awesome-repositories.com
Blog
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

Herramientas de auditoría de seguridad automatizada para AWS

Clasificación actualizada el 30 jun 2026

For herramienta de auditoría de seguridad automatizada para AWS, the strongest matches are duo-labs/cloudmapper (CloudMapper is an open-source tool that scans an AWS), prowler-cloud/prowler (Prowler is an automated cloud infrastructure security scanner that) and toniblyx/prowler (Prowler is a multi-cloud security scanner that automates compliance). aquasecurity/cloudsploit and capitalone/cloud-custodian round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

Identifica vulnerabilidades y configuraciones erróneas en tu infraestructura de AWS usando estos escáneres automatizados de evaluación de seguridad y cumplimiento.

Herramientas de auditoría de seguridad automatizada para AWS

Encuentra los mejores repositorios con IA.Buscaremos los repositorios que mejor coincidan usando IA.
  • duo-labs/cloudmapperAvatar de duo-labs

    duo-labs/cloudmapper

    6,259Ver en GitHub↗

    CloudMapper is an open-source tool that scans an AWS account for security misconfigurations and visualizes the environment with IAM and S3 checks, including some compliance assessments, making it a solid fit for auditing—though it lacks automated remediation and real-time event-driven scanning.

    JavaScriptIAM Policy AnalyzersIAM Policy AuditorsMulti-Account Orchestration
    Ver en GitHub↗6,259
  • prowler-cloud/prowlerAvatar de prowler-cloud

    prowler-cloud/prowler

    13,049Ver en GitHub↗

    Prowler is an automated cloud infrastructure security scanner and posture management tool. It evaluates cloud environments and infrastructure-as-code templates against security benchmarks to identify misconfigurations, vulnerabilities, and compliance gaps that could compromise system integrity. The platform distinguishes itself through graph-based attack path analysis, which identifies chains of misconfigurations that create exploitable routes for unauthorized access. It utilizes a plugin-based execution model to perform state-based assessments of live environments and static analysis of conf

    Prowler is an automated cloud infrastructure security scanner that evaluates AWS environments against compliance benchmarks like CIS, performs IAM and resource misconfiguration checks, and supports infrastructure-as-code analysis—exactly the kind of comprehensive, self-hostable tool you are looking for.

    PythonInfrastructure as Code Scanners
    Ver en GitHub↗13,049
  • toniblyx/prowlerAvatar de toniblyx

    toniblyx/prowler

    14,005Ver en GitHub↗

    Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast

    Prowler is a multi-cloud security scanner that automates compliance assessments against industry benchmarks like CIS and NIST across AWS, with checks for IAM, S3, and multi-account support, plus remediation recommendations and attack-path visualization — it directly fits your need for an open-source AWS security auditing tool.

    PythonMulti-Account Orchestration
    Ver en GitHub↗14,005
  • aquasecurity/cloudsploitAvatar de aquasecurity

    aquasecurity/cloudsploit

    3,705Ver en GitHub↗

    Cloudsploit is a cloud security posture management tool and multi-cloud security auditor. It audits cloud infrastructure for misconfigurations and compliance risks across multiple providers, specifically AWS and Azure, by evaluating resource configurations against a set of security plugins. The project functions as a cloud compliance scanner that maps infrastructure scan results to regulatory frameworks and security policy standards. It also serves as an automated cloud remediation tool, executing corrective actions to fix detected misconfigurations via SDK calls. The system covers resource

    Cloudsploit is an open-source cloud security posture management tool that audits AWS (and other clouds) for misconfigurations and compliance risks, provides automated remediation via SDK calls, and maps results to regulatory frameworks—exactly matching the need for an AWS security scanner with compliance and remediation features.

    JavaScriptMulti-Account Scanning
    Ver en GitHub↗3,705
  • capitalone/cloud-custodianAvatar de capitalone

    capitalone/cloud-custodian

    6,016Ver en GitHub↗

    Cloud Custodian is a multi-cloud governance engine and policy enforcement tool designed to automate security, compliance, and cost optimization across various cloud providers. It functions as a rules engine that uses a declarative domain specific language to query cloud resources and execute corrective actions based on predefined filters. The system operates as a serverless policy orchestrator, deploying provider-specific functions to trigger real-time enforcement in response to cloud resource changes. It provides a provider-agnostic resource abstraction to maintain consistent operational pol

    Cloud Custodian is a multi-cloud governance engine that automates security and compliance policy enforcement — it audits AWS resources against CIS and other benchmarks, analyzes IAM and S3, offers automated remediation, supports multi-account and event-driven scanning, and integrates with infrastructure-as-code, which directly matches your need for an open-source scanner with those features.

