// the find
deepfence/ThreatMapper
Open Source Cloud Native Application Protection Platform (CNAPP)
ThreatMapper is Deepfence's open-source CNAPP: a management console plus a mix of agent-based sensors and agentless cloud scanners that find vulnerabilities, exposed secrets, and misconfigurations across containers, Kubernetes, VMs, and cloud accounts, then graphs attack paths so you can prioritize. It's aimed at security/DevSecOps teams who already run production workloads on EKS/ECS/Fargate/bare metal and want runtime visibility, not just CI-time scanning.
ThreatGraph correlates findings into actual attack paths instead of dumping a flat CVE list, which is the real differentiator over plain scanners. Coverage is genuinely broad — Kubernetes (helm daemonset), Docker, ECS, Fargate sidecars, and bare metal are all first-class, plus agentless cloud scanner modules for AWS/Azure/GCP CSPM via Terraform. It already ships CI/CD integrations (GitHub Actions, Jenkins, GitLab, CircleCI) so shift-left and runtime data land in the same tool. Apache-2.0 licensed with the scanning engines (SecretScanner, YaraHunter, package-scanner) as separate submodules you could reuse independently.
The README is almost entirely marketing copy and links out to threatmapper.org — there's no architecture diagram, data flow, or component breakdown in-repo, so you can't evaluate the design without leaving GitHub. The sensor agent demands --privileged, --pid=host, --net=host, and a mounted docker.sock, which is a lot of host trust to grant for a security product and isn't addressed or justified here. The 'production' console deploy is a single docker-compose file with no story in the README for HA, backup, or upgrade paths, which doesn't inspire confidence for actual production use. It's a large multi-submodule monorepo (agent, scanners, compliance, cloud-scanner all as separate git commits/submodules), and the README gives no sense of how version compatibility across those pieces is managed. The prominent enterprise upsell (ThreatStryker) also makes it worth checking which features are gated before committing to this as your primary CNAPP.