21 مستودعات
Comprehensive toolkits, automation scripts, and assessment utilities for cloud environments.
Explore 21 awesome GitHub repositories matching part of an awesome list · Cloud Security Tooling and Automation. Refine with filters or upvote what's useful.
Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast
AWS security best practices assessment and hardening tool.
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
Curated collection of cloud security tools.
aws-vault is a secure credential manager and command-line wrapper for AWS. It stores long-term identity keys using the native operating system secure keystore to prevent plaintext secrets from residing on disk. The tool orchestrates the exchange of long-term credentials for short-lived temporary sessions by assuming IAM roles, with support for multi-factor authentication and integration with AWS Identity Center for single sign-on access. It prevents credential exposure by injecting these temporary tokens directly into subprocesses or by simulating local metadata endpoints for software develop
Secure storage utility for cloud credentials.
ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks. The tool provides auditing capabilities for AWS, Google Cloud, DigitalOcean, and Kubernetes clusters and control planes. It distinguishes itself by decoupling data collection from analysis, allowing users to cache cloud configurations locally for offline auditing and iterative rul
Multi-cloud infrastructure security auditing tool.
Visualization and analysis tool for cloud environments.
Pacu هو إطار عمل استغلال مصمم لتدقيق واختبار أمان بيئات Amazon Web Services. يعمل كأداة لاختبار اختراق السحابة ومعدد موارد يستخدم لتحديد التكوينات الخاطئة، ورسم خرائط أسطح الهجوم، وتنفيذ مسارات تصعيد الامتيازات. يوفر إطار العمل قدرات متخصصة لعمليات ما بعد الاستغلال والفريق الأحمر، بما في ذلك إنشاء الاستمرارية من خلال الأبواب الخلفية لإدارة الهوية والوصول. يتميز بنظام وحدات قائم على الإضافات يسمح بتطوير مهام مخصصة وتنسيق طلبات API عبر مناطق جغرافية متعددة. يغطي المشروع مجموعة واسعة من أنشطة تدقيق الأمان، بما في ذلك تعداد البنية التحتية، وتسريب البيانات من خدمات التخزين، وتدقيق الهوية. يتضمن أدوات لتنفيذ الكود عن بُعد عبر حقن الحمولة ونصوص بدء التشغيل، بالإضافة إلى قدرات لتعطيل خدمات الكشف وتحليل الحركة الجانبية للشبكة. يدير Pacu مفاتيح المصادقة الخاصة بالهدف وبيانات الجلسة الوصفية باستخدام حاويات معزولة وقاعدة بيانات محلية للحفاظ على الحالة وتقليل طلبات API.
AWS exploitation and penetration testing framework.
A Central Control Plane for AWS Permissions and Access
Centralized access control and permissions management.
Automating situational awareness for cloud penetration tests.
Situational awareness automation for cloud penetration tests.
AWS Auditing & Hardening Tool
Auditing and hardening utility for AWS accounts.
Collection of scripts and resources for DevSecOps and Automated Incident Response Security
Automation scripts for cloud incident response.
Open source demos, concept and guidance related to the AWS CIS Foundation framework.
CIS compliance and security benchmark automation.
Enhance the security of your web applications effortlessly with AWS Firewall Factory. Safeguard your valuable assets through seamless WAF deployment, updates, and staging, all centrally managed with AWS Firewall Manager.
Automated deployment tool for cloud firewalls.
Runs IAM policy linting and security checks against either a single AWS account or multiple member accounts of an AWS Organization.
Static analysis tool for identifying IAM policy issues.
Find S3 AWS/GCP/Azure buckets while surfing. S3DNS acts as DNS server, follows CNAMEs and matches any bucket pattern
Passive DNS reconnaissance tool for discovering cloud storage.
Fast, opinionated AWS security scanner. Curated checks. Zero noise. Copy-paste fixes.
Attack chain detector and remediation generator for cloud.
Comprehensive scanner for S3 security configurations.
Serverless security assessment platform with automated checks.
Serverless tracker for identity and access events.
Orchestration framework combining multiple cloud security scanners.