14 रिपॉजिटरी
Tools for enumerating and auditing cloud infrastructure and storage buckets.
Explore 14 awesome GitHub repositories matching part of an awesome list · Cloud Security Auditing. Refine with filters or upvote what's useful.
Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai
Comprehensive security scanner for cloud-native environments.
Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast
Security tool for cloud best practices, compliance, and forensics.
ScoutSuite is a multi-cloud security audit and configuration tool designed to identify security risks and misconfigurations across cloud environments. It functions as a security posture manager and compliance auditor, gathering resource metadata from cloud APIs to evaluate infrastructure against security benchmarks. The tool provides auditing capabilities for AWS, Google Cloud, DigitalOcean, and Kubernetes clusters and control planes. It distinguishes itself by decoupling data collection from analysis, allowing users to cache cloud configurations locally for offline auditing and iterative rul
Multi-cloud security auditing tool for assessing environment posture.
Keyhacks is a command-line tool that tests whether API keys and tokens for dozens of cloud services are valid and active. It automates the verification of discovered credentials during security auditing and penetration testing, confirming if leaked or harvested API keys, tokens, and secrets are still operational. The tool validates credentials by sending lightweight, service-specific HTTP requests to each platform's API endpoint and inspecting the response status or body. Each validation runs independently without storing state between requests, using pre-defined request templates with the co
Validates API keys found during bug bounty engagements.
Pacu एक एक्सप्लॉइटेशन फ्रेमवर्क है जिसे Amazon Web Services वातावरण की सुरक्षा का ऑडिट और परीक्षण करने के लिए डिज़ाइन किया गया है। यह क्लाउड पेनेट्रेशन टेस्टिंग टूल और संसाधन एन्यूमेरेटर के रूप में कार्य करता है जिसका उपयोग गलत कॉन्फ़िगरेशन की पहचान करने, अटैक सरफेस को मैप करने और विशेषाधिकार वृद्धि पथों को निष्पादित करने के लिए किया जाता है। फ्रेमवर्क पोस्ट-एक्सप्लॉइटेशन और रेड टीम ऑपरेशंस के लिए विशेष क्षमताएं प्रदान करता है, जिसमें पहचान और एक्सेस प्रबंधन बैकडोरिंग के माध्यम से दृढ़ता स्थापित करना शामिल है। यह एक प्लगइन-आधारित मॉड्यूल सिस्टम के साथ खुद को अलग करता है जो कस्टम कार्यों के विकास और कई भौगोलिक क्षेत्रों में API अनुरोधों के ऑर्केस्ट्रेशन की अनुमति देता है। यह प्रोजेक्ट सुरक्षा ऑडिटिंग गतिविधियों की एक विस्तृत श्रृंखला को कवर करता है, जिसमें बुनियादी ढांचे की गणना, भंडारण सेवाओं से डेटा निष्कर्षण और पहचान ऑडिटिंग शामिल है। इसमें पेलोड इंजेक्शन और स्टार्टअप स्क्रिप्ट के माध्यम से रिमोट कोड निष्पादन के लिए उपकरण शामिल हैं, साथ ही डिटेक्शन सेवाओं को बाधित करने और नेटवर्क पार्श्व आंदोलन का विश्लेषण करने की क्षमताएं भी शामिल हैं। Pacu स्थिति बनाए रखने और API कॉल को कम करने के लिए अलग-थलग कंटेनरों और एक स्थानीय डेटाबेस का उपयोग करके लक्ष्य-विशिष्ट प्रमाणीकरण कुंजियों और सेशन मेटाडेटा का प्रबंधन करता है।
Offensive security framework for testing AWS environments.
Flan एक कंटेनराइज़्ड नेटवर्क भेद्यता स्कैनर और सुरक्षा ऑडिटर है। यह ज्ञात सुरक्षा कमजोरियों और मिसकॉन्फ़िगरेशन का पता लगाने के लिए नेटवर्क पर खुले पोर्ट और सर्विस वर्ज़न की पहचान करता है। यह सिस्टम अलग-थलग कंटेनर वातावरण के भीतर चलने के लिए डिज़ाइन किया गया है, जो टारगेट लिस्ट और सीक्रेट्स को मैनेज करने के लिए कॉन्फ़िगरेशन मैप्स का उपयोग करता है। इसमें दीर्घकालिक स्टोरेज के लिए रिमोट S3 बकेट में स्कैन आउटपुट फाइलों और सुरक्षा विश्लेषण डेटा को आर्काइव करने के लिए एक समर्पित तंत्र शामिल है। यह टूल तकनीकी विश्लेषण के लिए कई दस्तावेज़ फॉर्मेट में स्वरूपित भेद्यता सारांश और सुरक्षा रिपोर्ट उत्पन्न करता है। यह केंद्रीकृत सुरक्षा ऑडिटिंग के लिए रिमोट क्लाउड स्टोरेज में रॉ स्कैन डेटा एक्सपोर्ट करने का समर्थन करता है।
Enables centralized security analysis by archiving network scan data to cloud storage.
This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr
Detects security risks in cloud infrastructure accounts.
Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.
Assesses AWS IAM policies for least privilege violations.
Find interesting Amazon S3 Buckets by watching certificate transparency logs.
Finds public S3 buckets by monitoring certificate transparency logs.
Enumerate the permissions associated with AWS credential set
Enumerates permissions for discovered AWS credentials.
Used for determining whether a leaked/found Google Maps API Key is vulnerable to unauthorized access by other applications or not.
Checks Google Maps API keys for unauthorized access vulnerabilities.
AWS Extender (Cloud Storage Tester) is a Burp plugin to assess permissions of cloud storage containers on AWS, Google Cloud and Azure.
Burp Suite extension for identifying and testing cloud storage misconfigurations.
Unified framework for multi-cloud security reconnaissance.