awesome-repositories.com
المدونة
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعحولكيفية ترتيب النتائجالصحافةخادم MCP
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to cloudsploit/scans

Open-source alternatives to Scans

30 open-source projects similar to cloudsploit/scans, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Scans alternative.

  • nccgroup/scoutsuiteالصورة الرمزية لـ nccgroup

    nccgroup/ScoutSuite

    7,548عرض على GitHub↗

    ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks. The tool provides auditing capabilities for AWS, Google Cloud, DigitalOcean, and Kubernetes clusters and control planes. It distinguishes itself by decoupling data collection from analysis, allowing users to cache cloud configurations locally for offline auditing and iterative rul

    Pythonauditingawsazure
    عرض على GitHub↗7,548
  • toniblyx/prowlerالصورة الرمزية لـ toniblyx

    toniblyx/prowler

    14,005عرض على GitHub↗

    Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast

    Python
    عرض على GitHub↗14,005
  • aquasecurity/cloudsploitالصورة الرمزية لـ aquasecurity

    aquasecurity/cloudsploit

    3,705عرض على GitHub↗

    Cloudsploit is a cloud security posture management tool and multi-cloud security auditor. It audits cloud infrastructure for misconfigurations and compliance risks across multiple providers, specifically AWS and Azure, by evaluating resource configurations against a set of security plugins. The project functions as a cloud compliance scanner that maps infrastructure scan results to regulatory frameworks and security policy standards. It also serves as an automated cloud remediation tool, executing corrective actions to fix detected misconfigurations via SDK calls. The system covers resource

    JavaScriptalibabaaquaaws
    عرض على GitHub↗3,705

بحث بالذكاء الاصطناعي

استكشف المزيد من المستودعات الرائعة

صف ما تحتاجه بلغة بسيطة — وسيقوم الذكاء الاصطناعي بترتيب آلاف المشاريع مفتوحة المصدر المنسقة حسب الصلة.

Find more with AI search
  • alfresco/prowlerالصورة الرمزية لـ Alfresco

    Alfresco/prowler

    14,005عرض على GitHub↗

    Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for automating security audits, evaluating cloud infrastructure against regulatory compliance frameworks, and managing security assessments through a dedicated analysis dashboard. The project distinguishes itself by providing an AI-driven security context server that feeds structured data to AI assistants for automated risk analysis. It also employs graph-based attack path mapping to visualize potential lateral movement and exploitation routes across cloud inventories. The platform cove

    Python
    عرض على GitHub↗14,005
  • lyft/cartographyالصورة الرمزية لـ lyft

    lyft/cartography

    3,926عرض على GitHub↗

    Cartography is a graph-based infrastructure visualization and security analysis framework. It ingests data from diverse cloud, identity, and software-as-a-service providers to model complex relationships between resources, users, and security findings within a centralized graph database. By mapping these interdependencies, the platform enables organizations to gain visibility into their environment and identify potential security risks through graph traversal queries. The platform distinguishes itself through its ontology-based normalization and cross-platform entity correlation, which map he

    Python
    عرض على GitHub↗3,926
  • aquasecurity/kube-benchالصورة الرمزية لـ aquasecurity

    aquasecurity/kube-bench

    8,078عرض على GitHub↗

    kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to the Center for Internet Security standards and other hardening guides to identify security misconfigurations and vulnerabilities. The tool operates as a containerized security scanner, utilizing host namespaces to analyze nodes and control plane components without requiring the installation of binaries directly on the host. It supports multiple Kubernetes distributions, applying environment-specific benchmarks to ensure auditing accuracy for managed services. The project cover

    Go
    عرض على GitHub↗8,078
  • aquasecurity/trivyالصورة الرمزية لـ aquasecurity

    aquasecurity/trivy

    36,462عرض على GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Gocontainersdevsecopsdocker
    عرض على GitHub↗36,462
  • salesforce/cloudsplainingالصورة الرمزية لـ salesforce

    salesforce/cloudsplaining

    2,226عرض على GitHub↗

    Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

    JavaScript
    عرض على GitHub↗2,226
  • netflix/security_monkeyالصورة الرمزية لـ Netflix

    Netflix/security_monkey

    4,370عرض على GitHub↗

    Security Monkey is a cloud security posture management tool and configuration auditor. It functions as a monitoring platform that tracks cloud assets and records state changes to identify when security policies are altered or insecure configurations are introduced. The system maintains a multi-cloud asset inventory, tracking resources across AWS, GCP, OpenStack, and GitHub organizations. It provides a centralized interface for searching and browsing assets across multiple cloud providers and regions. The platform covers cloud security auditing and infrastructure change tracking by comparing

    Pythonawsaws-ec2aws-iam
    عرض على GitHub↗4,370
  • accurics/terrascanالصورة الرمزية لـ accurics

    accurics/terrascan

    5,210عرض على GitHub↗

    Terrascan is an infrastructure as code security scanner and cloud configuration auditor designed to detect security violations and compliance risks in cloud templates and Dockerfiles before provisioning. It utilizes the Open Policy Agent to evaluate infrastructure templates against both standard security policies and custom organizational rules. The project functions as a security guardrail within build pipelines, blocking risky deployments by integrating scanning logic directly into CI/CD workflows. It also includes a container registry vulnerability scanner that collects vulnerability data

    Go
    عرض على GitHub↗5,210
  • capitalone/cloud-custodianالصورة الرمزية لـ capitalone

    capitalone/cloud-custodian

    6,016عرض على GitHub↗

    Cloud Custodian is a multi-cloud governance engine and policy enforcement tool designed to automate security, compliance, and cost optimization across various cloud providers. It functions as a rules engine that uses a declarative domain specific language to query cloud resources and execute corrective actions based on predefined filters. The system operates as a serverless policy orchestrator, deploying provider-specific functions to trigger real-time enforcement in response to cloud resource changes. It provides a provider-agnostic resource abstraction to maintain consistent operational pol

    Python
    عرض على GitHub↗6,016
  • cloudquery/cloudqueryالصورة الرمزية لـ cloudquery

    cloudquery/cloudquery

    6,438عرض على GitHub↗

    CloudQuery is a cloud infrastructure ETL tool and multi-cloud data pipeline designed to collect, synchronize, and normalize resource metadata from various cloud providers and SaaS platforms. It functions as a centralized asset inventory manager and security posture manager, extracting configuration and state data into relational databases, data lakes, or data warehouses. The system distinguishes itself by transforming complex, nested cloud API responses into flat relational tables, enabling the use of standard SQL for asset querying and analysis. It employs a modular plugin system for data ex

    Goairbyteattack-surface-managementaws
    عرض على GitHub↗6,438
  • mlabouardy/komiserالصورة الرمزية لـ mlabouardy

    mlabouardy/komiser

    4,133عرض على GitHub↗

    Komiser is a multi-cloud infrastructure inspector and asset inventory manager. It provides a centralized system for auditing, cataloging, and analyzing deployed services and assets across AWS, GCP, and Azure environments. The project transforms disparate resource schemas from different cloud vendors into a unified structural representation through a provider-based plugin architecture. It uses agentless API inspection and polling-based resource discovery to retrieve metadata and configuration states without requiring agents on target resources. The platform covers financial management via cos

    Go
    عرض على GitHub↗4,133
  • bridgecrewio/checkovالصورة الرمزية لـ bridgecrewio

    bridgecrewio/checkov

    8,798عرض على GitHub↗

    Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as code, container images, and Kubernetes configurations. It functions as a cloud security posture tool, an SCA vulnerability scanner, and a secret scanning utility to prevent security breaches and version control leaks. The project distinguishes itself through deep graph analysis and variable resolution, allowing it to map relationships between interconnected resources and evaluate the final state of infrastructure attributes. It provides extensibility for defining custom security

    Python
    عرض على GitHub↗8,798
  • tenable/terrascanالصورة الرمزية لـ tenable

    tenable/terrascan

    5,210عرض على GitHub↗

    Terrascan is a static analysis tool designed to evaluate infrastructure-as-code configuration files for security vulnerabilities and compliance violations. By parsing these files into an intermediate representation, it identifies risks before cloud resources are provisioned, serving as a compliance auditor for cloud-native environments. The tool functions as a policy-as-code engine, allowing users to define and enforce custom security rules and industry benchmarks using a specialized query language. It distinguishes itself through its ability to integrate directly into development and deploym

    Go
    عرض على GitHub↗5,210
  • cloud-custodian/cloud-custodianالصورة الرمزية لـ cloud-custodian

    cloud-custodian/cloud-custodian

    6,011عرض على GitHub↗

    Cloud Custodian is an open-source rules engine that uses declarative YAML policies to query, filter, and take automated actions on cloud resources for governance and compliance. It functions as a stateless policy execution engine, where each policy evaluation runs as an independent, idempotent operation without maintaining internal state between runs. Policies are defined using a YAML-based domain-specific language that structures rules as a query-filter-action pipeline. The engine supports dry-run validation, allowing users to simulate policy actions against live resources without applying c

    Python
    عرض على GitHub↗6,011
  • deepfence/threatmapperالصورة الرمزية لـ deepfence

    deepfence/ThreatMapper

    5,282عرض على GitHub↗

    ThreatMapper is a cloud native application protection platform and infrastructure security scanner. It functions as a vulnerability management system and cloud workload telemetry collector designed to monitor workloads and detect security risks across cloud and container environments. The platform distinguishes itself through a network traffic visualizer that uses machine learning to classify communication patterns and a graph-based attack mapping system to identify high-risk paths between vulnerabilities and network dependencies. Its broader capabilities cover cloud infrastructure complianc

    TypeScriptcloud-nativecloudsecuritycnapp
    عرض على GitHub↗5,282
  • dependencytrack/dependency-trackالصورة الرمزية لـ DependencyTrack

