Appliscale / cloud-security-audit
A command line security audit tool for Amazon Web Services
☆81Updated 6 years ago
Alternatives and similar repositories for cloud-security-audit:
Users that are interested in cloud-security-audit are comparing it to the libraries listed below
- 'Continuous' AWS perimeter monitoring: Periodically scan internet facing AWS resources to detect misconfigured services.☆64Updated 5 years ago
- A simple file-based scanner to look for potential AWS access and secret keys in files☆91Updated last year
- Route53/CloudFront Vulnerability Assessment Utility☆85Updated last year
- Lightspin AWS IAM Vulnerability Scanner☆96Updated 4 years ago
- Scan your EC2 instance to find its vulnerabilities using Vuls (https://vuls.io/en/)☆88Updated 2 years ago
- Visualize your Terraform files☆34Updated 4 years ago
- Manage GuardDuty At Enterprise Scale☆22Updated 4 years ago
- Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.☆76Updated 3 years ago
- Tools for AWS forensics☆63Updated 9 years ago
- Varna: Quick & Cheap AWS CloudTrail Monitoring with Event Query Language (EQL)☆51Updated 2 years ago
- A collection of slides, videos, and proof-of-concept scripts from various Rhino presentations.☆38Updated 6 years ago
- sgCheckup generates nmap output based on scanning your AWS Security Groups for unexpected open ports.☆81Updated 3 years ago
- This command line tool counts the number of resources in different categories across Amazon regions.☆57Updated 5 years ago
- Updated incident response generator for training classes☆43Updated 3 years ago
- IAMFinder enumerates and finds users and IAM roles in a target AWS account.☆111Updated 4 years ago
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Updated 3 years ago
- Pivot into private VPC networks using a VPN connection☆41Updated 5 years ago
- Assess certain AWS network configurations☆11Updated 6 years ago
- AppSecPipeline Specification for DevOps automation.☆40Updated 2 years ago
- Project intended to make Attack Maps part of software development by reducing the time it takes to complete them.☆48Updated 8 years ago
- Hayat is a script for report and analyze Google Cloud Platform resources.☆80Updated 5 years ago
- Dockerfile Security Checker using OPA Rego policies with Conftest☆59Updated 2 years ago
- Jekyll Files for cloudsecwiki.com☆50Updated 3 years ago
- Offensive Terraform Website☆44Updated 4 years ago
- SyntheticSun is a defense-in-depth security automation and monitoring framework which utilizes threat intelligence, machine learning, man…☆77Updated 3 years ago
- Tools to automate AWS Cloud security assessments☆24Updated 5 years ago
- Application Security Workflow Automation using Docker and Kubernetes☆22Updated 2 years ago
- OpenCSPM Community Controls☆14Updated 3 years ago
- Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).☆142Updated last year
- Monitoring GitHub for sensitive data shared publicly☆66Updated 3 years ago