← All Netgraph solutions
Cloud Security, CDR · CNAPP · CSPMCloud & Data Security

Cloud posture, runtime and code: one edge apart on one graph.

Netgraph runs cloud detection & response across AWS, Azure and GCP, continuous posture management with CIS benchmarks and policy-as-code, and CNAPP workload & IaC scanning, and lands every finding on the same security knowledge graph as endpoint, network and identity telemetry. A misconfiguration, the workload it exposes, the identity that can reach it and the alert that just fired are connected edges, not four consoles.

AWSAzureGCPCDR + CSPM + CNAPPSAST & DAST built inCIS benchmarks + policy-as-codeCross-domain blast radiusL1 autopilot on every finding

What ships in the module

From control plane to code, wired to the graph.

01

CDR: cloud detection & response

Control-plane log ingest (CloudTrail-class, gcp.audit), identity monitoring, runtime detections and data-loss signals across AWS, Azure and GCP, plus cloud-native deception to catch attackers who think nobody's watching.

02

CSPM: posture management

Benchmark checks against CIS, framework mapping, and custom policy-as-code. Posture collection auto-wires itself per enabled cloud integration, connect an account and checks start running.

03

CNAPP: workload & IaC

Workload and infrastructure-as-code scanning, drift detection, admission control and a supply-chain / vulnerability graph, ten console pages, all wired to the runtime graph rather than a static inventory.

04

SAST: code security

Static analysis with secret-leak detection and exploitability triage, SARIF ingest and Gitleaks, findings land on the same graph as runtime alerts, so a leaked key is one edge from the workload it opens.

05

DAST: dynamic probing

Dynamic web and API probing with Nuclei and scheduled scans, verify what's actually exploitable from the outside, on your cadence, with results correlated to the assets they hit.

06

Cross-domain correlation

Cloud findings correlate with endpoint, network and identity signals on one graph, blast radius spans domains, so "what can this misconfig reach?" is a traversal, not a meeting.

07

Central alerting & autopilot

Cloud detections write to the central alerts table alongside every other plane, and get the same L1 autopilot triage, case management and Take-Action menu as everything else.

08

Per-tenant vaulted credentials

Cloud credentials are vaulted per tenant, no shared secrets across tenants, and posture collection for each account runs strictly under its own tenant's credentials.

09

Drift & admission control

Detect when deployed infrastructure drifts from its declared IaC, and gate what's admitted in the first place, closing the loop between what you meant to run and what's running.

Posture meets runtime

A misconfig is a finding. A misconfig with a path to data is an incident.

Standalone CSPM tools rank misconfigurations in a vacuum. Netgraph traverses the graph from the misconfiguration to the workload running behind it, the identity that can reach it, and the data it exposes, so priority reflects real reachability, and the runtime alert that fires an hour later arrives already connected to its root cause.

  • Misconfig → workload → identity → data, one traversal, one screen.
  • Code findings (SAST / DAST) sit one edge from the workloads running that code.
  • Blast radius spans cloud, endpoint, network and identity domains.
  • Every correlated finding lands in the central alerts queue for autopilot triage.

Functionality map

Module functions at a glance

FunctionWhat it doesWhere it lives
CDRControl-plane ingest (CloudTrail-class, gcp.audit), identity monitoring, runtime detections, data-loss signals, cloud deceptionCloud ▸ CDR pages
CSPMCIS benchmark checks, framework mapping, custom policy-as-code; auto-wired per enabled integrationCloud ▸ CSPM pages
CNAPPWorkload & IaC scanning, drift detection, admission control, supply-chain / vulnerability graphCloud ▸ CNAPP, ten console pages
SASTStatic analysis, secret-leak detection with exploitability triage, SARIF ingest, GitleaksCode security pages
DASTDynamic web / API probing with Nuclei, scheduled scansCode security pages
Cloud integrationsConnect AWS / Azure / GCP accounts with per-tenant vaulted credentialsSOC ▸ Ingest & Process ▸ Integrations
Central alertingCloud detections write to the central alerts table; L1 autopilot triages themSOC ▸ Detect ▸ Alerts

See it live

Connect one cloud account. Watch posture meet runtime.