Diagramming using CloudMapper

Table Of Contents

The snowball effect for organizations & startups using AWS is a real thing. You may start experimenting with using one of the cloud platforms (AWS in this article) and soon to find out you have quite the labyrinth of policies, groups, users, access keys and more. This handy tool developed by the security company DUO (now owned by Cisco) will help you untangle the ball of yarn that started with a back & forth between you and the developers.

DUO CloudMapper is a tool that has grown from originally diagramming your AWS Virtual Private Cloud to now including IAM reports and much more.

A few examples of my personal favorite components of the CloudMapper tool are the resource aggregation along with the IAM reporting for identifying policy best-practices and potential problems.

Here are a few screenshots from the tool and it’s components:

principals layout report findings report findings summary
report findings summary

For installation, code repository and more visit the official DUO CloudMapper GitHub page. Cheers!

Share :

Related Posts

Backup AWS Route 53 using AWS Lambda

This has been updated to use AWS CDK and is much more refined. Check out: https://www.troydieter.com/post/r53_backups_2.0/ Need a way to automatically back up your AWS Route53 public DNS zones? Look no further, as a combination of the following AWS products can fit the need: Lambda Route53 CloudWatch S3 This will execute a Lambda function every 6 hours (or whichever you set the CloudWatch event to). It will use the IAM role to export your Route53 public zones as a CSV & JSON to the S3 bucket of your choice.

Read More

Shared Secret

Goal Create an end-to-end fully encrypted, publicly accessible secret storage tool

Read More