    PythonInfrastructure as Code Security
    Ver en GitHub↗6,016
  • nccgroup/scoutsuiteAvatar de nccgroup

    nccgroup/ScoutSuite

    7,548Ver en GitHub↗

    ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks. The tool provides auditing capabilities for AWS, Google Cloud, DigitalOcean, and Kubernetes clusters and control planes. It distinguishes itself by decoupling data collection from analysis, allowing users to cache cloud configurations locally for offline auditing and iterative rul

    ScoutSuite is a multi-cloud security auditing tool that evaluates AWS resources against security benchmarks and compliance rulesets, with features like multi-account scanning and detailed analysis reports, making it a comprehensive solution for automated AWS security assessment.

    PythonMulti-Account Scanning
    Ver en GitHub↗7,548
  • alfresco/prowlerAvatar de Alfresco

    Alfresco/prowler

    14,005Ver en GitHub↗

    Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for automating security audits, evaluating cloud infrastructure against regulatory compliance frameworks, and managing security assessments through a dedicated analysis dashboard. The project distinguishes itself by providing an AI-driven security context server that feeds structured data to AI assistants for automated risk analysis. It also employs graph-based attack path mapping to visualize potential lateral movement and exploitation routes across cloud inventories. The platform cove

    Prowler is a multi-cloud security posture scanner that automates AWS security audits, checks against CIS/NIST/SOC2 benchmarks, and analyzes IAM and S3 configurations, directly matching your need for an open-source cloud security scanner.

    PythonCloud Security Posture ManagementAI Security Context ServersAI Security Data Providers
    Ver en GitHub↗14,005
  • cloudsploit/scansAvatar de cloudsploit

    cloudsploit/scans

    3,748Ver en GitHub↗

    This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr

    CloudSploit is a cloud security posture management (CSPM) tool that automatically scans AWS accounts for misconfigurations, compliance violations (CIS, NIST, SOC2), and security risks, including IAM and S3 analysis, multi-account support, and remediation guidance — squarely fitting the need for a self-hosted AWS security auditor.

    JavaScriptCloud Security Posture ManagementAutomated Security RemediationCloud Auditing Tools
    Ver en GitHub↗3,748
  • aquasecurity/trivyAvatar de aquasecurity

    aquasecurity/trivy

    36,462Ver en GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Trivy is a comprehensive cloud security scanner that can assess AWS accounts for misconfigurations, vulnerabilities, and compliance benchmarks (CIS, NIST) via its cloud and IaC scanning modes, though it lacks dedicated real-time event-driven monitoring, making it a solid fit for the core intent.

    GoInfrastructure as Code Scanners
    Ver en GitHub↗36,462
  • salesforce/cloudsplainingAvatar de salesforce

    salesforce/cloudsplaining

    2,226Ver en GitHub↗

    Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

    Cloudsplaining is an AWS IAM security assessment tool that identifies least-privilege violations, matching your need for automated auditing, but it is limited to IAM analysis and does not cover compliance benchmarks, S3 checks, or remediation.

    JavaScriptAWS SecurityCloud SecurityCloud Security Auditing
    Ver en GitHub↗2,226
Compara los 10 mejores de un vistazo
RepositorioEstrellasLenguajeLicenciaÚltimo push
duo-labs/cloudmapper6.3KJavaScriptbsd-3-clause15 jul 2024
prowler-cloud/prowler13KPythonapache-2.019 feb 2026
toniblyx/prowler14KPythonApache-2.017 jun 2026
aquasecurity/cloudsploit3.7KJavaScriptgpl-3.020 feb 2026
capitalone/cloud-custodian6KPythonApache-2.025 jun 2026
nccgroup/scoutsuite7.5KPythongpl-2.023 sept 2025
alfresco/prowler14KPythonApache-2.017 jun 2026
cloudsploit/scans3.7KJavaScriptGPL-3.023 feb 2026
aquasecurity/trivy36.5KGoApache-2.016 jun 2026
salesforce/cloudsplaining2.2KJavaScriptBSD-3-Clause14 jun 2026

Related searches

  • herramienta de postura de seguridad en la nube
  • herramienta de inventario de recursos cloud
  • herramienta para limpiar recursos cloud inactivos
  • herramienta de auditoría de seguridad para servidores Linux
  • un toolkit de endurecimiento de servidores
  • una herramienta de endurecimiento de contenedores
  • entorno en la nube intencionalmente vulnerable para prácticas
  • escáner de seguridad para IaC