TiloBox
Back to directory
Cartography project preview

Cartography

Consolidate infrastructure assets and dependencies into an intuitive Neo4j graph database.

LicenseApache-2.0
GitHub stars4.5k
Last commit1 weeks ago
Tags5 topics
Lyft CartographyNeo4j Security MapCloud Asset GraphAttack Path AnalysisSecurity
Overview

Why consider Cartography?

Cartography is an open-source cloud security asset consolidation tool written in Python by Lyft. Cartography maps multi-cloud infrastructure assets (AWS, GCP, Azure, GitHub, Okta, Kubernetes) into a Neo4j graph database, illustrating complex lateral movement and privilege attack pathways.

Guided learning

Learn Cartography by building

Practical setup notes, real use cases, and copy-ready examples in one focused guide.

1 min read 2 sections
In this guide2 sections

Overview of Cartography

Cartography visualizes hidden infrastructure connections and cloud resource access permissions using graph queries.

Quickstart

bash
1pip install cartography
2cartography --neo4j-uri bolt://localhost:7687

Cartography is licensed under the Apache License Version 2.0.

Related tools

More options with a similar category or technology profile.

Cartography FAQs

Cartography is listed as a Security tool on TiloBox. Review the overview, features, and official documentation on this page to decide whether it solves your specific workflow.

Start with the project's GitHub repository for supported installation and deployment instructions. Test the setup with representative data or a small project before rolling it out more widely.

Cartography is listed under the Apache-2.0 license. Read the complete license text and the project's notices before using, modifying, or distributing the software.

Production readiness depends on your requirements. Review maintenance activity, security practices, documentation, backup and upgrade procedures, and compatibility with your stack; then validate it in a non-production environment.

Cartography is listed as an alternative to JupiterOne. Compare the core workflow, deployment model, integrations, and licensing against your must-have requirements before switching.