
Modellatore di minacce IaC con framework STRIDE, MITRE ATT&CK e PASTA. Supporto per REST API, GraphQL e Docker per Terraform, CloudFormation e Kubernetes.
Modellatore statico di minacce per IaC che analizza manifest Terraform, CloudFormation e Kubernetes e produce report strutturati di modelli di minaccia utilizzando i framework STRIDE, MITRE ATT&CK o PASTA. Nessuna chiamata di rete, nessuna credenziale cloud, completamente offline. Funziona come CLI, API REST o servizio containerizzato.
CLI:
pip install threatmap
threatmap scan ./examples --output report.md --fail-on HIGH
Docker:
docker run -v $(pwd):/workspace bogdynn/threatmap:2.1.0 threatmap scan /workspace --output /workspace/report.md
Server API REST:
threatmap serve --host 0.0.0.0 --port 8000
# Oppure tramite Docker:
docker run -p 8000:8000 bogdynn/threatmap:2.1.0
# Endpoint API: /health, /version, /rules, /analyze
API GraphQL:
docker run -p 8000:8000 bogdynn/threatmap:2.1.0
# Endpoint GraphQL: http://localhost:8000/graphql
# Query: health, version, rules
# Mutation: analyze(content, filename, framework)
| Formato | Provider | Estensione |
|---|---|---|
| Terraform HCL | AWS, Azure, GCP | .tf |
| CloudFormation | AWS | .yaml, .yml, .json |
| Kubernetes manifests | Kubernetes | .yaml, .yml |
Installa da PyPI:
pip install threatmap
Oppure per sviluppo locale:
git clone https://github.com/bogdanticu88/threatmap.git
cd threatmap
pip install -e .
Esegui la scansione di una directory e stampa un report Markdown su stdout:
threatmap scan ./terraform/
Esegui la scansione di più percorsi e scrivi un report JSON in un file:
threatmap scan ./terraform/ ./k8s/ ./cloudformation/ --format json --output report.json
Genera un report HTML interattivo o un report SARIF per GitHub Security:
threatmap scan ./infra/ --format html --output report.html
threatmap scan ./infra/ --format sarif --output report.sarif
Gate CI — codice di uscita 1 se viene trovata una minaccia CRITICAL o HIGH:
threatmap scan ./infra/ --fail-on HIGH --output threat-report.md
Stampa solo una tabella riepilogativa nel terminale, senza scrivere un report completo:
threatmap scan ./infra/ --summary
Usa indicatori di gravità solo ASCII (senza emoji) per ambienti che non supportano Unicode:
threatmap scan ./infra/ --ascii --output report.md
Analizza utilizzando diversi framework di modelli di minaccia:
# STRIDE (predefinito)
threatmap scan ./infra/ --framework stride
# MITRE ATT&CK (mappa a tattiche e tecniche)
threatmap scan ./infra/ --framework mitre --format json
# PASTA (modellazione di minacce incentrata sugli asset)
threatmap scan ./infra/ --framework pasta --format json
STRIDE (73 regole)
MITRE ATT&CK (11 regole, 14 tattiche)
PASTA (12 regole, incentrato sugli asset)
Eseguendo threatmap scan ./examples --output report.md sugli esempi inclusi si ottiene un report Markdown completo. Di seguito viene mostrato un estratto rappresentativo.
| ID | Gravità | Categoria STRIDE | Risorsa | Descrizione |
|---|---|---|---|---|
| T-001 | 🔴 CRITICAL | Information Disclosure | AuditBucket | Il bucket S3 'AuditBucket' non ha un blocco di accesso pubblico configurato — il bucket potrebbe essere accessibile pubblicamente. |
| T-002 | 🔴 CRITICAL | Spoofing | WebSecurityGroup | Il gruppo di sicurezza 'WebSecurityGroup' espone SSH/RDP (porta 22/3389) a 0.0.0.0/0. |
| T-003 | 🔴 CRITICAL | Elevation of Privilege | app_contributor | L'assegnazione di ruolo 'app_contributor' concede il ruolo privilegiato 'Contributor'. |
| T-006 | 🟠 HIGH | Information Disclosure | AuditBucket | Il bucket S3 'AuditBucket' non ha la crittografia lato server configurata. |
| T-008 | 🟠 HIGH | Elevation of Privilege | api | Il contenitore 'api' nel Deployment 'api' potrebbe essere eseguito come root (nessun runAsNonRoot=true o runAsUser=0). |
| T-011 | 🟠 HIGH | Elevation of Privilege | web | L'istanza EC2 'web' consente IMDSv1 — il servizio di metadati è accessibile senza token di sessione, consentendo il furto di credenziali basato su SSRF. |
### T-002 — Spoofing (CRITICAL)
Resource: AWS::EC2::SecurityGroup.WebSecurityGroup
Property: ingress.ssh_rdp_open
Finding: Il gruppo di sicurezza 'WebSecurityGroup' espone SSH/RDP (porta 22/3389) a 0.0.0.0/0.
Mitigation: Rimuovere l'accesso SSH/RDP pubblico. Utilizzare AWS Systems Manager Session Manager
o un bastion host con restrizioni IP.
Il report aggiunge un diagramma Mermaid flowchart LR. I nodi sono colorati in base alla gravità peggiore (🔴 rosso = CRITICAL, 🟠 arancione = HIGH). Incolla il blocco in qualsiasi renderer Mermaid o visualizzalo direttamente su GitHub.