awesome-repositories.com
المدونة
MCP
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعخادم MCPحولكيفية ترتيب النتائجالصحافة
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

14 مستودعات

Awesome GitHub RepositoriesCloud Security Auditing

Tools for enumerating and auditing cloud infrastructure and storage buckets.

Explore 14 awesome GitHub repositories matching part of an awesome list · Cloud Security Auditing. Refine with filters or upvote what's useful.

Awesome Cloud Security Auditing GitHub Repositories

اعثر على أفضل المستودعات باستخدام الذكاء الاصطناعي.سنبحث عن أفضل المستودعات المطابقة باستخدام الذكاء الاصطناعي.
  • aquasecurity/trivyالصورة الرمزية لـ aquasecurity

    aquasecurity/trivy

    36,462عرض على GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Comprehensive security scanner for cloud-native environments.

    Gocontainersdevsecopsdocker
    عرض على GitHub↗36,462
  • toniblyx/prowlerالصورة الرمزية لـ toniblyx

    toniblyx/prowler

    14,005عرض على GitHub↗

    Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast

    Security tool for cloud best practices, compliance, and forensics.

    Python
    عرض على GitHub↗14,005
  • nccgroup/scoutsuiteالصورة الرمزية لـ nccgroup

    nccgroup/ScoutSuite

    7,548عرض على GitHub↗

    ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks. The tool provides auditing capabilities for AWS, Google Cloud, DigitalOcean, and Kubernetes clusters and control planes. It distinguishes itself by decoupling data collection from analysis, allowing users to cache cloud configurations locally for offline auditing and iterative rul

    Multi-cloud security auditing tool for assessing environment posture.

    Pythonauditingawsazure
    عرض على GitHub↗7,548
  • streaak/keyhacksالصورة الرمزية لـ streaak

    streaak/keyhacks

    6,069عرض على GitHub↗

    Keyhacks is a command-line tool that tests whether API keys and tokens for dozens of cloud services are valid and active. It automates the verification of discovered credentials during security auditing and penetration testing, confirming if leaked or harvested API keys, tokens, and secrets are still operational. The tool validates credentials by sending lightweight, service-specific HTTP requests to each platform's API endpoint and inspecting the response status or body. Each validation runs independently without storing state between requests, using pre-defined request templates with the co

    Validates API keys found during bug bounty engagements.

    عرض على GitHub↗6,069
  • rhinosecuritylabs/pacuالصورة الرمزية لـ RhinoSecurityLabs

    RhinoSecurityLabs/pacu

    5,234عرض على GitHub↗

    Pacu هو إطار عمل استغلال مصمم لتدقيق واختبار أمان بيئات Amazon Web Services. يعمل كأداة لاختبار اختراق السحابة ومعدد موارد يستخدم لتحديد التكوينات الخاطئة، ورسم خرائط أسطح الهجوم، وتنفيذ مسارات تصعيد الامتيازات. يوفر إطار العمل قدرات متخصصة لعمليات ما بعد الاستغلال والفريق الأحمر، بما في ذلك إنشاء الاستمرارية من خلال الأبواب الخلفية لإدارة الهوية والوصول. يتميز بنظام وحدات قائم على الإضافات يسمح بتطوير مهام مخصصة وتنسيق طلبات API عبر مناطق جغرافية متعددة. يغطي المشروع مجموعة واسعة من أنشطة تدقيق الأمان، بما في ذلك تعداد البنية التحتية، وتسريب البيانات من خدمات التخزين، وتدقيق الهوية. يتضمن أدوات لتنفيذ الكود عن بُعد عبر حقن الحمولة ونصوص بدء التشغيل، بالإضافة إلى قدرات لتعطيل خدمات الكشف وتحليل الحركة الجانبية للشبكة. يدير Pacu مفاتيح المصادقة الخاصة بالهدف وبيانات الجلسة الوصفية باستخدام حاويات معزولة وقاعدة بيانات محلية للحفاظ على الحالة وتقليل طلبات API.

    Offensive security framework for testing AWS environments.

    Python
    عرض على GitHub↗5,234
  • cloudflare/flanالصورة الرمزية لـ cloudflare

    cloudflare/flan

    4,162عرض على GitHub↗

    Flan هو ماسح ثغرات شبكة حاوية ومدقق أمني. يحدد المنافذ المفتوحة وإصدارات الخدمة عبر الشبكة لاكتشاف نقاط الضعف الأمنية المعروفة والتكوينات الخاطئة. تم تصميم النظام للتشغيل داخل بيئات حاوية معزولة، مستخدماً خرائط التكوين لإدارة قوائم الأهداف والأسرار. يتضمن آلية مخصصة لأرشفة ملفات مخرجات المسح وبيانات التحليل الأمني إلى دلاء S3 بعيدة للتخزين طويل الأمد. تولد الأداة ملخصات ثغرات منسقة وتقارير أمنية بتنسيقات مستندات متعددة للتحليل التقني. تدعم تصدير بيانات المسح الخام إلى تخزين سحابي بعيد لتدقيق الأمن المركزي.

    Enables centralized security analysis by archiving network scan data to cloud storage.

    Python
    عرض على GitHub↗4,162
  • cloudsploit/scansالصورة الرمزية لـ cloudsploit

    cloudsploit/scans

    3,748عرض على GitHub↗

    This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr

    Detects security risks in cloud infrastructure accounts.

    JavaScript
    عرض على GitHub↗3,748
  • salesforce/cloudsplainingالصورة الرمزية لـ salesforce

    salesforce/cloudsplaining

    2,226عرض على GitHub↗

    Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

    Assesses AWS IAM policies for least privilege violations.

    JavaScript
    عرض على GitHub↗2,226
  • eth0izzle/bucket-streamالصورة الرمزية لـ eth0izzle

    eth0izzle/bucket-stream

    1,809عرض على GitHub↗

    Find interesting Amazon S3 Buckets by watching certificate transparency logs.

    Finds public S3 buckets by monitoring certificate transparency logs.

    Python
    عرض على GitHub↗1,809
  • andresriancho/enumerate-iamالصورة الرمزية لـ andresriancho

    andresriancho/enumerate-iam

    1,242عرض على GitHub↗

    Enumerate the permissions associated with AWS credential set

    Enumerates permissions for discovered AWS credentials.

    Python
    عرض على GitHub↗1,242
  • ozguralp/gmapsapiscannerالصورة الرمزية لـ ozguralp

    ozguralp/gmapsapiscanner

    1,178عرض على GitHub↗

    Used for determining whether a leaked/found Google Maps API Key is vulnerable to unauthorized access by other applications or not.

    Checks Google Maps API keys for unauthorized access vulnerabilities.

    Python
    عرض على GitHub↗1,178
  • virtuesecurity/aws-extenderالصورة الرمزية لـ VirtueSecurity

    VirtueSecurity/aws-extender

    258عرض على GitHub↗

    AWS Extender (Cloud Storage Tester) is a Burp plugin to assess permissions of cloud storage containers on AWS, Google Cloud and Azure.

    Burp Suite extension for identifying and testing cloud storage misconfigurations.

    Python
    عرض على GitHub↗258
  • netspi/gcpwnN

    NetSPI/gcpwn

    0عرض على GitHub↗

    Pentesting framework for enumerating and exploiting GCP environments.

    عرض على GitHub↗0
  • praetorian-inc/aurelianP

    praetorian-inc/aurelian

    0عرض على GitHub↗

    Unified framework for multi-cloud security reconnaissance.

    عرض على GitHub↗0
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Cloud Security Auditing