toxic-combination detection; quality of the “fix these 10” output versus raw finding volume; false-positive rate in your own accounts
20%
Coverage Model: Agentless Breadth vs. Runtime Depth
Agentless snapshot/API scanning for fast 100%-estate visibility versus agent/eBPF runtime for in-production threat detection (CDR); container, serverless, and Kubernetes (KSPM) coverage; how the two models combine without double-counting; performance impact and deployment friction
20%
Multi-Cloud & Platform Consolidation (CNAPP)
Depth and parity across AWS, Azure, GCP, OCI, and Kubernetes from one console; how many of CSPM, CIEM, CWPP, DSPM, KSPM, and code/IaC security are genuinely unified on one data model versus bolted-on acquisitions; single policy and one risk score across domains
15%
Identity & Entitlements (CIEM)
Effective-permission analysis across human and machine identities, cross-account and federated role mapping, detection of unused and over-privileged entitlements, least-privilege right-sizing recommendations, and privilege escalation / lateral-movement path discovery
10%
Remediation, Automation & Developer Workflow
Guided and auto-remediation, IaC and pull-request fixes (shift-left to code), guardrails that prevent drift, ticketing/SOAR integration, ownership routing to the right team, and API/Terraform coverage for security-as-code
10%
Compliance, Reporting & SOC Integration
Out-of-the-box frameworks (CIS, PCI DSS, HIPAA, SOC 2, FedRAMP, NIST) with custom policy authoring, audit-ready evidence and drift history, RBAC/SSO on the console, and clean export of correlated cloud risk into the SIEM/SOC rather than a siloed dashboard

Related Buyer Guides

Our buyer guides across Cybersecurity. Each one compares the main vendors in its category and what buyers weigh up.

API Security Platforms
The API is now the primary attack surface, and a WAF pointed at it isn't API security. Evaluate Salt, Akamai (Noname), Imperva, F5, Traceable, Wallarm, Cequence, and Data Theorem on whether they actually discover your shadow APIs and catch BOLA and business-logic abuse at runtime — not just sign endpoints off as “protected.”
Attack Surface Management (ASM / CTEM)
Evaluate Wiz, CrowdStrike Falcon Surface, Microsoft Defender EASM, Cortex Xpanse, Censys, CyCognito, Tenable, and runZero across EASM, CAASM, and platform-embedded camps — judged on discovery accuracy and how cleanly the surface feeds prioritization, not how many assets it claims to find.
Cloud Access Security Broker (CASB)
Evaluate Netskope, Microsoft Defender for Cloud Apps, Zscaler, and Palo Alto for SaaS security, shadow IT discovery, and data protection.

CIOPages put this listing together from public sources. It’s information, not an endorsement. How we build listings. Work here? Claim this listing or .

Quick Facts

github.com/duo-labs/cloudmapper
CategoryCybersecurity
SubcategoryCloud Security & CSPM
FoundedNot on file
HeadquartersNot on file

We publish a detail only when we can point at the page it came from. Claim this listing to fill in the rest.