# ThreatMapper

Open Source Cloud Native Application Protection Platform (CNAPP)

Repository: https://github.com/deepfence/ThreatMapper
Canonical: https://ross.abutalabs.com/products/threatmapper
Homepage: https://threatmapper.org
Language: TypeScript
License: Apache-2.0
License Family: permissive
Topics: cloud-native, vulnerability-management, threat-analysis, devsecops, secops, registry-scanning, security-tools, cwpp, observability, cloudsecurity, vulnerability-scanners, vulnerability-detection, scanning-tool, cnapp, compliance, containers, cspm, devops, kubernetes
Last push: 2026-06-01T08:38:26+00:00
Link (homepage): https://threatmapper.org
Link (site_page): https://threatmapper.org/threatmapper/docs
Link (site_page): https://threatmapper.org/docs/secretscanner
Link (site_page): https://threatmapper.org/docs/yarahunter
Link (site_page): https://threatmapper.org/docs/packetstreamer

## Health v2 (maintenance only)
Score: 84/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 85, release rhythm 74, longevity 100
- inputs: {"age_days": 2400, "days_push": 93, "days_rel": 179, "gap_med": 17.5, "n_releases_24m": 13}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 5318, forks 631 (observed 2026-08-28T04:09:15.561977+00:00)

## What it is
Deepfence ThreatMapper is an open-source Cloud Native Application Protection Platform (CNAPP) that hunts threats in production cloud, Kubernetes, serverless, and on-prem environments, ranking them by risk-of-exploit. It bundles SecretScanner for exposed secrets and YaraHunter for malware indicators, generating runtime SBOMs and compliance checks.

## Use cases
- scan kubernetes clusters for vulnerabilities and misconfigurations
- find exposed secrets and api keys in container images
- detect malware in running docker containers
- generate runtime SBOMs from production workloads
- check cloud infrastructure against CIS and PCI-DSS compliance benchmarks
- prioritize vulnerabilities by risk of exploit
- visualize attack paths in cloud native applications

## When to choose
- you need runtime security observability for containers, Kubernetes, or serverless workloads
- you want a self-hosted, fully open-source CNAPP with no feature limits
- you need combined vulnerability, secret, malware, and compliance scanning in one console
- you want to rank threats by exploitability rather than raw CVSS scores

## When to avoid
- you only need lightweight CI-time image scanning without a management console
- you require a managed SaaS security product with vendor support
- your workloads are not containerized or cloud-based
- you need deep host-based endpoint detection beyond container and cloud scanning

## Facets
- artifact type: application
- maturity: active
- function: security, vulnerability-scanning, monitoring, secrets-management, container-runtime, container-orchestration
- domain: security, cloud-computing
- platform: cloud, self-hosted
- tags: cnapp, cwpp, cspm, devsecops, threat-detection, sbom, attack-path-analysis, runtime-security, yara, malware-scanning, compliance, containers, devops, kubernetes, docker, linux

## Member repositories
- deepfence/ThreatMapper (main) score 84
- deepfence/SecretScanner (plugin) score 74
- deepfence/YaraHunter (plugin) score 74

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:15.561977+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:58:55.900767+00:00, confidence not recorded.
  - readme: https://github.com/deepfence/ThreatMapper (fetched 2026-08-28T04:09:15.561977+00:00, sha 37e7356c6b96)
  - homepage: https://threatmapper.org (fetched 2026-08-29T08:54:02.669676+00:00, sha c03093397d26)
  - site_page: https://threatmapper.org/threatmapper/docs (fetched 2026-08-29T08:54:02.672669+00:00, sha c9153e69e36c)
  - site_page: https://threatmapper.org/docs/secretscanner (fetched 2026-08-29T08:54:02.674841+00:00, sha 2d1dea76647c)
  - site_page: https://threatmapper.org/docs/yarahunter (fetched 2026-08-29T08:54:02.676782+00:00, sha 5053c820e5ab)
  - site_page: https://threatmapper.org/docs/packetstreamer (fetched 2026-08-29T08:54:02.678516+00:00, sha 27d7b76db6b6)
  - site_page: https://threatmapper.org/docs/ebpfguard (fetched 2026-08-29T08:54:02.680262+00:00, sha 5fd56bd39a4f)
  - site_page: https://threatmapper.org/docs/flowmeter (fetched 2026-08-29T08:54:02.682756+00:00, sha aea13916f256)
- Data as of 2026-08-30T08:39:29.467469+00:00.
