← All Netgraph solutions
Cloud Security — CDR · CNAPP · CSPMCloud & Data Security

Cloud posture, runtime and code — one edge apart on one graph.

Netgraph runs cloud detection & response across AWS, Azure and GCP, continuous posture management with CIS benchmarks and policy-as-code, and CNAPP workload & IaC scanning — and lands every finding on the same security knowledge graph as endpoint, network and identity telemetry. A misconfiguration, the workload it exposes, the identity that can reach it and the alert that just fired are connected edges, not four consoles.

AWSAzureGCPCDR + CSPM + CNAPPSAST & DAST built inCIS benchmarks + policy-as-codeCross-domain blast radiusL1 autopilot on every finding

What ships in the module

From control plane to code — wired to the graph.

01

CDR — cloud detection & response

Control-plane log ingest (CloudTrail-class, gcp.audit), identity monitoring, runtime detections and data-loss signals across AWS, Azure and GCP — plus cloud-native deception to catch attackers who think nobody's watching.

02

CSPM — posture management

Benchmark checks against CIS, framework mapping, and custom policy-as-code. Posture collection auto-wires itself per enabled cloud integration — connect an account and checks start running.

03

CNAPP — workload & IaC

Workload and infrastructure-as-code scanning, drift detection, admission control and a supply-chain / vulnerability graph — ten console pages, all wired to the runtime graph rather than a static inventory.

04

SAST — code security

Static analysis with secret-leak detection and exploitability triage, SARIF ingest and Gitleaks — findings land on the same graph as runtime alerts, so a leaked key is one edge from the workload it opens.

05

DAST — dynamic probing

Dynamic web and API probing with Nuclei and scheduled scans — verify what's actually exploitable from the outside, on your cadence, with results correlated to the assets they hit.

06

Cross-domain correlation

Cloud findings correlate with endpoint, network and identity signals on one graph — blast radius spans domains, so "what can this misconfig reach?" is a traversal, not a meeting.

07

Central alerting & autopilot

Cloud detections write to the central alerts table alongside every other plane — and get the same L1 autopilot triage, case management and Take-Action menu as everything else.

08

Per-tenant vaulted credentials

Cloud credentials are vaulted per tenant — no shared secrets across tenants, and posture collection for each account runs strictly under its own tenant's credentials.

09

Drift & admission control

Detect when deployed infrastructure drifts from its declared IaC, and gate what's admitted in the first place — closing the loop between what you meant to run and what's running.

Posture meets runtime

A misconfig is a finding. A misconfig with a path to data is an incident.

Standalone CSPM tools rank misconfigurations in a vacuum. Netgraph traverses the graph from the misconfiguration to the workload running behind it, the identity that can reach it, and the data it exposes — so priority reflects real reachability, and the runtime alert that fires an hour later arrives already connected to its root cause.

  • Misconfig → workload → identity → data — one traversal, one screen.
  • Code findings (SAST / DAST) sit one edge from the workloads running that code.
  • Blast radius spans cloud, endpoint, network and identity domains.
  • Every correlated finding lands in the central alerts queue for autopilot triage.

Functionality map

Module functions at a glance

FunctionWhat it doesWhere it lives
CDRControl-plane ingest (CloudTrail-class, gcp.audit), identity monitoring, runtime detections, data-loss signals, cloud deceptionCloud ▸ CDR pages
CSPMCIS benchmark checks, framework mapping, custom policy-as-code; auto-wired per enabled integrationCloud ▸ CSPM pages
CNAPPWorkload & IaC scanning, drift detection, admission control, supply-chain / vulnerability graphCloud ▸ CNAPP — ten console pages
SASTStatic analysis, secret-leak detection with exploitability triage, SARIF ingest, GitleaksCode security pages
DASTDynamic web / API probing with Nuclei, scheduled scansCode security pages
Cloud integrationsConnect AWS / Azure / GCP accounts with per-tenant vaulted credentialsSOC ▸ Ingest & Process ▸ Integrations
Central alertingCloud detections write to the central alerts table; L1 autopilot triages themSOC ▸ Detect ▸ Alerts

See it live

Connect one cloud account. Watch posture meet runtime.