For herramienta de auditoría de seguridad automatizada para AWS, the strongest matches are duo-labs/cloudmapper (CloudMapper is an open-source tool that scans an AWS), prowler-cloud/prowler (Prowler is an automated cloud infrastructure security scanner that) and toniblyx/prowler (Prowler is a multi-cloud security scanner that automates compliance). aquasecurity/cloudsploit and capitalone/cloud-custodian round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Identifica vulnerabilidades y configuraciones erróneas en tu infraestructura de AWS usando estos escáneres automatizados de evaluación de seguridad y cumplimiento.
CloudMapper is an open-source tool that scans an AWS account for security misconfigurations and visualizes the environment with IAM and S3 checks, including some compliance assessments, making it a solid fit for auditing—though it lacks automated remediation and real-time event-driven scanning.
Prowler is an automated cloud infrastructure security scanner and posture management tool. It evaluates cloud environments and infrastructure-as-code templates against security benchmarks to identify misconfigurations, vulnerabilities, and compliance gaps that could compromise system integrity. The platform distinguishes itself through graph-based attack path analysis, which identifies chains of misconfigurations that create exploitable routes for unauthorized access. It utilizes a plugin-based execution model to perform state-based assessments of live environments and static analysis of conf
Prowler is an automated cloud infrastructure security scanner that evaluates AWS environments against compliance benchmarks like CIS, performs IAM and resource misconfiguration checks, and supports infrastructure-as-code analysis—exactly the kind of comprehensive, self-hostable tool you are looking for.
Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast
Prowler is a multi-cloud security scanner that automates compliance assessments against industry benchmarks like CIS and NIST across AWS, with checks for IAM, S3, and multi-account support, plus remediation recommendations and attack-path visualization — it directly fits your need for an open-source AWS security auditing tool.
Cloudsploit is a cloud security posture management tool and multi-cloud security auditor. It audits cloud infrastructure for misconfigurations and compliance risks across multiple providers, specifically AWS and Azure, by evaluating resource configurations against a set of security plugins. The project functions as a cloud compliance scanner that maps infrastructure scan results to regulatory frameworks and security policy standards. It also serves as an automated cloud remediation tool, executing corrective actions to fix detected misconfigurations via SDK calls. The system covers resource
Cloudsploit is an open-source cloud security posture management tool that audits AWS (and other clouds) for misconfigurations and compliance risks, provides automated remediation via SDK calls, and maps results to regulatory frameworks—exactly matching the need for an AWS security scanner with compliance and remediation features.
Cloud Custodian is a multi-cloud governance engine and policy enforcement tool designed to automate security, compliance, and cost optimization across various cloud providers. It functions as a rules engine that uses a declarative domain specific language to query cloud resources and execute corrective actions based on predefined filters. The system operates as a serverless policy orchestrator, deploying provider-specific functions to trigger real-time enforcement in response to cloud resource changes. It provides a provider-agnostic resource abstraction to maintain consistent operational pol
Cloud Custodian is a multi-cloud governance engine that automates security and compliance policy enforcement — it audits AWS resources against CIS and other benchmarks, analyzes IAM and S3, offers automated remediation, supports multi-account and event-driven scanning, and integrates with infrastructure-as-code, which directly matches your need for an open-source scanner with those features.
ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks. The tool provides auditing capabilities for AWS, Google Cloud, DigitalOcean, and Kubernetes clusters and control planes. It distinguishes itself by decoupling data collection from analysis, allowing users to cache cloud configurations locally for offline auditing and iterative rul
ScoutSuite is a multi-cloud security auditing tool that evaluates AWS resources against security benchmarks and compliance rulesets, with features like multi-account scanning and detailed analysis reports, making it a comprehensive solution for automated AWS security assessment.
Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for automating security audits, evaluating cloud infrastructure against regulatory compliance frameworks, and managing security assessments through a dedicated analysis dashboard. The project distinguishes itself by providing an AI-driven security context server that feeds structured data to AI assistants for automated risk analysis. It also employs graph-based attack path mapping to visualize potential lateral movement and exploitation routes across cloud inventories. The platform cove
Prowler is a multi-cloud security posture scanner that automates AWS security audits, checks against CIS/NIST/SOC2 benchmarks, and analyzes IAM and S3 configurations, directly matching your need for an open-source cloud security scanner.
This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr
CloudSploit is a cloud security posture management (CSPM) tool that automatically scans AWS accounts for misconfigurations, compliance violations (CIS, NIST, SOC2), and security risks, including IAM and S3 analysis, multi-account support, and remediation guidance — squarely fitting the need for a self-hosted AWS security auditor.
Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai
Trivy is a comprehensive cloud security scanner that can assess AWS accounts for misconfigurations, vulnerabilities, and compliance benchmarks (CIS, NIST) via its cloud and IaC scanning modes, though it lacks dedicated real-time event-driven monitoring, making it a solid fit for the core intent.
Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.
Cloudsplaining is an AWS IAM security assessment tool that identifies least-privilege violations, matching your need for automated auditing, but it is limited to IAM analysis and does not cover compliance benchmarks, S3 checks, or remediation.
| Repositorio | Estrellas | Lenguaje | Licencia | Último push |
|---|---|---|---|---|
| duo-labs/cloudmapper | 6.3K | JavaScript | bsd-3-clause | |
| prowler-cloud/prowler | 13K | Python | apache-2.0 | |
| toniblyx/prowler | 14K | Python | Apache-2.0 | |
| aquasecurity/cloudsploit | 3.7K | JavaScript | gpl-3.0 | |
| capitalone/cloud-custodian | 6K | Python | Apache-2.0 | |
| nccgroup/scoutsuite | 7.5K | Python | gpl-2.0 | |
| alfresco/prowler | 14K | Python | Apache-2.0 | |
| cloudsploit/scans | 3.7K | JavaScript | GPL-3.0 | |
| aquasecurity/trivy | 36.5K | Go | Apache-2.0 | |
| salesforce/cloudsplaining | 2.2K | JavaScript | BSD-3-Clause |