awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
nccgroup avatar

nccgroup/ScoutSuite

0
View on GitHub↗
7,548 estrellas·1,185 forks·Python·gpl-2.0·7 vistas

ScoutSuite

ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks.

The tool provides auditing capabilities for AWS, Google Cloud, DigitalOcean, and Kubernetes clusters and control planes. It distinguishes itself by decoupling data collection from analysis, allowing users to cache cloud configurations locally for offline auditing and iterative rule testing without repeated API calls.

The system employs a JSON-based rule engine that supports custom security rule definitions, parameterized checks, and the suppression of specific findings. It manages authentication through credential files, managed identities, and temporary role assumptions, while generating visual security posture assessments via HTML reports and JSON exports.

The tool can be executed within a pre-configured container environment containing all necessary dependencies.

Features

  • Cloud Auditing Tools - Provides a multi-cloud auditing tool to assess infrastructure configurations against security best practices.
  • Cloud Compliance Auditors - Automates the evaluation of cloud infrastructure against industry-standard regulatory frameworks and security benchmarks.
  • Configuration Logic Evaluators - Evaluates resource configurations using nested logical operators and dynamic macros to detect security risks.
  • Offline Configuration Analysis - Evaluates cloud resource settings offline using cached data to test security rules without repeated API calls.
  • Control Plane Auditing - Scans Kubernetes control planes and master nodes across cloud providers to identify posture risks.
  • GCP Configuration Audits - Analyzes Google Cloud configurations across organizations and projects to identify security risks.
  • Cloud Provider Abstraction Layers - Employs unified interfaces to standardize the fetching of configuration data across multiple cloud service providers.
  • Cloud Security Posture Management - Gathers cloud configuration data to track and visualize the security posture of cloud accounts.
  • JSON-Based Rule Engines - Uses a JSON-based rule engine to evaluate cloud resource configurations against security benchmarks.
  • DigitalOcean Configuration Audits - Gathers configuration data from DigitalOcean APIs to perform security posture assessments.
  • AWS - Gathers security posture data from AWS APIs to identify risk areas.
  • Kubernetes Posture Scanning - Scans Kubernetes clusters and control planes across multiple cloud providers to identify security risks.
  • Security Rule Development - Allows the creation of tailored security checks to identify environment-specific risks.
  • HTML Analysis Reports - Generates structured HTML reports for visual inspection of cloud security posture and analysis results.
  • Local State Caches - Persists downloaded cloud configurations locally to allow iterative rule testing without repeating API calls.
  • Rule Parameterization - Supports using arguments within rule definitions to reuse a single security check across different values.
  • Cloud Provider Integrations - Enables the implementation of custom authentication strategies and data facades to integrate additional cloud platforms.
  • Multi-Account Scanning - Allows scanning a specific list of cloud subscriptions or all accessible accounts in one run.
  • Cloud Credential Management - Supports authenticating to cloud APIs using environment variables or credential files.
  • Custom Compliance Rulesets - Executes specific security findings based on industry-standard benchmarks using custom rulesets.
  • Temporary Security Tokens - Manages temporary security token exchanges and role assumptions to access multiple cloud accounts.
  • Identity Authentication - Provides support for connecting to cloud environments via CLI sessions, managed identities, and browser-based MFA.
  • AWS Role Assumption - Allows requesting temporary security credentials using role identifiers to perform audits in specific security contexts.
  • Security Finding Management - Allows marking specific resources as exceptions to security rules to suppress them from reports.
  • Security Report Generation - Generates security scan findings as structured HTML reports and JSON exports for stakeholders.
  • Offline Configuration Analysis - Performs security audits against downloaded configuration data to test rule changes without live API calls.
  • Collection and Analysis Decoupling - Implements a decoupled architecture that separates cloud data collection from security analysis to enable offline auditing.
  • Rule Evaluators - Allows passing external arguments and resolving resource IDs at runtime for flexible rule evaluation across environments.
  • Cloud Platform Security - Multi-cloud security auditing for posture assessment.
  • Cloud Security - Multi-cloud security scanning tool.
  • Cloud Security Tooling and Automation - Multi-cloud infrastructure security auditing tool.
  • Cloud Infrastructure Security - Multi-cloud security auditing tool for infrastructure assessment.
  • Cloud Security - Multi-cloud security auditing tool for configuration assessment.
  • Cloud Security Auditing - Multi-cloud security auditing tool for assessing environment posture.
  • Security Assessment Tools - Multi-cloud security auditing tool for infrastructure assessment.

