ENNAENNA

ThreatMapper

Apache-2.0

๐Ÿ“ฆ Container Security ยท Go

ThreatMapper is an open-source Cloud Native Application Protection Platform (CNAPP) developed by Deepfence that performs runtime vulnerability scanning, secret detection, and compliance auditing across cloud-native workloads and infrastructure. It deploys lightweight sensors into Kubernetes clusters, Docker hosts, and cloud environments to discover running workloads and scan them for known CVEs, exposed secrets, and compliance violations. DevSecOps teams and cloud security engineers use ThreatMapper to maintain continuous visibility into their containerized and serverless environments, prioritizing vulnerabilities based on runtime context rather than static severity scores alone. The platform provides a visual attack graph that maps exploit paths through the infrastructure, helping teams focus remediation efforts on the vulnerabilities that pose the greatest real-world risk.

5.3kstars
640forks
142issues
Updated 1mo ago

Tags

cloudcontainervulnerabilityruntimecloud-nativecloudsecuritycnappcompliancecontainerscspmcwppdevopsdevsecopskubernetesobservabilityregistry-scanningscanning-toolsecopssecurity-toolsthreat-analysisvulnerability-detectionvulnerability-managementvulnerability-scanners

Community Reviews

No reviews yet. Be the first to review ThreatMapper.

More in Container Security