Sample queries¶
Note: you might want to add LIMIT 30
at the end of these queries to make sure they return
quickly in case you have a large graph.
Which AWS IAM roles have admin permissions in my accounts?¶
MATCH (stmt:AWSPolicyStatement)--(pol:AWSPolicy)--(principal:AWSPrincipal)--(a:AWSAccount)
WHERE stmt.effect = "Allow"
AND any(x IN stmt.action WHERE x = '*')
RETURN *
Which AWS IAM roles in my environment have the ability to delete policies?¶
MATCH (stmt:AWSPolicyStatement)--(pol:AWSPolicy)--(principal:AWSPrincipal)--(acc:AWSAccount)
WHERE stmt.effect = "Allow"
AND any(x IN stmt.action WHERE x="iam:DeletePolicy" )
RETURN *
Note: can replace “iam:DeletePolicy
” to search for other IAM actions.
Which AWS IAM roles in my environment have an action that contains the word “create”?¶
MATCH (stmt:AWSPolicyStatement)--(pol:AWSPolicy)--(principal:AWSPrincipal)--(acc:AWSAccount)
WHERE stmt.effect = "Allow"
AND any(x IN stmt.action WHERE toLower(x) contains "create")
RETURN *
What RDS instances are installed in my AWS accounts?¶
MATCH (aws:AWSAccount)-[r:RESOURCE]->(rds:RDSInstance)
return *
Which RDS instances have encryption turned off?¶
MATCH (a:AWSAccount)-[:RESOURCE]->(rds:RDSInstance{storage_encrypted:false})
return a.name, rds.id
Which EC2 instances are exposed (directly or indirectly) to the internet?¶
MATCH (instance:EC2Instance{exposed_internet: true})
RETURN instance.instanceid, instance.publicdnsname
Which ELB LoadBalancers are internet accessible?¶
MATCH (elb:LoadBalancer{exposed_internet: true})—->(listener:ELBListener)
RETURN elb.dnsname, listener.port
ORDER by elb.dnsname, listener.port
Which ELBv2 LoadBalancerV2s (Application Load Balancers) are internet accessible?¶
MATCH (elbv2:LoadBalancerV2{exposed_internet: true})—->(listener:ELBV2Listener)
RETURN elbv2.dnsname, listener.port
ORDER by elbv2.dnsname, listener.port
Which S3 buckets have a policy granting any level of anonymous access to the bucket?¶
MATCH (s:S3Bucket)
WHERE s.anonymous_access = true
RETURN s
How many unencrypted RDS instances do I have in all my AWS accounts?¶
MATCH (a:AWSAccount)-[:RESOURCE]->(rds:RDSInstance)
WHERE rds.storage_encrypted = false
return a.name as AWSAccount, count(rds) as UnencryptedInstances
What users have the TotallyFake Chrome extension installed?¶
MATCH (u:GSuiteUser)-[r:INSTALLS]->(ext:ChromeExtension)
WHERE ext.name CONTAINS 'TotallyFake'
return ext.name, ext.version, u.email
What users have installed extensions that are risky based on CRXcavator scoring?¶
Risk > 200 is evidence of 3 or more critical risks or many high risks in the extension.
MATCH (u:GSuiteUser)-[r:INSTALLS]->(ext:ChromeExtension)
WHERE ext.risk_total > 200
return ext.name, ext.version, u.email
What languages are used in a given GitHub repository?¶
MATCH (:GitHubRepository{name:"myrepo"})-[:LANGUAGE]->(lang:ProgrammingLanguage)
RETURN lang.name
What are the dependencies used in a given GitHub repository?¶
MATCH (:GitHubRepository{name:"myrepo"})-[edge:REQUIRES]->(dep:Dependency)
RETURN dep.name, edge.specifier, dep.version
If you want to filter to just e.g. Python libraries:
MATCH (:GitHubRepository{name:"myrepo"})-[edge:REQUIRES]->(dep:Dependency:PythonLibrary)
RETURN dep.name, edge.specifier, dep.version
Given a dependency, which GitHub repos depend on it?¶
Using boto3 as an example dependency:
MATCH (dep:Dependency:PythonLibrary{name:"boto3"})<-[req:REQUIRES]-(repo:GitHubRepository)
RETURN repo.name, req.specifier, dep.version
What are all the dependencies used across all GitHub repos?¶
Just the list of dependencies and their versions:
MATCH (dep:Dependency)
RETURN DISTINCT dep.name AS name, dep.version AS version
ORDER BY dep.name
With info about which repos are using them:
MATCH (repo:GitHubRepository)-[edge:REQUIRES]->(dep:Dependency)
RETURN repo.name, dep.name, edge.specifier, dep.version
Lyft ingests this information into our internal data stack, which has enabled us to throw BI tooling on top for easy reporting - this is highly recommended!