awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to cisagov/sparrow

Projects sharing features with Sparrow

30 open-source projects similar to cisagov/sparrow, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • toniblyx/prowlertoniblyx avatar

    toniblyx/prowler

    14,005View on GitHub↗

    Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast

    Python
    View on GitHub↗14,005
  • cloudsploit/scanscloudsploit avatar

    cloudsploit/scans

    3,748View on GitHub↗

    This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr

    JavaScript
    View on GitHub↗3,748
  • duo-labs/cloudmapperduo-labs avatar

    duo-labs/cloudmapper

    6,259View on GitHub↗
    JavaScriptawscytoscapediagram
    View on GitHub↗6,259
  • securityftw/cs-suiteSecurityFTW avatar

    SecurityFTW/cs-suite

    1,172View on GitHub↗

    Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.

    Shellaws-auditaws-securityazure
    View on GitHub↗1,172

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • jpcertcc/logontracerJPCERTCC avatar

    JPCERTCC/LogonTracer

    3,136View on GitHub↗

    LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a dockerized security auditor that utilizes a security event graph database to map account names and network addresses, allowing for the visualization of complex system compromise patterns and authentication paths. The system features a Sigma detection engine that scans imported event logs against standardized rule sets to identify known malicious activity. It also includes an anomalous behavior detector that applies statistical analysis, graph algorithms, and hidden Markov models to

    Pythonactive-directoryblueteamdfir
    View on GitHub↗3,136
  • cyberark/skywrappercyberark avatar

    cyberark/SkyWrapper

    107View on GitHub↗

    SkyWrapper helps to discover suspicious creation forms and uses of temporary tokens in AWS

    Python
    View on GitHub↗107
  • cyberark/skyarkcyberark avatar

    cyberark/SkyArk

    912View on GitHub↗

    SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS

    PowerShell
    View on GitHub↗912
  • darkbitio/aws-recondarkbitio avatar

    darkbitio/aws-recon

    557View on GitHub↗

    Multi-threaded AWS inventory collection tool with a focus on security-relevant resources and metadata.

    Ruby
    View on GitHub↗557
  • nccgroup/aws-inventorynccgroup avatar

    nccgroup/aws-inventory

    740View on GitHub↗

    Discover resources created in an AWS account.

    Python
    View on GitHub↗740
  • salesforce/cloudsplainingsalesforce avatar

    salesforce/cloudsplaining

    2,226View on GitHub↗

    Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

    JavaScript
    View on GitHub↗2,226
  • nccgroup/scoutsuitenccgroup avatar

    nccgroup/ScoutSuite

    7,548View on GitHub↗

    ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks. The tool provides auditing capabilities for AWS, Google Cloud, DigitalOcean, and Kubernetes clusters and control planes. It distinguishes itself by decoupling data collection from analysis, allowing users to cache cloud configurations locally for offline auditing and iterative rul

    Pythonauditingawsazure
    View on GitHub↗7,548
  • nccgroup/pmappernccgroup avatar

    nccgroup/PMapper

    1,562View on GitHub↗

    A tool for quickly evaluating IAM permissions in AWS.

    Python
    View on GitHub↗1,562
  • duo-labs/cloudtrackerduo-labs avatar

    duo-labs/cloudtracker

    911View on GitHub↗

    CloudTracker helps you find over-privileged IAM users and roles by comparing CloudTrail logs with current IAM policies.

    Python
    View on GitHub↗911
  • awslabs/aws-security-benchmarkawslabs avatar

    awslabs/aws-security-benchmark

    620View on GitHub↗

    Open source demos, concept and guidance related to the AWS CIS Foundation framework.

    Python
    View on GitHub↗620
  • 0kee-team/watchad0

    0Kee-Team/WatchAD

    0View on GitHub↗
    View on GitHub↗0
  • aquasecurity/kube-benchaquasecurity avatar

    aquasecurity/kube-bench

    8,078View on GitHub↗

    kube-bench is a Kubernetes security benchmark scanner and configuration auditor. It verifies if a cluster adheres to the Center for Internet Security standards and other hardening guides to identify security misconfigurations and vulnerabilities. The tool operates as a containerized security scanner, utilizing host namespaces to analyze nodes and control plane components without requiring the installation of binaries directly on the host. It supports multiple Kubernetes distributions, applying environment-specific benchmarks to ensure auditing accuracy for managed services. The project cover

    Go
    View on GitHub↗8,078
  • anssi-fr/dfir-o365rcA

    ANSSI-FR/DFIR-O365RC

    0View on GitHub↗
    View on GitHub↗0
  • aliyun/aliyun-cliA

    aliyun/aliyun-cli

    0View on GitHub↗
    View on GitHub↗0
  • anssi-fr/adtimelineANSSI-FR avatar

    ANSSI-FR/ADTimeline

    525View on GitHub↗

    1. The ADTimeline PowerShell script 1. Description 2. Prerequisites 3. Usage 4. Files generated 5. Custom groups 2. The ADTimeline App for Splunk 1. Description 2. Sourcetypes 3. AD General information dashboards 4. AD threat hunting dashboards 5. Enhance your traditional event logs threat…

    PowerShell
    View on GitHub↗525
  • anirudhbiyani/findmytakeoveranirudhbiyani avatar

    anirudhbiyani/findmytakeover

    175View on GitHub↗

    find dangling domains in a multi cloud environment

    Python
    View on GitHub↗175
  • alfresco/prowlerAlfresco avatar

    Alfresco/prowler

    14,005View on GitHub↗

    Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for automating security audits, evaluating cloud infrastructure against regulatory compliance frameworks, and managing security assessments through a dedicated analysis dashboard. The project distinguishes itself by providing an AI-driven security context server that feeds structured data to AI assistants for automated risk analysis. It also employs graph-based attack path mapping to visualize potential lateral movement and exploitation routes across cloud inventories. The platform cove

    Python
    View on GitHub↗14,005
  • 0xsha/cloudbrute0xsha avatar

    0xsha/cloudbrute

    1,137View on GitHub↗

    Awesome cloud enumerator

    Go
    View on GitHub↗1,137
  • bishopfox/smogcloudB

    BishopFox/smogcloud

    0View on GitHub↗
    View on GitHub↗0
  • bloodhoundad/azurehoundB

    BloodHoundAD/AzureHound

    0View on GitHub↗
    View on GitHub↗0
  • bridgecrewio/airiambridgecrewio avatar

    bridgecrewio/AirIAM

    824View on GitHub↗

    Least privilege AWS IAM Terraformer

    Python
    View on GitHub↗824
  • bridgecrewio/cdkgoatbridgecrewio avatar

    bridgecrewio/cdkgoat

    48View on GitHub↗

    CdkGoat is Bridgecrew's "Vulnerable by Design" AWS CDK repository. CdkGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

    Python
    View on GitHub↗48
  • bridgecrewio/cfngoatbridgecrewio avatar

    bridgecrewio/cfngoat

    97View on GitHub↗

    Cfngoat is Bridgecrew's "Vulnerable by Design" Cloudformation repository. Cfngoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

    View on GitHub↗97
  • carlospolop/purplepandaC

    carlospolop/PurplePanda

    0View on GitHub↗
    View on GitHub↗0
  • carnal0wnage/weirdaalcarnal0wnage avatar

    carnal0wnage/weirdAAL

    844View on GitHub↗

    WeirdAAL (AWS Attack Library)

    Python
    View on GitHub↗844
  • bishopfox/iam-vulnerableBishopFox avatar

    BishopFox/iam-vulnerable

    574View on GitHub↗

    Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

    HCL
    View on GitHub↗574