Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Continuous Integration and Continuous Delivery
  3. ThreatMapper

ThreatMapper

Apache-2.0TypeScriptv2.5.8

Open source CNAPP that hunts for threats in cloud native platforms, ranks them by risk, and visualizes attack paths.

Visit WebsiteGitHubGitHub
5.3k stars635 forks0 contributors

What is ThreatMapper?

ThreatMapper is an open-source Cloud Native Application Protection Platform (CNAPP) that hunts for security threats in production cloud-native environments. It identifies vulnerabilities, exposed secrets, and misconfigurations, then ranks them by risk and visualizes potential attack paths through its ThreatGraph feature. The platform helps security and DevOps teams maintain continuous security observability across their running applications and infrastructure.

Target Audience

Security engineers, DevOps teams, and platform engineers responsible for securing cloud-native applications and infrastructure across Kubernetes, Docker, cloud, and on-premises environments.

Value Proposition

Developers choose ThreatMapper because it provides a comprehensive, open-source CNAPP solution that combines agent-based and agent-less monitoring for wide coverage. Its unique ThreatGraph visualization helps prioritize high-risk threats, and its support for multiple platforms makes it adaptable to diverse cloud-native deployments without vendor lock-in.

Overview

Open Source Cloud Native Application Protection Platform (CNAPP)

Use Cases

Best For

  • Continuous security monitoring of production Kubernetes clusters
  • Identifying and prioritizing software vulnerabilities in running containerized applications
  • Visualizing attack paths and security risks in cloud-native environments
  • Checking cloud infrastructure compliance against security benchmarks (e.g., CIS)
  • Extending shift-left security practices into runtime protection
  • Securing hybrid deployments across cloud, on-premises, and serverless platforms

Not Ideal For

  • Teams exclusively focused on pre-deployment security (e.g., SAST/DAST) without runtime monitoring needs
  • Organizations with legacy on-premises systems not using containers or cloud-native technologies
  • Environments where deploying privileged agents is prohibited due to security or compliance policies
  • Projects requiring real-time behavioral threat detection or deep packet inspection, as it primarily scans for known vulnerabilities and misconfigurations

Pros & Cons

Pros

Hybrid Monitoring Coverage

Combines agent-based inspection for detailed host data (e.g., via Docker or Kubernetes sensors) with agent-less cloud scanning (using Terraform modules), ensuring wide threat detection across cloud and on-premises environments.

Multi-Platform Adaptability

Supports Kubernetes, Docker, AWS Fargate, ECS, bare-metal, and major cloud providers (AWS, Azure, GCP), making it versatile for diverse cloud-native deployments without vendor lock-in.

Risk-Based Threat Prioritization

Uses ThreatGraph visualization to map attack paths and rank threats by exploit risk, helping teams focus remediation on the most critical vulnerabilities and misconfigurations first.

Compliance Benchmark Integration

Checks host and cloud configurations against industry-expert benchmarks like CIS, aiding in regulatory compliance and security hardening directly from the Management Console.

Cons

Complex Multi-Component Deployment

Requires setting up the Management Console, Cloud Scanner tasks (via Terraform), and Sensor Agents across different platforms, which can be time-consuming and prone to configuration errors, as noted in the separate installation steps.

Agent Resource Overhead

Sensor agents run with privileged access (e.g., Docker command includes CPU limits and host mounts), potentially impacting performance in resource-constrained environments and raising operational concerns.

Limited to Supported Runtimes

While it covers many platforms, it may not support niche or custom container runtimes, and the agent-based approach requires compatibility with specific environments like Docker or Kubernetes, limiting flexibility.

Frequently Asked Questions

Quick Stats

Stars5,302
Forks635
Contributors0
Open Issues141
Last commit1 month ago
CreatedSince 2020

Tags

#container-security#vulnerability-management#observability#runtime-protection#cloudsecurity#devsecops#secops#security-tools#kubernetes-security#cloud-native#cloud-security#threat-detection

Built With

T
Terraform
K
Kubernetes
H
Helm
D
Docker

Links & Resources

Website

Included in

Docker35.8kStatic Analysis & Code Quality14.5kSecurity14.2kContinuous Integration and Continuous Delivery2.0kDevSecOps1.7k
Auto-fetched 4 hours ago

Related Projects

Metasploit FrameworkMetasploit Framework

Metasploit Framework

Stars38,642
Forks14,914
Last commit13 hours ago
trivytrivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Stars37,051
Forks552
Last commit17 hours ago
ESLintESLint

Find and fix problems in your JavaScript code.

Stars27,397
Forks5,117
Last commit23 hours ago
oxcoxc

⚓ A collection of high-performance JavaScript tools.

Stars22,074
Forks1,147
Last commit5 hours ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub