awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to virtuesecurity/aws-extender

Open-source alternatives to Aws Extender

20 open-source projects similar to virtuesecurity/aws-extender, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Aws Extender alternative.

  • cloudflare/flancloudflare avatar

    cloudflare/flan

    4,162View on GitHub↗

    Flan is a containerized network vulnerability scanner and security auditor. It identifies open ports and service versions across a network to detect known security weaknesses and misconfigurations. The system is designed to run within isolated container environments, utilizing configuration maps to manage target lists and secrets. It includes a dedicated mechanism for archiving scan output files and security analysis data to remote S3 buckets for long-term storage. The tool generates formatted vulnerability summaries and security reports in multiple document formats for technical analysis. I

    Python
    View on GitHub↗4,162
  • anvilventures/aws-sigv4anvilventures avatar

    anvilventures/aws-sigv4

    22View on GitHub↗

    Anvil Secure's Burp extension for signing AWS requests with SigV4

    Java
    View on GitHub↗22
  • aquasecurity/trivyaquasecurity avatar

    aquasecurity/trivy

    36,462View on GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Gocontainersdevsecopsdocker
    View on GitHub↗36,462
  • belane/cloudhunterbelane avatar

    belane/CloudHunter

    195View on GitHub↗

    AWS, Azure, Alibaba and Google bucket scanner

    Python
    View on GitHub↗195

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • cloudsploit/scanscloudsploit avatar

    cloudsploit/scans

    3,748View on GitHub↗

    This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr

    JavaScript
    View on GitHub↗3,748
  • codewatchorg/burp-anonymouscloudcodewatchorg avatar

    codewatchorg/Burp-AnonymousCloud

    48View on GitHub↗

    Burp extension that performs a passive scan to identify cloud buckets and then test them for publicly accessible vulnerabilities

    Java
    View on GitHub↗48
  • eth0izzle/bucket-streameth0izzle avatar

    eth0izzle/bucket-stream

    1,809View on GitHub↗

    Find interesting Amazon S3 Buckets by watching certificate transparency logs.

    Python
    View on GitHub↗1,809
  • nccgroup/scoutsuitenccgroup avatar

    nccgroup/ScoutSuite

    7,548View on GitHub↗

    ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks. The tool provides auditing capabilities for AWS, Google Cloud, DigitalOcean, and Kubernetes clusters and control planes. It distinguishes itself by decoupling data collection from analysis, allowing users to cache cloud configurations locally for offline auditing and iterative rul

    Pythonauditingawsazure
    View on GitHub↗7,548
  • ncoblentz/burpmontoyacognitoncoblentz avatar

    ncoblentz/BurpMontoyaCognito

    8View on GitHub↗
    Java
    View on GitHub↗8
  • netspi/awssignerNetSPI avatar

    NetSPI/AWSSigner

    93View on GitHub↗

    Burp Extension for AWS Signing

    Java
    View on GitHub↗93
  • netspi/gcpwnN

    NetSPI/gcpwn

    0View on GitHub↗
    View on GitHub↗0
  • ozguralp/gmapsapiscannerozguralp avatar

    ozguralp/gmapsapiscanner

    1,178View on GitHub↗

    Used for determining whether a leaked/found Google Maps API Key is vulnerable to unauthorized access by other applications or not.

    Python
    View on GitHub↗1,178
  • portswigger/aws-security-checksPortSwigger avatar

    PortSwigger/aws-security-checks

    41View on GitHub↗

    AWS Security Checks

    Python
    View on GitHub↗41
  • praetorian-inc/aurelianP

    praetorian-inc/aurelian

    0View on GitHub↗
    View on GitHub↗0
  • rhinosecuritylabs/gcpbucketbruteRhinoSecurityLabs avatar

    RhinoSecurityLabs/GCPBucketBrute

    563View on GitHub↗

    A script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privilege escalated.

    Python
    View on GitHub↗563
  • rhinosecuritylabs/pacuRhinoSecurityLabs avatar

    RhinoSecurityLabs/pacu

    5,234View on GitHub↗

    Pacu is an exploitation framework designed for auditing and testing the security of Amazon Web Services environments. It serves as a cloud penetration testing tool and resource enumerator used to identify misconfigurations, map attack surfaces, and execute privilege escalation paths. The framework provides specialized capabilities for post-exploitation and red team operations, including establishing persistence through identity and access management backdooring. It distinguishes itself with a plugin-based module system that allows for the development of custom tasks and the orchestration of A

    Python
    View on GitHub↗5,234
  • salesforce/cloudsplainingsalesforce avatar

    salesforce/cloudsplaining

    2,226View on GitHub↗

    Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

    JavaScript
    View on GitHub↗2,226
  • streaak/keyhacksstreaak avatar

    streaak/keyhacks

    6,069View on GitHub↗

    Keyhacks is a command-line tool that tests whether API keys and tokens for dozens of cloud services are valid and active. It automates the verification of discovered credentials during security auditing and penetration testing, confirming if leaked or harvested API keys, tokens, and secrets are still operational. The tool validates credentials by sending lightweight, service-specific HTTP requests to each platform's API endpoint and inspecting the response status or body. Each validation runs independently without storing state between requests, using pre-defined request templates with the co

    View on GitHub↗6,069
  • andresriancho/enumerate-iamandresriancho avatar

    andresriancho/enumerate-iam

    1,242View on GitHub↗

    Enumerate the permissions associated with AWS credential set

    Python
    View on GitHub↗1,242
  • toniblyx/prowlertoniblyx avatar

    toniblyx/prowler

    14,005View on GitHub↗

    Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast

    Python
    View on GitHub↗14,005