    DependencyTrack/dependency-track

    3,612عرض على GitHub↗

    Dependency-Track is a software composition analysis tool and vulnerability management system designed to track dependencies and supply chain risk. It functions as a platform for ingesting and analyzing CycloneDX software bills of materials to identify known vulnerabilities and license compliance issues within third-party software components. The system distinguishes itself by mirroring external vulnerability databases locally to enable fast offline analysis and using VEX documents to differentiate between technical vulnerabilities and actual contextual risks. It also integrates with identity

    Javaappsecbill-of-materialsbom
    عرض على GitHub↗3,612
  • ravikiranvm/aws-finops-dashboardالصورة الرمزية لـ ravikiranvm

    ravikiranvm/aws-finops-dashboard

    1,259عرض على GitHub↗

    This project is a terminal-based command-line interface designed for cloud financial operations, cost management, and infrastructure auditing. It provides a unified dashboard for visualizing AWS expenditure, tracking budget adherence, and monitoring resource utilization across multiple accounts and regions. The tool distinguishes itself by aggregating data from diverse cloud profiles into a single view, allowing for cross-account governance and detailed spending analysis. It supports automated reporting workflows, enabling users to generate cost and audit summaries in multiple file formats an

    Python
    عرض على GitHub↗1,259
  • awslabs/automated-security-helperالصورة الرمزية لـ awslabs

    awslabs/automated-security-helper

    598عرض على GitHub↗

    The automated security helper is a command-line utility designed to orchestrate multiple security analysis tools into a unified, configuration-driven workflow. It functions as a central engine that executes static application security testing and infrastructure scans, aggregating diverse tool outputs into a standardized, machine-readable format to ensure consistent vulnerability detection across development lifecycles. The tool distinguishes itself through a modular plugin architecture that allows for the integration of custom or proprietary scanners, alongside an external intelligence layer

    Pythonawsawslabsiac
    عرض على GitHub↗598
  • securego/gosecالصورة الرمزية لـ securego

    securego/gosec

    8,866عرض على GitHub↗

    gosec is a static analysis security tool designed to scan Go source code for vulnerabilities and common coding flaws. It functions as a security analyzer that inspects the abstract syntax tree to identify insecure function calls, API usage, and potential security risks. The tool distinguishes itself by mapping detected vulnerabilities to Common Weakness Enumeration identifiers for standardized reporting and integrating with external AI models to suggest code fixes for identified issues. Its capabilities cover the detection of injection vulnerabilities, hardcoded credentials, weak cryptograph

    Go
    عرض على GitHub↗8,866
  • gitleaks/gitleaksالصورة الرمزية لـ gitleaks

    gitleaks/gitleaks

    24,973عرض على GitHub↗

    Gitleaks is a security scanning engine designed to identify hardcoded credentials, API keys, and other sensitive information within version control systems and local file structures. It functions as a static analysis tool that automates the detection of secrets, helping to prevent the accidental exposure of sensitive data during the development lifecycle. The tool distinguishes itself through its ability to perform deep forensic analysis of git history, allowing users to audit entire project timelines or enforce security gates within continuous integration pipelines. It supports complex detec

    Goai-poweredci-cdcicd
    عرض على GitHub↗24,973
  • darkbitio/aws-reconالصورة الرمزية لـ darkbitio

    darkbitio/aws-recon

    557عرض على GitHub↗

    Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.

    Ruby
    عرض على GitHub↗557
  • cyberark/skywrapperالصورة الرمزية لـ cyberark

    cyberark/SkyWrapper

    107عرض على GitHub↗

    SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS

    Python
    عرض على GitHub↗107
  • cyberark/skyarkالصورة الرمزية لـ cyberark

    cyberark/SkyArk

    912عرض على GitHub↗

    SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS

    PowerShell
    عرض على GitHub↗912
  • cisagov/sparrowالصورة الرمزية لـ cisagov

    cisagov/Sparrow

    1,430عرض على GitHub↗

    Sparrow.ps1 was created by CISA's Cloud Forensics team to help detect possible compromised accounts and applications in the Azure/m365 environment.

    PowerShell
    عرض على GitHub↗1,430
  • duo-labs/cloudmapperالصورة الرمزية لـ duo-labs

    duo-labs/cloudmapper

    6,259عرض على GitHub↗
    JavaScriptawscytoscapediagram
    عرض على GitHub↗6,259
  • awslabs/aws-security-benchmarkالصورة الرمزية لـ awslabs

    awslabs/aws-security-benchmark

    620عرض على GitHub↗

    Open source demos, concept and guidance related to the AWS CIS Foundation framework.

    Python
    عرض على GitHub↗620
  • eth0izzle/bucket-streamالصورة الرمزية لـ eth0izzle

    eth0izzle/bucket-stream

    1,809عرض على GitHub↗

    Find interesting Amazon S3 Buckets by watching certificate transparency logs.

    Python
    عرض على GitHub↗1,809
  • nccgroup/aws-inventoryالصورة الرمزية لـ nccgroup

    nccgroup/aws-inventory

    740عرض على GitHub↗

    Discover resources created in an AWS account.

    Python
    عرض على GitHub↗740