Cloud posture, runtime and code — one edge apart on one graph.
Netgraph runs cloud detection & response across AWS, Azure and GCP, continuous posture management with CIS benchmarks and policy-as-code, and CNAPP workload & IaC scanning — and lands every finding on the same security knowledge graph as endpoint, network and identity telemetry. A misconfiguration, the workload it exposes, the identity that can reach it and the alert that just fired are connected edges, not four consoles.
What ships in the module
From control plane to code — wired to the graph.
Posture meets runtime
A misconfig is a finding. A misconfig with a path to data is an incident.
Standalone CSPM tools rank misconfigurations in a vacuum. Netgraph traverses the graph from the misconfiguration to the workload running behind it, the identity that can reach it, and the data it exposes — so priority reflects real reachability, and the runtime alert that fires an hour later arrives already connected to its root cause.
- Misconfig → workload → identity → data — one traversal, one screen.
- Code findings (SAST / DAST) sit one edge from the workloads running that code.
- Blast radius spans cloud, endpoint, network and identity domains.
- Every correlated finding lands in the central alerts queue for autopilot triage.
Functionality map
Module functions at a glance
| Function | What it does | Where it lives |
|---|---|---|
| CDR | Control-plane ingest (CloudTrail-class, gcp.audit), identity monitoring, runtime detections, data-loss signals, cloud deception | Cloud ▸ CDR pages |
| CSPM | CIS benchmark checks, framework mapping, custom policy-as-code; auto-wired per enabled integration | Cloud ▸ CSPM pages |
| CNAPP | Workload & IaC scanning, drift detection, admission control, supply-chain / vulnerability graph | Cloud ▸ CNAPP — ten console pages |
| SAST | Static analysis, secret-leak detection with exploitability triage, SARIF ingest, Gitleaks | Code security pages |
| DAST | Dynamic web / API probing with Nuclei, scheduled scans | Code security pages |
| Cloud integrations | Connect AWS / Azure / GCP accounts with per-tenant vaulted credentials | SOC ▸ Ingest & Process ▸ Integrations |
| Central alerting | Cloud detections write to the central alerts table; L1 autopilot triages them | SOC ▸ Detect ▸ Alerts |
Works with everything on the graph
DSPM
Data classification tells the cloud graph what a misconfigured bucket actually holds — blast radius includes sensitivity.
Explore→NextGen SIEM
Cloud control-plane logs flow through the same streaming ingest, NQL and detection pipeline as every other source.
Explore→Agentic AI SOC
The L1 autopilot triages cloud detections from the central queue — and agent skills act through your enabled cloud integrations.
Explore→