Historial de estrellas

Gráfico del historial de estrellas de nccgroup/scoutsuiteGráfico del historial de estrellas de nccgroup/scoutsuite

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Start searching with AI

Alternativas open-source a ScoutSuite

Proyectos open-source similares, clasificados según cuántas características comparten con ScoutSuite.
  • toniblyx/prowlerAvatar de toniblyx

    toniblyx/prowler

    14,005Ver en GitHub↗

    Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast

    Python
    Ver en GitHub↗14,005
  • aquasecurity/cloudsploitAvatar de aquasecurity

    aquasecurity/cloudsploit

    3,705Ver en GitHub↗

    Cloudsploit is a cloud security posture management tool and multi-cloud security auditor. It audits cloud infrastructure for misconfigurations and compliance risks across multiple providers, specifically AWS and Azure, by evaluating resource configurations against a set of security plugins. The project functions as a cloud compliance scanner that maps infrastructure scan results to regulatory frameworks and security policy standards. It also serves as an automated cloud remediation tool, executing corrective actions to fix detected misconfigurations via SDK calls. The system covers resource

    JavaScriptalibabaaquaaws
    Ver en GitHub↗3,705
  • cloudsploit/scansAvatar de cloudsploit

    cloudsploit/scans

    3,748Ver en GitHub↗

    This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr

    JavaScript
    Ver en GitHub↗3,748
  • rhinosecuritylabs/pacuAvatar de RhinoSecurityLabs

    RhinoSecurityLabs/pacu

    5,234Ver en GitHub↗

    Pacu is an exploitation framework designed for auditing and testing the security of Amazon Web Services environments. It serves as a cloud penetration testing tool and resource enumerator used to identify misconfigurations, map attack surfaces, and execute privilege escalation paths. The framework provides specialized capabilities for post-exploitation and red team operations, including establishing persistence through identity and access management backdooring. It distinguishes itself with a plugin-based module system that allows for the development of custom tasks and the orchestration of A

    Python
    Ver en GitHub↗5,234
Ver las 30 alternativas a ScoutSuite→

Preguntas frecuentes

¿Qué hace nccgroup/scoutsuite?

ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks.

¿Cuáles son las características principales de nccgroup/scoutsuite?

Las características principales de nccgroup/scoutsuite son: Cloud Auditing Tools, Cloud Compliance Auditors, Configuration Logic Evaluators, Offline Configuration Analysis, Control Plane Auditing, GCP Configuration Audits, Cloud Provider Abstraction Layers, Cloud Security Posture Management.

¿Qué alternativas de código abierto existen para nccgroup/scoutsuite?

Las alternativas de código abierto para nccgroup/scoutsuite incluyen: toniblyx/prowler — Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance… aquasecurity/cloudsploit — Cloudsploit is a cloud security posture management tool and multi-cloud security auditor. It audits cloud… cloudsploit/scans — This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and… rhinosecuritylabs/pacu — Pacu is an exploitation framework designed for auditing and testing the security of Amazon Web Services environments.… aquasecurity/tfsec — tfsec is a static analysis tool and infrastructure as code linter designed to detect security misconfigurations and… 99designs/aws-vault — aws-vault is a secure credential manager and command-line wrapper for AWS. It stores long-term identity keys using the…