awesome-repositories.com
Blog
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektÜber unsRanking-MethodikPresseMCP-Server
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
aquasecurity avatar

aquasecurity/cloudsploit

0
View on GitHub↗
3,705 Stars·737 Forks·JavaScript·gpl-3.0·6 Aufrufecloud.aquasec.com/signup↗

Cloudsploit

Cloudsploit is a cloud security posture management tool and multi-cloud security auditor. It audits cloud infrastructure for misconfigurations and compliance risks across multiple providers, specifically AWS and Azure, by evaluating resource configurations against a set of security plugins.

The project functions as a cloud compliance scanner that maps infrastructure scan results to regulatory frameworks and security policy standards. It also serves as an automated cloud remediation tool, executing corrective actions to fix detected misconfigurations via SDK calls.

The system covers resource risk analysis and security scanning, allowing for the development of custom security plugins to define specialized test logic. It includes capabilities for cross-account role scanning, finding suppression using regular expressions, and the export of audit results into formats such as JSON, CSV, and JUnit.

The scanner utilizes API response caching to reduce redundant network requests across plugins and provides visualization for security findings through printable reports and a visual interface.

Features

  • Cloud Infrastructure Security - Audits cloud infrastructure across multiple accounts for security misconfigurations using specialized plugins.
  • Cloud Compliance Auditors - Maps cloud infrastructure scan results to regulatory frameworks and security policy standards for compliance auditing.
  • Security Risk Assessments - Evaluates collected cloud data against security rules to assign risk levels from pass to fail.
  • Compliance Mapping Tools - Maps security scan results to industry-standard regulatory frameworks to evaluate compliance.
  • Automated Configuration Remediation - Implements automated mechanisms to fix identified security misconfigurations in cloud infrastructure.
  • Cloud Infrastructure Security Auditors - Evaluates AWS and Azure resource configurations against security plugins to identify risks.
  • Cloud Security Posture Management - Provides a centralized platform for tracking and visualizing the security posture of AWS and Azure environments.
  • Azure Misconfiguration Detectors - Detects security risks and benchmark violations specifically within Azure infrastructure.
  • AWS - Performs automated security audits of AWS resource settings and access controls.
  • Modular Scanning Engines - Uses a modular engine to execute a library of security check plugins across cloud environments.
  • Scan Result Visualizers - Displays security findings through a visual interface and printable reports for easier analysis.
  • Cloud Infrastructure Data Collection - Fetches infrastructure resource data from cloud providers via API calls to prepare for security analysis.
  • Cloud Resource Discovery - Provides automated discovery of cloud infrastructure state via authenticated API requests to cloud providers.
  • Multi-Account Scanning - Audits multiple cloud subscriptions or accounts in a single pass using authorized roles.
  • Scan Result Exporters - Writes security scan findings to structured formats like JSON, CSV, and JUnit for external reporting.
  • Cloud Provider Abstraction Layers - Provides a unified abstraction layer to standardize security scanning logic across AWS and Azure.
  • Cloud Resource Risk Analysis - Evaluates cloud infrastructure data to identify and assign risk levels to misconfigured resources.
  • Custom Security Scan Extensions - Offers a pluggable architecture for defining custom security tests and API probes.
  • Security Finding Management - Excludes known risks from scan results using regular expressions to manage security findings.
  • Cloud Security - Detection of security risks in cloud infrastructure.
  • Cloud and Container Security - Automated cloud infrastructure security scanning.

Star-Verlauf

Star-Verlauf für aquasecurity/cloudsploitStar-Verlauf für aquasecurity/cloudsploit

KI-Suche

Entdecke weitere awesome Repositories

Beschreibe in einfachen Worten, was du brauchst — die KI bewertet tausende kuratierte Open-Source-Projekte nach Relevanz.

Start searching with AI

Open-Source-Alternativen zu Cloudsploit

Ähnliche Open-Source-Projekte, sortiert nach der Anzahl der gemeinsamen Funktionen mit Cloudsploit.
  • nccgroup/scoutsuiteAvatar von nccgroup

    nccgroup/ScoutSuite

    7,548Auf GitHub ansehen↗

    ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks. The tool provides auditing capabilities for AWS, Google Cloud, DigitalOcean, and Kubernetes clusters and control planes. It distinguishes itself by decoupling data collection from analysis, allowing users to cache cloud configurations locally for offline auditing and iterative rul

    Pythonauditingawsazure
    Auf GitHub ansehen↗7,548
  • toniblyx/prowlerAvatar von toniblyx

    toniblyx/prowler

    14,005Auf GitHub ansehen↗

    Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast

    Python
    Auf GitHub ansehen↗14,005
  • cloudsploit/scansAvatar von cloudsploit

    cloudsploit/scans

    3,748Auf GitHub ansehen↗

    This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr

    JavaScript
    Auf GitHub ansehen↗3,748
  • alfresco/prowlerAvatar von Alfresco

    Alfresco/prowler

    14,005Auf GitHub ansehen↗

    Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for automating security audits, evaluating cloud infrastructure against regulatory compliance frameworks, and managing security assessments through a dedicated analysis dashboard. The project distinguishes itself by providing an AI-driven security context server that feeds structured data to AI assistants for automated risk analysis. It also employs graph-based attack path mapping to visualize potential lateral movement and exploitation routes across cloud inventories. The platform cove

    Python
    Auf GitHub ansehen↗14,005
Alle 30 Alternativen zu Cloudsploit anzeigen→

Häufig gestellte Fragen

Was macht aquasecurity/cloudsploit?

Cloudsploit is a cloud security posture management tool and multi-cloud security auditor. It audits cloud infrastructure for misconfigurations and compliance risks across multiple providers, specifically AWS and Azure, by evaluating resource configurations against a set of security plugins.

Was sind die Hauptfunktionen von aquasecurity/cloudsploit?

Die Hauptfunktionen von aquasecurity/cloudsploit sind: Cloud Infrastructure Security, Cloud Compliance Auditors, Security Risk Assessments, Compliance Mapping Tools, Automated Configuration Remediation, Cloud Infrastructure Security Auditors, Cloud Security Posture Management, Azure Misconfiguration Detectors.

Welche Open-Source-Alternativen gibt es zu aquasecurity/cloudsploit?

Open-Source-Alternativen zu aquasecurity/cloudsploit sind unter anderem: nccgroup/scoutsuite — ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and… toniblyx/prowler — Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance… cloudsploit/scans — This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and… alfresco/prowler — Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for… tfsec/tfsec — tfsec is a static analysis tool and security scanner for infrastructure as code, specifically designed to detect… aquasecurity/kube-bench — kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to…