Need help with cloudmapper?
Click the “chat” button below for chat support from the developer who created it, or find similar developers for support.

About the developer

4.7K Stars 660 Forks BSD 3-Clause "New" or "Revised" License 877 Commits 210 Opened issues


CloudMapper helps you analyze your Amazon Web Services (AWS) environments.

Services available


Need anything else?

Contributors list


CloudMapper helps you analyze your Amazon Web Services (AWS) environments. The original purpose was to generate network diagrams and display them in your browser. It now contains much more functionality, including auditing for security issues.


  • audit
    : Check for potential misconfigurations.
  • collect
    : Collect metadata about an account. More details here.
  • find_admins
    : Look at IAM policies to identify admin users and roles, or principals with specific privileges. More details here.
  • find_unused
    : Look for unused resources in the account. Finds unused Security Groups, Elastic IPs, network interfaces, volumes and elastic load balancers.
  • prepare
    : See Network Visualizations
  • public
    : Find public hosts and port ranges. More details here.
  • sg_ips
    : Get geoip info on CIDRs trusted in Security Groups. More details here.
  • stats
    : Show counts of resources for accounts. More details here.
  • weboftrust
    : Show Web Of Trust. More details here.
  • report
    : Generate HTML report. Includes summary of the accounts and audit findings. More details here.
  • iam_report
    : Generate HTML report for the IAM information of an account. More details here.

If you want to add your own private commands, you can create a

directory and add them there.


Ideal layout

Report screenshot Findings summary
Findings IAM report
Command-line audit Command-line public command


Requirements: - python 3 (3.7.0rc1 is known to work),

, and
- You will also need
( and the library
(, which require some additional tools installed that will be shown.

On macOS:

# clone the repo
git clone
# Install pre-reqs for pyjq
brew install autoconf automake libtool jq awscli python3
cd cloudmapper/
python3 -m venv ./venv && source venv/bin/activate
pip install -r requirements.txt

On Linux: ```

clone the repo

git clone

(AWS Linux, Centos, Fedora, RedHat etc.):

sudo yum install autoconf automake libtool python3-devel.x86_64 python3-tkinter python-pip jq awscli

(Debian, Ubuntu etc.):

You may additionally need "build-essential"

sudo apt-get install autoconf automake libtool python3.7-dev python3-tk jq awscli cd cloudmapper/ python3 -m venv ./venv && source venv/bin/activate pip install -r requirements.txt ```

Run with demo data

A small set of demo data is provided. This will display the same environment as the demo site

# Generate the data for the network map
python prepare --config config.json.demo --account demo
# Generate a report
python report --config config.json.demo --account demo
python webserver

This will run a local webserver at View the network map from that link, or view the report at


  1. Configure information about your account.
  2. Collect information about an AWS account.

1. Configure your account

Copy the

and edit it to include your account ID and name (ex. "prod"), along with any external CIDR names. A CIDR is an IP range such as
which means only the IP

2. Collect data about the account

This step uses the CLI to make

calls and records the json in the folder specified by the account name under

AWS Privileges required

You must have AWS credentials configured that can be used by the CLI with read permissions for the different metadata to collect. I recommend using aws-vault. CloudMapper will collect IAM information, which means you MUST use MFA. Only the

step requires AWS access.

You must have the following privileges (these grant various read access of metadata):

  • arn:aws:iam::aws:policy/SecurityAudit
  • arn:aws:iam::aws:policy/job-function/ViewOnlyAccess

Collect the data

Collecting the data is done as follows:

python collect --account my_account

Analyze the data

From here, try running the different commands, such as:

python report --account my_account
python webserver

Then view the report in your browser at

Further configuration

Generating a config file

Instead of modifying

directly, there is a command to configure the data there, in case that is needed:
python configure {add-account|remove-account} --config-file CONFIG_FILE --name NAME --id ID [--default DEFAULT]
python configure {add-cidr|remove-cidr} --config-file CONFIG_FILE --cidr CIDR --name NAME

This will allow you to define the different AWS accounts you use in your environment and the known CIDR IPs.

If you use AWS Organizations, you can also automatically add organization member accounts to

python configure discover-organization-accounts

You need to be authenticated to the AWS CLI and have the permission

prior to running this command.

Using audit config overrides

You may find that you don't care about some of audit items. You may want to ignore the check entirely, or just specific resources. Copy

and edit the file based on the comments in there.

Using a Docker container

The docker container that is created is meant to be used interactively.

docker build -t cloudmapper .

Cloudmapper needs to make IAM calls and cannot use session credentials for collection, so you cannot use the aws-vault server if you want to collect data, and must pass role credentials in directly or configure aws credentials manually inside the container. The following code exposes your raw credentials inside the container.

    export $(aws-vault exec YOUR_PROFILE --no-session -- env | grep ^AWS | xargs) && \ 
    docker run -ti \
        -p 8000:8000 \
        cloudmapper /bin/bash

This will drop you into the container. Run

aws sts get-caller-identity
to confirm this was setup correctly. Cloudmapper demo data is not copied into the docker container so you will need to collect live data from your system. Note docker defaults may limit the memory available to your container. For example on Mac OS the default is 2GB which may not be enough to generate the report on a medium sized account.
python configure add-account --config-file config.json --name YOUR_ACCOUNT --id YOUR_ACCOUNT_NUMBER
python collect --account YOUR_ACCOUNT
python report --account YOUR_ACCOUNT
python prepare --account YOUR_ACCOUNT
python webserver --public

You should then be able to view the report by visiting

Running CloudMapper regularly to audit your environment

A CDK app for deploying CloudMapper via Fargate so that it runs nightly, sends audit findings as alerts to a Slack channel, and generating a report that is saved on S3, is described here.


For network diagrams, you may want to try or

For auditing and other AWS security tools see


  • cytoscape.js: MIT
  • cytoscape.js-qtip: MIT
  • cytoscape.js-grid-guide: MIT
  • cytoscape.js-panzoom: MIT
  • jquery: JS Foundation
  • jquery.qtip: MIT
  • cytoscape-navigator: MIT
  • cytoscape.js-autopan-on-drag: MIT
  • font-awesome: MIT
  • FileSave.js: MIT
  • circular-json: MIT
  • rstacruz/nprogress: MIT
  • mousetrap: Apache
  • akkordion MIT

We use cookies. If you continue to browse the site, you agree to the use of cookies. For more information on our use of cookies please see our Privacy Policy.