riskprofiler / CloudFrontier
Monitor the internet attack surface of various public cloud environments. Currently supports AWS, GCP, Azure, DigitalOcean and Oracle Cloud.
โ124Updated last year
Alternatives and similar repositories for CloudFrontier:
Users that are interested in CloudFrontier are comparing it to the libraries listed below
- IAMFinder enumerates and finds users and IAM roles in a target AWS account.โ111Updated 4 years ago
- 'Continuous' AWS perimeter monitoring: Periodically scan internet facing AWS resources to detect misconfigured services.โ64Updated 5 years ago
- Find cloud assets that no one wants exposed ๐ โ๏ธโ344Updated 4 years ago
- ๐๏ธ STRIDE vs. ASVS equivalence tableโ76Updated 8 months ago
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.โ134Updated 5 years ago
- Monitoring GitHub for sensitive data shared publiclyโ66Updated 3 years ago
- Prevent SSRF attacks on AWS EC2 via automated upgrades to the more secure Instance Metadata Service v2 (IMDSv2).โ143Updated last week
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raiderโ139Updated 3 years ago
- A Docker container for remote penetration testing.โ135Updated 4 years ago
- Lightspin AWS IAM Vulnerability Scannerโ96Updated 4 years ago
- โ137Updated 2 years ago
- Presentations, training modules, and other education materials from Duo Security's Application Security team.โ73Updated 3 years ago
- sgCheckup generates nmap output based on scanning your AWS Security Groups for unexpected open ports.โ81Updated 3 years ago
- Scan your EC2 instance to find its vulnerabilities using Vuls (https://vuls.io/en/)โ88Updated 2 years ago
- Protect against subdomain takeoverโ92Updated 11 months ago
- A Cloud Security Posture Manager or CSPM with a focus on security analysis for the modern cloud stack and a focus on the emerging threat โฆโ186Updated 8 months ago
- A simple file-based scanner to look for potential AWS access and secret keys in filesโ91Updated last year
- All-in-one tool for managing vulnerability reports from AppSec pipelinesโ106Updated 2 years ago
- Cloud Security Dashboard for AWS - based on ScoutSuiteโ1Updated last year
- Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.โ76Updated 3 years ago
- Hayat is a script for report and analyze Google Cloud Platform resources.โ80Updated 5 years ago
- Cloud Security Operations Orchestratorโ184Updated last year
- ๐งฎ An online calculator to assess the risk of web vulnerabilities based on OWASP Risk Assessmentโ158Updated 3 years ago
- Clean accounts over permissions in GCP infra at scaleโ71Updated 2 years ago
- Fetch the details of assets hosted on AWS.โ88Updated last year
- Tools for AWS forensicsโ63Updated 9 years ago
- Scans Slack for API tokens, credentials, passwords, and more using YARA rulesโ38Updated 4 years ago
- FestIn - Open S3 Bucket Scannerโ234Updated 4 years ago
- SyntheticSun is a defense-in-depth security automation and monitoring framework which utilizes threat intelligence, machine learning, manโฆโ78Updated 3 years ago
- GCP GOAT is the vulnerable application for learn the GCP Securityโ64Updated last year