Skip to content

Every provider's file

Seven providers are read natively: AWS through its two export formats, GitHub through the assembled organization export (D-076), Kubernetes through the cluster's own dump (D-079), Google Cloud through a document of gcloud's own answers (D-080), Azure and Entra through a document of Graph's objects and the command line's output (D-081), Okta through a document of the management API's objects (D-082), and Active Directory through two doors, a document of the directory cmdlets' objects (D-083) and the SharpHound collector's zip (D-084), the second carrying the control rights that say who can obtain what without being a member. Every other provider on the list enters through the table door (D-074, D-078): a file of who holds what, read through a mapping, with the shipped template's columns as the default. A provider through the door gets the inventory, the authorization record, the delta, and campaigns the same day; what it does not get until it earns a parser of its own is credentials and their ages, second-factor state, activity, trust relationships, and the contents of a role definition, which is what the privilege findings read.

The recipes under recipes/ turn each provider's own export into the door's table, and a sample table per provider ships in sample-data so each can be tried at once. The jq recipes run in the test suite against inputs in the provider's documented shape, so a recipe that stops producing the table fails the build; the PowerShell and SQL recipes are documented and shipped, and their sample tables are the tested half.

Provider The provider's own export Recipe Sample table
Kubernetes Read natively (D-079): kubectl get roles,clusterroles,rolebindings,clusterrolebindings,serviceaccounts -A -o json through POST /imports/kubernetes-rbac, the cluster's name given beside the file recipes/kubernetes.jq remains for the table door observed-kubernetes.csv and the three kubernetes-rbac.json months
Google Cloud Read natively (D-080): one document holding gcloud projects describe, get-iam-policy, iam service-accounts list, and keys list outputs verbatim, through POST /imports/google-cloud recipes/google-cloud.jq remains for the table door observed-gcp.csv and the three google-cloud.json months
Azure and Entra Read natively (D-081): one document holding Graph's users, groups, service principals, directory roles, and eligibilities with each subscription's az role assignment list output, through POST /imports/azure-tenant recipes/azure.jq remains for the table door observed-azure.csv and the three azure-tenant.json months
Okta Read natively (D-082): one document holding the management API's users, groups, role assignments, custom roles, and applications with their assignments, through POST /imports/okta-org recipes/okta.jq remains for the table door observed-okta.csv and the three okta-org.json months
Active Directory Read natively (D-083, D-084): one document of Get-ADDomain, Get-ADUser, Get-ADGroup with Get-ADGroupMember, Get-ADComputer, and Get-ADTrust outputs through POST /imports/active-directory, or the SharpHound collector's zip through POST /imports/sharphound recipes/active-directory.ps1 remains for the table door observed-active-directory.csv, the three active-directory.json months, and the three sharphound.json months
Database (PostgreSQL) pg_roles and pg_auth_members, read by the script psql -v instance=NAME -f recipes/database.sql observed-database.csv
SaaS, generic Whatever table the system exports A mapping of its own columns the shipped template

What a recipe cannot carry is stated in its header. A Kubernetes group is a name the cluster cannot list the members of, so it enters as a group with no members; a Google Cloud binding's condition is not read; an Azure assignment at a resource group is filed under its subscription, and Entra directory roles and eligibilities are not in the command's output; an Okta role that arrives through a group records the hop without the group's name; a directory account's password age, last logon, service principal names, and control rights stay behind. Each of those is what the native parser for that provider carries, and every provider with a recipe except the database has one.